OWASP Dependency-Track v5.2.0 released
By SecBurg
OWASP Dependency-Track is an open source platform that analyzes the components in your SBOMs for known vulnerabilities.
Version 5.2.0 is a feature release. After the bugfixes in https://secburg.com/posts/dependency-track-v512-released/, this one brings some new functionality. Highlights include:
Service accounts, API key expiry and workload identity federation
Webhook payloads signed with HMAC-SHA256
New outbound connection policy for the shared HTTP client, also exposed to plugins
Maximum size for BOM and VEX uploads
Trivy API token is now optional, Snyk supports checksum matching
Cargo metadata resolver uses the sparse index
Fixes for NVD, OSV and GitHub Advisories data sources
Fewer N+1 queries and better query plans (dependency graph, component metrics, findings)
Matching fixes: PyPI names via PEP 503, case-insensitive NuGet names, >=0 version ranges as wildcards
CVSSv4 scores now consider more than just base metrics
Pagination for /v1/vulnerability/component/{uuid}
The release notes also list persistence changes from JDO to JDBI and further smaller fixes, so check the full list.
As usual, the project notes to read the upgrade notes before upgrading your instance.
Full changelog and release notes: GitHub releases
Happy tracking! :-)