4.14.5
·
4 commits
to 4.14.x
since this release
Immutable
release. Only release title and notes can be modified.
For official releases, refer to Dependency Track Docs >> Changelogs for information about improvements and upgrade notes.
If additional details are required, consult the closed issues for this release milestone.
# SHA1
16d73175e293a807409c621bf39bac1e1aaa9c2b dependency-track-apiserver.jar
de0b87dbe7bb23d2d9bfd587ce56514820c35ded dependency-track-bundled.jar
# SHA256
50f698fa06078f800b6ca626c05ce6190efcbadecc88d03b0d80a6e144f60055 dependency-track-apiserver.jar
9c1153fbb98b224a171121e0447abe20f085160a19445f82d36a77cd60b34733 dependency-track-bundled.jar
# SHA512
c81a3f192a92f8bebe3fe458ed140991acfc1937cda358151f5d89f82a3feedc2e334bdb537da3db603fec8dbc1d37879a20885520ff0ee96eb341d55ccb8b7e dependency-track-apiserver.jar
c93a4a507fec4d6201c071ef0fdf655dc4819ed9a173ca737ab925ec238dd07ffab28237515cd0561e74d0630678a3dcc5267842051a07cc61388912d89007c1 dependency-track-bundled.jar
What's Changed
Bug Fixes 🐛
- Fix portfolio vulnerability analysis cache eviction by @mikael-carneholm-2-wcar in #7448
- Backport: Prevent NPEs during DataNucleus L1 cache eviction by @nscuro in #7499
- Fix NEW_VULNERABLE_DEPENDENCY notifications not including project tags by @nscuro in #7500
- Backport: PEP 503-normalize PyPI package names for vuln matching by @nscuro in #7564
- Backport: Treat NuGet package names as case-insensitive for vuln matching by @nscuro in #7565
- Backport: Fix Trivy findings dropped for PURLs with URL-valued qualifiers by @nscuro in #7592
- Backport: Fix OS package scanning for Trivy analyzer by @nscuro in #7593
Dependency Updates 🤖
- Bump alpine from 3.24.1 to 3.24.2 in /src/main/docker by @dependabot[bot] in #7338
- Bump eclipse-temurin from
20a695etoabed22bin /src/main/docker by @dependabot[bot] in #7339 - Bump com.microsoft.sqlserver:mssql-jdbc from 13.4.0.jre11 to 13.6.0.jre11 by @dependabot[bot] in #7340
- Bump io.github.nscuro:versatile-core from 0.24.0 to 0.25.0 by @dependabot[bot] in #7397
- Bump io.github.ascopes:protobuf-maven-plugin from 5.1.8 to 5.1.9 by @dependabot[bot] in #7398
- Bump actions/setup-java from 6.0.0 to 6.0.1 by @dependabot[bot] in #7399
- Bump io.github.jeremylong:open-vulnerability-clients from 9.0.6 to 9.0.7 by @dependabot[bot] in #7400
- Bump org.codehaus.mojo:exec-maven-plugin from 3.6.3 to 3.6.4 by @dependabot[bot] in #7401
- Bump org.metaeffekt.core:ae-security from 0.157.0 to 0.157.1 by @dependabot[bot] in #7427
- Bump lib.protobuf-java.version from 4.36.1 to 4.36.2 by @dependabot[bot] in #7453
- Bump debian from
0463431to5bc3287in /src/main/docker by @dependabot[bot] in #7475 - Bump alpine from
31b6477to294b683in /src/main/docker by @dependabot[bot] in #7476 - Bump docker/setup-buildx-action from 4.3.0 to 4.4.1 by @dependabot[bot] in #7480
- Bump com.icegreen:greenmail-junit5 from 2.1.13 to 2.1.14 by @dependabot[bot] in #7481
- Bump docker/build-push-action from 7.3.0 to 7.4.0 by @dependabot[bot] in #7483
- Bump io.github.ascopes:protobuf-maven-plugin from 5.1.9 to 5.1.10 by @dependabot[bot] in #7484
- Bump docker/setup-qemu-action from 4.3.0 to 4.4.0 by @dependabot[bot] in #7485
- Bump org.slf4j:log4j-over-slf4j from 2.0.19 to 2.0.20 by @dependabot[bot] in #7517
- Bump org.metaeffekt.core:ae-security from 0.157.1 to 0.157.2 by @dependabot[bot] in #7529
- Backport: Bump versatile to 0.26.0 by @nscuro in #7563
- Bump eclipse-temurin from 25.0.4_7-jdk-alpine to 25.0.4.1_1-jdk-alpine in /src/main/docker by @dependabot[bot] in #7570
- Bump org.apache.maven:maven-artifact from 3.9.16 to 3.10.0 by @dependabot[bot] in #7574
- Bump bundled frontend to 4.14.5 by @nscuro in #7595
Other Changes
Full Changelog: 4.14.4...4.14.5