OWASP Dependency-Track v5.1.0 released
By SecBurg
OWASP Dependency-Track continuously monitors SBOMs for known vulnerabilities, helping organizations track and reduce risk across their software supply chain.
Version 5.1.0 is a major release with over 60 enhancements and around 50 bug fixes. Highlights include:
Support for CycloneDX 1.7
KEV (Known Exploited Vulnerabilities) implementation and integration
New JVN (Japan Vulnerability Notes) data source
New Checkmarx SCA vulnerability analyser
Support for compressed SBOMs in multipart uploads
GitHub App authentication for the GitHub Advisories mirror
LDAP authentication NPE fix
Fix for suppressed vulnerabilities being wrongly considered in policy evaluation
OSV ecosystem name URL-encoding corrections
The release also ships over 100 dependency updates (Jackson, Flyway, Jetty and others) and several architectural decision records. The project notes to read the upgrade notes before upgrading your instance.
Full changelog and release notes: GitHub releases
Happy hacking! :-)