OWASP Dependency-Track v5.1.1 released
By SecBurg
OWASP Dependency-Track continuously monitors SBOMs for known vulnerabilities, helping organizations track and reduce risk across their software supply chain.
Version 5.1.1 is a patch release backporting fixes from the next branch. Highlights include:
Fix for PURLs without version being submitted for analysis
Fix for DATASOURCE_MIRRORING notifications not being emitted
Fix for project lookup endpoints not serving aggregate metrics for collection projects
Fix for calculated CVSSv4 score only considering base metrics
Fix for Checkmarx model conversion NPEs
Fix for proxy authentication for the GitHub Advisories vulnerability data source
Fix for NVD vulnerability data source iteration and watermarking issues
Fix for management server preventing shutdown on initialization failures
v4-migrator fixes for collapsed project PROJECT_PROPERTY rows and tag reconciliation
Treat `>=0` ranges as wildcard during vers matching
As usual, the project notes to read the upgrade notes before upgrading your instance.
Full changelog and release notes: GitHub releases
Happy tracking! :-)