Important
Please read the upgrade notes before upgrading your instance.
What's Changed
Enhancements 🚀
- Make the Trivy API token optional by @arjavdongaonkar in #7178
- Tweak apiserver Dockerfile by @nscuro in #7180
- Make Dockerfile more layer cache friendly by @nscuro in #7181
- Allow operators to load external JDBC drivers by @nscuro in #7182
- Support inverted tag matching in policy scope by @arjavdongaonkar in #7176
- Refactor component metrics computation to avoid pathological query plans by @nscuro in #7214
- Add
analyzer_identityinNEW_VULNERABILITYnotifications by @sahibamittal in #7206 - Fix N+1 queries in dependency graph endpoint by @nscuro in #7275
- Improve efficiency of is_dependency_of and is_exclusive_dependency_of CEL functions by @nscuro in #7276
- Avoid redundant component iteration during dependency graph export by @nscuro in #7277
- Add checksum matching support for Snyk vuln analyzer by @mehab in #6835
- Migrate cargo package metadata resolver to sparse index by @nscuro in #7315
- Implement service accounts by @nscuro in #7293
- Implement service account API key expiry by @nscuro in #7317
- Sign webhook payloads with HMAC-SHA256 by @adilalperenciftci in #7323
- Implement workload identity federation by @nscuro in #7330
- Make the monitoring dashboards usable outside the dev stack by @nissessenap in #7335
- Introduce outbound connection policy by @nscuro in #7449
- Integrate outbound connection policy with shared HTTP client by @nscuro in #7450
- Expose outbound connection policy to plugins by @nscuro in #7451
- Streamline JDBI mappers by @nscuro in #7466
- Support bracketed list strings in OIDC teams claim by @Akhil-1527 in #7467
- Bump spdx license list 3.29.0 by @nscuro in #7502
- Enforce a max size for BOM and VEX uploads by @nscuro in #7545
- Batch finding bulk operations and notification emission by @nscuro in #7608
Bug Fixes 🐛
- Run spotless:apply after Maven release plugin modifies them POM by @nscuro in #7138
- v4-migrator: Reconcile PROJECT collection logic and tag by @arjavdongaonkar in #7172
- v4-migrator: Dedup PROJECT_PROPERTY rows of collapsed projects by @arjavdongaonkar in #7171
- Fix PURLs without version being submitted for analysis by @nscuro in #7196
- Add option to use Snyk's per-package endpoint when batching is not available by @arjavdongaonkar in #7195
- Remove unused LDAP properties by @nscuro in #7240
- Fix management server preventing shutdown on initialization failures by @nscuro in #7278
- Fix incorrect OpenAPI docs for POST /v1/project WRT parent semantics by @nscuro in #7312
- Fix DATASOURCE_MIRRORING notifications not being emitted by @nscuro in #7313
- Fix project lookup endpoints not serving aggregate metrics for collection projects by @nscuro in #7311
- Resolve project parent before other fields in updateProject by @adityaanikam in #7262
- Treat >=0 ranges as wildcard during vers matching by @nscuro in #7329
- Fix broken link to VulnCheck token creation by @nscuro in #7347
- Accumulate mirrored VulnerableSoftware by vulnerability key by @nscuro in #7351
- Fix Checkmarx model conversion NPEs by @sahibamittal in #7352
- Fix tag binding triggering unnecessary relationship loads by @nscuro in #7353
- Fix OS package scanning for Trivy analyzer by @nscuro in #7355
- Prevent NPEs during DataNucleus L1 cache eviction by @nscuro in #7357
- Fix proxy authentication for GitHub Advisories vuln data source by @nscuro in #7356
- Fix calculated CVSSv4 score only considering base metrics by @nscuro in #7358
- Fix NVD vuln data source iteration and watermarking issues by @nscuro in #7359
- Move vuln data source mirroring off JDO by @nscuro in #7382
- Fix lack of context in NVD & OSV unexpected status code exception messages by @nscuro in #7385
- Fix invalid PURLs causing list API endpoints to fail by @nscuro in #7501
- Fix failure to match CPE with wildcard version and version range >=0 by @nscuro in #7514
- Fix internal vulns with finding attributions failing deletion by @nscuro in #7542
- PEP 503-normalize PyPI package names for vuln matching by @nscuro in #7546
- Treat NuGet package names as case-insensitive for vuln matching by @nscuro in #7547
- Fix manually assigned findings being deactivated on analysis by @nscuro in #7551
- Fix Trivy findings dropped for PURLs with URL-valued qualifiers by @nissessenap in #7581
- Consistently tolerate trailing slashes in configurable URLs by @nscuro in #7607
- Fix collection project metrics shape when children have no metrics by @nscuro in #7609
- Fix missing pagination in
/v1/vulnerability/component/{uuid}by @nscuro in #7610
Dependency Updates 🤖
- Update maintenance branch in Dependabot config to 5.1.x by @nscuro in #7139
- chore(deps): Bump io.smallrye.config:smallrye-config-bom from 3.18.1 to 3.18.2 by @dependabot[bot] in #7143
- Bump squawk to 2.63.0 by @nscuro in #7150
- Pin spectral image by @nscuro in #7151
- Group CodeQL actions in Dependabot by @nscuro in #7156
- chore(deps): Bump the codeql group with 2 updates by @dependabot[bot] in #7157
- Bump com.uber.nullaway:nullaway from 0.13.8 to 0.14.0 by @dependabot[bot] in #7167
- Bump com.adobe.testing:s3mock-testcontainers from 5.1.0 to 5.2.0 by @dependabot[bot] in #7185
- Bump com.icegreen:greenmail-junit5 from 2.1.12 to 2.1.13 by @dependabot[bot] in #7184
- Bump actions/setup-java from 5.7.0 to 6.0.0 by @dependabot[bot] in #7183
- Bump org.openapitools:openapi-generator-maven-plugin from 7.24.0 to 7.25.0 by @dependabot[bot] in #7198
- Bump io.dropwizard.flywaydb:flyway-bom from 13.3.0 to 13.4.0 by @dependabot[bot] in #7215
- Bump com.diffplug.spotless:spotless-maven-plugin from 3.10.0 to 3.10.1 by @dependabot[bot] in #7217
- Bump org.apache.felix:maven-bundle-plugin from 6.1.0 to 6.1.2 by @dependabot[bot] in #7216
- Bump the codeql group with 2 updates by @dependabot[bot] in #7227
- Bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 by @dependabot[bot] in #7228
- Bump oasdiff/oasdiff-action/breaking from 0.1.13 to 0.1.14 by @dependabot[bot] in #7229
- Bump com.github.luben:zstd-jni from 1.5.7-15 to 1.5.7-16 by @dependabot[bot] in #7230
- Bump org.apache.maven.plugins:maven-compiler-plugin from 3.15.0 to 3.16.0 by @dependabot[bot] in #7231
- Bump com.uber.nullaway:nullaway from 0.14.0 to 0.14.1 by @dependabot[bot] in #7232
- Bump lib.protobuf-java.version from 4.36.0 to 4.36.1 by @dependabot[bot] in #7245
- Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.6 to 3.6.0 by @dependabot[bot] in #7248
- Bump org.apache.maven.plugins:maven-surefire-report-plugin from 3.5.6 to 3.6.0 by @dependabot[bot] in #7249
- Bump io.swagger.parser.v3:swagger-parser from 2.1.47 to 2.1.48 by @dependabot[bot] in #7247
- Bump lib.swagger.version from 2.2.54 to 2.2.55 by @dependabot[bot] in #7266
- Bump org.apache.maven.plugins:maven-failsafe-plugin from 3.5.6 to 3.6.0 by @dependabot[bot] in #7267
- Bump lib.byte-buddy.version from 1.18.12 to 1.18.13 by @dependabot[bot] in #7274
- Bump org.metaeffekt.core:ae-security from 0.156.6 to 0.157.0 by @dependabot[bot] in #7281
- Bump lib.jetty.version from 12.1.12 to 12.1.13 by @dependabot[bot] in #7282
- Bump oasdiff/oasdiff-action/breaking from 0.1.14 to 0.1.15 by @dependabot[bot] in #7295
- Bump docker/setup-qemu-action from 4.2.0 to 4.3.0 by @dependabot[bot] in #7296
- Bump org.slf4j:slf4j-bom from 2.0.18 to 2.0.19 by @dependabot[bot] in #7298
- Bump com.diffplug.spotless:spotless-maven-plugin from 3.10.1 to 3.10.2 by @dependabot[bot] in #7297
- Bump io.dropwizard.flywaydb:flyway-bom from 13.4.0 to 13.5.0 by @dependabot[bot] in #7300
- chore(deps): Bump io.github.openfeign:feign-bom from 13.13 to 13.14 by @dependabot[bot] in #7134
- Bump org.jetbrains.kotlin:kotlin-bom from 2.4.10 to 2.4.20 by @dependabot[bot] in #7319
- Bump io.github.openfeign:feign-bom from 13.14 to 13.15 by @dependabot[bot] in #7324
- Bump com.microsoft.sqlserver:mssql-jdbc from 13.4.0.jre11 to 13.6.0.jre11 by @dependabot[bot] in #7341
- Bump alpine base image to 3.24.2 by @nscuro in #7380
- Bump the codeql group with 2 updates by @dependabot[bot] in #7388
- Bump zizmorcore/zizmor-action from 0.6.3 to 0.6.4 by @dependabot[bot] in #7389
- Bump oasdiff/oasdiff-action/breaking from 0.1.15 to 0.1.16 by @dependabot[bot] in #7390
- Bump actions/setup-java from 6.0.0 to 6.0.1 by @dependabot[bot] in #7391
- Bump com.adobe.testing:s3mock-testcontainers from 5.2.0 to 5.2.2 by @dependabot[bot] in #7392
- Bump io.dropwizard.flywaydb:flyway-bom from 13.5.0 to 13.6.0 by @dependabot[bot] in #7393
- Bump io.github.jeremylong:open-vulnerability-clients from 9.0.6 to 9.0.7 by @dependabot[bot] in #7394
- Bump io.smallrye.config:smallrye-config-bom from 3.18.2 to 3.18.3 by @dependabot[bot] in #7395
- Bump org.apache.felix:maven-bundle-plugin from 6.1.2 to 6.2.0 by @dependabot[bot] in #7396
- Bump io.github.nscuro:versatile-core from 0.24.0 to 0.25.0 by @dependabot[bot] in #7411
- Bump org.codehaus.mojo:exec-maven-plugin from 3.6.3 to 3.6.4 by @dependabot[bot] in #7412
- Bump io.github.ascopes:protobuf-maven-plugin from 5.1.8 to 5.1.9 by @dependabot[bot] in #7413
- Bump org.apache.maven.plugins:maven-install-plugin from 3.1.4 to 3.2.0 by @dependabot[bot] in #7414
- Bump lib.byte-buddy.version from 1.18.13 to 1.18.14 by @dependabot[bot] in #7415
- Bump io.prometheus:prometheus-metrics-bom from 1.8.0 to 1.9.0 by @dependabot[bot] in #7424
- Bump org.apache.maven.plugins:maven-deploy-plugin from 3.1.4 to 3.2.0 by @dependabot[bot] in #7425
- Bump org.metaeffekt.core:ae-security from 0.157.0 to 0.157.1 by @dependabot[bot] in #7426
- Bump org.codehaus.mojo:build-helper-maven-plugin from 3.6.1 to 3.6.2 by @dependabot[bot] in #7428
- Bump io.dropwizard.flywaydb:flyway-bom from 13.6.0 to 13.7.0 by @dependabot[bot] in #7438
- Bump com.github.luben:zstd-jni from 1.5.7-16 to 1.5.7-17 by @dependabot[bot] in #7437
- Bump io.smallrye.config:smallrye-config-bom from 3.18.3 to 4.0.0 by @dependabot[bot] in #7455
- Bump lib.protobuf-java.version from 4.36.1 to 4.36.2 by @dependabot[bot] in #7454
- Bump the codeql group with 2 updates by @dependabot[bot] in #7469
- Bump docker/build-push-action from 7.3.0 to 7.4.0 by @dependabot[bot] in #7470
- Bump docker/setup-qemu-action from 4.3.0 to 4.4.0 by @dependabot[bot] in #7471
- Bump oasdiff/oasdiff-action/breaking from 0.1.16 to 0.1.17 by @dependabot[bot] in #7472
- Bump docker/setup-buildx-action from 4.3.0 to 4.4.1 by @dependabot[bot] in #7473
- Bump com.adobe.testing:s3mock-testcontainers from 5.2.2 to 5.2.3 by @dependabot[bot] in #7474
- Bump com.github.luben:zstd-jni from 1.5.7-17 to 1.5.7-18 by @dependabot[bot] in #7477
- Bump com.github.ben-manes.caffeine:caffeine from 3.2.4 to 3.3.0 by @dependabot[bot] in #7478
- Bump io.github.ascopes:protobuf-maven-plugin from 5.1.9 to 5.1.10 by @dependabot[bot] in #7479
- Bump com.icegreen:greenmail-junit5 from 2.1.13 to 2.1.14 by @dependabot[bot] in #7482
- Bump tools.jackson:jackson-bom from 3.2.2 to 3.2.3 by @dependabot[bot] in #7504
- Bump org.eclipse.microprofile.config:microprofile-config-api from 3.1.1 to 3.1.2 by @dependabot[bot] in #7506
- Bump com.fasterxml.jackson:jackson-bom from 2.22.2 to 2.22.3 by @dependabot[bot] in #7505
- Bump versatile to 0.26.0 by @nscuro in #7515
- Bump org.slf4j:slf4j-nop from 1.7.36 to 2.0.20 by @dependabot[bot] in #7518
- Bump com.github.luben:zstd-jni from 1.5.7-18 to 1.5.7-19 by @dependabot[bot] in #7521
- Bump org.slf4j:slf4j-bom from 2.0.19 to 2.0.20 by @dependabot[bot] in #7522
- Bump org.mockito:mockito-bom from 5.23.0 to 5.24.0 by @dependabot[bot] in #7530
- Bump org.metaeffekt.core:ae-security from 0.157.1 to 0.157.2 by @dependabot[bot] in #7528
- Bump lib.logback.version from 1.6.3 to 1.6.4 by @dependabot[bot] in #7534
- Bump io.dropwizard.flywaydb:flyway-bom from 13.7.0 to 13.8.0 by @dependabot[bot] in #7535
- Bump com.github.luben:zstd-jni from 1.5.7-19 to 1.5.7-20 by @dependabot[bot] in #7537
- Bump com.uber.nullaway:nullaway from 0.14.1 to 0.14.2 by @dependabot[bot] in #7536
- Bump the codeql group with 2 updates by @dependabot[bot] in #7567
- Bump com.diffplug.spotless:spotless-maven-plugin from 3.10.2 to 3.10.3 by @dependabot[bot] in #7568
- Bump org.apache.commons:commons-lang3 from 3.20.0 to 3.21.0 by @dependabot[bot] in #7573
- Bump com.tngtech.archunit:archunit-junit5 from 1.5.0 to 1.5.1 by @dependabot[bot] in #7569
- Bump org.jdbi:jdbi3-bom from 3.54.0 to 3.55.0 by @dependabot[bot] in #7571
- Bump eclipse-temurin from 25.0.4_7-jdk-alpine to 25.0.4.1_1-jdk-alpine in /apiserver/src/main/docker by @dependabot[bot] in #7588
- Bump com.fasterxml.woodstox:woodstox-core from 7.2.2 to 7.3.0 by @dependabot[bot] in #7600
- Bump com.google.guava:guava from 33.7.1-jre to 33.7.2-jre by @dependabot[bot] in #7612
- Bump io.github.ascopes:protobuf-maven-plugin from 5.1.10 to 5.1.11 by @dependabot[bot] in #7620
- Bump lib.logback.version from 1.6.4 to 1.6.5 by @dependabot[bot] in #7619
Documentation 📃
- Update repository docs by @nscuro in #7162
- Add ADR for policy violation messages by @fffinkel in #7322
- Make description of Snyk's checksumMatchingEnabled less verbose by @nscuro in #7606
- Tweak docs of allowed destinations property by @nscuro in #7611
Other Changes
- Decouple API v1 DELETE endpoints from JDO models by @nscuro in #7148
- Decouple more API v1 endpoints from JDO models by @nscuro in #7149
- Fix broken clean-build-cache make target by @nscuro in #7160
- Remove JDO from auth path by @nscuro in #7168
- Switch Alpine tests to Postgres and remove H2 by @nscuro in #7169
- Address zizmor findings by @nscuro in #7193
- Remove ServiceRegistry from plugin API by @nscuro in #7255
- Relocate analyzer_identity notification field by @nscuro in #7279
- Dogfood API v2 OpenAPI spec for e2e tests by @nscuro in #7287
- Reduce noise of e2e test log output by @nscuro in #7288
- Drop deprecated AFFECTEDVERSIONATTRIBUTION.LAST_SEEN column by @nscuro in #7349
- Cleanup dead code by @nscuro in #7383
- Enable default ERROR-level ErrorProne checks and fix issues by @nscuro in #7457
- Improve effectiveness of caching in CI by @nscuro in #7458
- Promote various Error Prone checks to ERROR by @nscuro in #7459
- Expand CompileTimeConstant annotation usage by @nscuro in #7460
- Enable JDBI to interface with JDO transactions by @nscuro in #7461
- Remove duplicated or unused JDO cruft by @nscuro in #7462
- Migrate config property reads from JDO to JDBI by @nscuro in #7463
- Remove redundant JDO VulnerableSoftware sync logic by @nscuro in #7464
- Migrate more code from JDO to JDBI by @nscuro in #7465
- Co-locate persistence code with its feature packages by @nscuro in #7498
- Disable caching in docker/setup-qemu-action by @nscuro in #7525
- Add regression test for Go pseudo version range matching by @nscuro in #7548
- Add shell script for backport skill by @nscuro in #7549
- Ignore major version bumps of eclipse-temurin image by @nscuro in #7587
New Contributors
- @adityaanikam made their first contribution in #7262
- @adilalperenciftci made their first contribution in #7323
- @Akhil-1527 made their first contribution in #7467
Full Changelog: 5.1.0...5.2.0