OWASP Dependency-Track v5.1.2 released
By SecBurg
OWASP Dependency-Track is a component analysis platform that ingests SBOMs and flags known vulnerabilities in your software supply chain.
Version 5.1.2 is another bugfix release. Highlights include:
Fix for invalid PURLs breaking list API endpoints
Fix for CPE matching with wildcard versions and ranges starting at >=0
Fix for deletion of internal vulnerabilities with finding attributions
Fix for PyPI package name matching via PEP 503 normalization
Fix for manually assigned findings being deactivated during analysis
Fix for NuGet package names being matched case-sensitively
Fix for Trivy findings being dropped for PURLs with URL-valued qualifiers
As usual, the project notes to read the upgrade notes before upgrading your instance.
Full changelog and release notes: GitHub releases
Happy tracking! :-)