Dependency-Track
Continuous SBOM analysis platform for software supply chain risk
A v5 release candidate train carrying a database migrator that has to work on the first try.
◆Recent moves
- 2mo ago
Dependency-Track 5.0.0-rc.5 adds hash mismatch policy conditions
Extends the policy engine with component hash mismatch conditions and exposes latest-version publish timestamps to CEL, giving policies a time dimension they lacked. The migrator gains completion logs and row-count diff annotations in its verify phase — instrumentation for an operation users only get to run once.
View source ↗ - 2mo ago
Dependency-Track 5.0.0-rc.4 caps uncompressed repository responses
Tunes latest-version detection per ecosystem — Cargo, Ruby Gems, and Maven now preferring stable releases over prereleases — and enforces separate limits on compressed and uncompressed repository responses, a decompression-bomb defense. Also fixes ineffective assignment of random BOM refs during import.
View source ↗ - 2mo ago
Dependency-Track 5.0.0-rc.3 bumps CycloneDX proto to 1.7.1
Bumps the CycloneDX proto to v1.7.1 and clears six migrator defects, including cross-schema type dependencies and an overly strict schema name validation. The density of migrator fixes across consecutive candidates shows where the risk in this major version sits.
View source ↗ - 2mo ago
Dependency-Track 5.0.0-rc.2 drops the legacy alpine.* config shim
Drops the shim that translated v4-era alpine.* and unprefixed configuration properties into their dt.* equivalents, and makes the API server refuse to start when it finds a legacy key rather than starting misconfigured. A deliberate hard failure chosen over a silent one.
View source ↗