Skip to content

Latest commit

 

History

History
65 lines (45 loc) · 2.48 KB

2023-xx-xx-v4.10.0.md

File metadata and controls

65 lines (45 loc) · 2.48 KB
title type
v4.10.0
major

Features:

  • Add support for mirroring the NVD via its REST API - apiserver/#3175
    • Refer to the [NVD datasource documentation] for details
  • Improve efficiency of search index operations - apiserver/#3116
  • Add option to emit log for successfully published notifications, and improve logging around notifications in general - apiserver/#3211

Fixes:

  • Fix false positives in CPE matching due to ambiguous vendor-product relations - apiserver/#3209

Upgrade Notes:

  • The CPE table is no longer needed and will be dropped automatically upon upgrade - apiserver/#3117
  • A warning will be logged when mirroring the NVD through its legacy data feeds
    • Refer to the [NVD datasource documentation] to learn how to switch to API-based mirroring

For a complete list of changes, refer to the respective GitHub milestones:

We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub & Slack to testing of fixes.

Special thanks to everyone who contributed code to implement enhancements and fix defects:
TBD

dependency-track-apiserver.jar
Algorithm Checksum
SHA-1
SHA-256
dependency-track-bundled.jar
Algorithm Checksum
SHA-1
SHA-256
frontend-dist.zip
Algorithm Checksum
SHA-1
SHA-256
Software Bill of Materials (SBOM)

[NVD datasource documentation]: {{ site.baseurl }}{% link _docs/datasources/nvd.md %}#mirroring-via-nvd-rest-api