<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://docs.dependencytrack.org/feed.xml" rel="self" type="application/atom+xml" /><link href="https://docs.dependencytrack.org/" rel="alternate" type="text/html" /><updated>2026-04-21T11:14:46+00:00</updated><id>https://docs.dependencytrack.org/feed.xml</id><title type="html">Dependency-Track</title><subtitle>Product documentation</subtitle><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><entry><title type="html">v4.14.1</title><link href="https://docs.dependencytrack.org/2026/04/03/v4.14.1/" rel="alternate" type="text/html" title="v4.14.1" /><published>2026-04-03T00:00:00+00:00</published><updated>2026-04-03T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2026/04/03/v4.14.1</id><content type="html" xml:base="https://docs.dependencytrack.org/2026/04/03/v4.14.1/"><![CDATA[<p><strong>Features:</strong></p>

<ul>
  <li>Add support for NuGet versioning scheme - <a href="https://github.com/DependencyTrack/dependency-track/pull/5958">apiserver/#5958</a></li>
  <li>Add support for Composer versioning scheme - <a href="https://github.com/DependencyTrack/dependency-track/pull/5963">apiserver/#5963</a></li>
  <li>Document age and version distance operational policy criteria - <a href="https://github.com/DependencyTrack/dependency-track/pull/5964">apiserver/#5964</a></li>
  <li>Use ecosystem-aware version comparison for latest version detection - <a href="https://github.com/DependencyTrack/dependency-track/pull/5995">apiserver/#5995</a></li>
  <li>Support Sonatype Guide tokens for OSS Index analyzer - <a href="https://github.com/DependencyTrack/dependency-track/pull/5996">apiserver/#5996</a></li>
  <li>Improve Chinese translations - <a href="https://github.com/DependencyTrack/frontend/pull/1490">frontend/#1490</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix PURL-specific version matching being bypassed for components with CPE - <a href="https://github.com/DependencyTrack/dependency-track/pull/5959">apiserver/#5959</a></li>
  <li>Fix wasteful existence queries - <a href="https://github.com/DependencyTrack/dependency-track/pull/5960">apiserver/#5960</a></li>
  <li>Fix potentially wrong version being used for CPE comparison - <a href="https://github.com/DependencyTrack/dependency-track/pull/5962">apiserver/#5962</a></li>
  <li>Fix scheduled notification query failing when ID columns are not of type BIGINT - <a href="https://github.com/DependencyTrack/dependency-track/pull/5979">apiserver/#5979</a></li>
  <li>Avoid NPE when computing Trivy pkgType - <a href="https://github.com/DependencyTrack/dependency-track/pull/5987">apiserver/#5987</a></li>
  <li>Remove leading whitespace from vulnerability badge SVG template - <a href="https://github.com/DependencyTrack/dependency-track/pull/6000">apiserver/#6000</a></li>
  <li>Fix Japanese Trivy analyzer strings - <a href="https://github.com/DependencyTrack/frontend/pull/1489">frontend/#1489</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/50?closed=1">API server milestone 4.14.1</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/35?closed=1">Frontend milestone 4.14.1</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<p>Special thanks to everyone who contributed code to implement enhancements and fix defects:</p>

<p><a href="https://github.com/Zureno">@Zureno</a>, <a href="https://github.com/jonbally">@jonbally</a>, <a href="https://github.com/retanoj">@retanoj</a>, <a href="https://github.com/shayFoo">@shayFoo</a>, <a href="https://github.com/stohrendorf">@stohrendorf</a></p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">750b0c768208d7c6b7e32e8f1a7500eb94788069</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">142bdfa36defffc2304d03f9ef7ecd162f1185dcbc00933a73529cac7f12980c</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">61eac5828458dfea46507c26f3384bb452ebeefe</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">6cedc727a3f8eb2343397e50a1b5515a99c2a361b7c55aa60dbeff85c1f4af2d</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">a08b4280aad4e9946908ca6fd05e1fbc0ad0f1af</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">e13d9b729d2082fcfb440bc1deb6f373290d1ead414447d8834368b4dbceec27</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.14.1/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.14.1/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Features:]]></summary></entry><entry><title type="html">v4.14.0</title><link href="https://docs.dependencytrack.org/2026/03/09/v4.14.0/" rel="alternate" type="text/html" title="v4.14.0" /><published>2026-03-09T00:00:00+00:00</published><updated>2026-03-09T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2026/03/09/v4.14.0</id><content type="html" xml:base="https://docs.dependencytrack.org/2026/03/09/v4.14.0/"><![CDATA[<p><strong>Highlights:</strong></p>

<ul>
  <li><strong>Ecosystem-aware version matching</strong>. Vulnerability analysis now uses version comparison algorithms
native to the component’s ecosystem, rather than relying on generic semantic versioning.
For example, Debian versions are compared using the <a href="https://manpages.debian.org/stretch/dpkg-dev/deb-version.5.en.html#Sorting_algorithm">dpkg sorting algorithm</a>.
Supported ecosystems are Alpine Linux, Debian, Go, Maven, NPM, PyPI, and RPM.</li>
  <li><strong>Distro-aware vulnerability matching</strong>. Linux distributions like Debian backport security fixes
to older releases, meaning a component may be vulnerable in one distro release but not another.
Dependency-Track now uses the <code class="language-plaintext highlighter-rouge">distro</code> qualifier of package URLs (e.g.,
<code class="language-plaintext highlighter-rouge">pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?distro=debian-13.3</code>) to determine the OS release
and match vulnerabilities accordingly. Currently supported for Alpine Linux, Debian, and Ubuntu.
    <ul>
      <li><strong>Note</strong>: Requires vulnerability data from OSV, as the NVD does not contextualize
version ranges by OS release. Not all BOM generators populate the <code class="language-plaintext highlighter-rouge">distro</code> PURL qualifier today.</li>
    </ul>
  </li>
  <li><strong>CVSSv4 support</strong>. Upstream vulnerability sources are increasingly publishing CVSSv4 scores.
Dependency-Track now ingests and displays CVSSv4 vectors and derived severities alongside existing
CVSSv2 and CVSSv3 data.</li>
</ul>

<p><strong>Features:</strong></p>

<ul>
  <li>Include project UUID in log messages - <a href="https://github.com/DependencyTrack/dependency-track/pull/5500">apiserver/#5500</a></li>
  <li>Add support for incremental mirroring of OSV - <a href="https://github.com/DependencyTrack/dependency-track/pull/5537">apiserver/#5537</a></li>
  <li>Add internal status policy condition support - <a href="https://github.com/DependencyTrack/dependency-track/pull/5570">apiserver/#5570</a></li>
  <li>Implement VERS approach for PURL version matching - <a href="https://github.com/DependencyTrack/dependency-track/pull/5591">apiserver/#5591</a></li>
  <li>Add projectUuid via MDC to logger statements within VEX upload - <a href="https://github.com/DependencyTrack/dependency-track/pull/5615">apiserver/#5615</a></li>
  <li>Specify newer version of Docker Compose in README - <a href="https://github.com/DependencyTrack/dependency-track/pull/5648">apiserver/#5648</a></li>
  <li>Add configurable base URL for OSS Index API - <a href="https://github.com/DependencyTrack/dependency-track/pull/5736">apiserver/#5736</a></li>
  <li>Update OSS Index documentation - <a href="https://github.com/DependencyTrack/dependency-track/pull/5774">apiserver/#5774</a></li>
  <li>Improve efficiency and caching behaviour of OSS Index analyzer - <a href="https://github.com/DependencyTrack/dependency-track/pull/5793">apiserver/#5793</a></li>
  <li>Switch to G1GC and limit default Docker Compose memory to 4GB - <a href="https://github.com/DependencyTrack/dependency-track/pull/5794">apiserver/#5794</a></li>
  <li>Add EPSS score support for GitHub Advisory vulnerabilities - <a href="https://github.com/DependencyTrack/dependency-track/pull/5829">apiserver/#5829</a></li>
  <li>Add page on users and permissions to documentation - <a href="https://github.com/DependencyTrack/dependency-track/pull/5831">apiserver/#5831</a></li>
  <li>Include CVSS vectors and metadata in Finding model - <a href="https://github.com/DependencyTrack/dependency-track/pull/5844">apiserver/#5844</a></li>
  <li>Tweak vulnerability persistence logic - <a href="https://github.com/DependencyTrack/dependency-track/pull/5862">apiserver/#5862</a></li>
  <li>Add CVSSv4 support - <a href="https://github.com/DependencyTrack/dependency-track/pull/5863">apiserver/#5863</a></li>
  <li>Delete NVD feed timestamp files during v4.14.0 upgrade - <a href="https://github.com/DependencyTrack/dependency-track/pull/5886">apiserver/#5886</a></li>
  <li>Bump SPDX license list to v3.28.0 - <a href="https://github.com/DependencyTrack/dependency-track/pull/5888">apiserver/#5888</a></li>
  <li>Bump CWE dictionary to v4.19.1 - <a href="https://github.com/DependencyTrack/dependency-track/pull/5889">apiserver/#5889</a></li>
  <li>Make username optional for Repositories Bearer Auth - <a href="https://github.com/DependencyTrack/frontend/pull/1128">frontend/#1128</a></li>
  <li>Improve German Translation - <a href="https://github.com/DependencyTrack/frontend/pull/1227">frontend/#1227</a></li>
  <li>Add suffix to vulnerability locale keys - <a href="https://github.com/DependencyTrack/frontend/pull/1276">frontend/#1276</a></li>
  <li>Add match mode selector to internal component config - <a href="https://github.com/DependencyTrack/frontend/pull/1283">frontend/#1283</a></li>
  <li>Display license ID - <a href="https://github.com/DependencyTrack/frontend/pull/1311">frontend/#1311</a></li>
  <li>Support for scope mentioned in CycloneDX format - <a href="https://github.com/DependencyTrack/frontend/pull/1319">frontend/#1319</a></li>
  <li>Add support for IS_INTERNAL policy condition - <a href="https://github.com/DependencyTrack/frontend/pull/1394">frontend/#1394</a></li>
  <li>Add Traditional Chinese (zh-TW) language support - <a href="https://github.com/DependencyTrack/frontend/pull/1412">frontend/#1412</a></li>
  <li>Remove database information from About dialogue - <a href="https://github.com/DependencyTrack/frontend/pull/1421">frontend/#1421</a></li>
  <li>Add OSS Index Base URL configuration field - <a href="https://github.com/DependencyTrack/frontend/pull/1431">frontend/#1431</a></li>
  <li>Add CVSSv4 support - <a href="https://github.com/DependencyTrack/frontend/pull/1455">frontend/#1455</a></li>
  <li>Add missing internal_status i18n key for zh-TW locale - <a href="https://github.com/DependencyTrack/frontend/pull/1456">frontend/#1456</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix sneaky double quote - <a href="https://github.com/DependencyTrack/dependency-track/pull/5420">apiserver/#5420</a></li>
  <li>Fix incorrect UTF-8 encoding in notification payload - <a href="https://github.com/DependencyTrack/dependency-track/pull/5574">apiserver/#5574</a></li>
  <li>Fix excessive memory usage of Nix analyzer - <a href="https://github.com/DependencyTrack/dependency-track/pull/5653">apiserver/#5653</a></li>
  <li>Fix wrong NPM component coordinate separator for Trivy analysis - <a href="https://github.com/DependencyTrack/dependency-track/pull/5679">apiserver/#5679</a></li>
  <li>Fix performance issue with PURL lookups - <a href="https://github.com/DependencyTrack/dependency-track/pull/5711">apiserver/#5711</a></li>
  <li>Fall back to generic versioning scheme if no PURL is available - <a href="https://github.com/DependencyTrack/dependency-track/pull/5714">apiserver/#5714</a></li>
  <li>Fix incorrect URL for VulnDB analyzer - <a href="https://github.com/DependencyTrack/dependency-track/pull/5751">apiserver/#5751</a></li>
  <li>Ensure container zombie processes are reaped - <a href="https://github.com/DependencyTrack/dependency-track/pull/5758">apiserver/#5758</a></li>
  <li>Fix singleton events not being labelled as such - <a href="https://github.com/DependencyTrack/dependency-track/pull/5775">apiserver/#5775</a></li>
  <li>Consider OS distro during vulnerability matching - <a href="https://github.com/DependencyTrack/dependency-track/pull/5783">apiserver/#5783</a></li>
  <li>Fix re-initialization of teams when opening create-modal - <a href="https://github.com/DependencyTrack/frontend/pull/1410">frontend/#1410</a></li>
</ul>

<p><strong>Upgrade Notes:</strong></p>

<ul>
  <li>To backfill CVSSv4 and EPSS data, mirror watermarks for NVD and GitHub Advisories will be reset,                                                                                                    <br />
triggering a full re-mirror on next invocation.</li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/49?closed=1">API server milestone 4.14.0</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/34?closed=1">Frontend milestone 4.14.0</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<p>Special thanks to everyone who contributed code to implement enhancements and fix defects:</p>

<p><a href="https://github.com/anantk24">@anantk24</a>, <a href="https://github.com/AndreVirtimo">@AndreVirtimo</a>, <a href="https://github.com/arjavdongaonkar">@arjavdongaonkar</a>, <a href="https://github.com/brianf">@brianf</a>, <a href="https://github.com/ch8matt">@ch8matt</a>, <a href="https://github.com/ElenaStroebele">@ElenaStroebele</a>,
<a href="https://github.com/fupgang">@fupgang</a>, <a href="https://github.com/Granjow">@Granjow</a>, <a href="https://github.com/jonbally">@jonbally</a>, <a href="https://github.com/jvirgovic">@jvirgovic</a>, <a href="https://github.com/setchy">@setchy</a>, <a href="https://github.com/snieguu">@snieguu</a>, <a href="https://github.com/stohrendorf">@stohrendorf</a>,
<a href="https://github.com/tobiasgies">@tobiasgies</a>, <a href="https://github.com/valentijnscholten">@valentijnscholten</a>, <a href="https://github.com/WoozyMasta">@WoozyMasta</a>, <a href="https://github.com/wengct">@wengct</a></p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">a06d7f57876befc80b6653fcc44b321958388f12</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">2e3d5bcfb7b5d4ad4daf789bc5ca3802ef05d012c516090e8bc5323f46585f53</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">6573a4522dd84520859ab951d86d8a9e4dd43fb2</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">a8edd7c94ba811bae73d9213d769687c493e1bd95435dbe39dfeee28ff1f8008</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">8a822e22c6c087b0e46f9478f9b342d2e2bad162</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">9a96be982a80c6c8714ad8d22a932d013a6b3593744083d551a7fb2b4a281aa3</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.14.0/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.14.0/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Highlights:]]></summary></entry><entry><title type="html">v4.13.6</title><link href="https://docs.dependencytrack.org/2025/11/17/v4.13.6/" rel="alternate" type="text/html" title="v4.13.6" /><published>2025-11-17T00:00:00+00:00</published><updated>2025-11-17T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2025/11/17/v4.13.6</id><content type="html" xml:base="https://docs.dependencytrack.org/2025/11/17/v4.13.6/"><![CDATA[<p>Starting with this release, we’re publishing a new container image variant for the
<em>apiserver</em> and <em>bundled</em> distributions. The variant is based on <a href="https://www.alpinelinux.org/">Alpine Linux</a> and uses
<a href="https://dev.java/learn/jlink/">jlink</a> to ship a minimal Java Runtime Environment (JRE). As a result, image size is decreased
by over 55% (~350MB vs. ~150MB uncompressed), and attack surface is reduced due to fewer
operating system packages. It uses Java 25 and enables <a href="https://openjdk.org/jeps/519">compact object headers</a> by default,
leading to lower memory footprint.</p>

<p>To use the new image variant, append the <code class="language-plaintext highlighter-rouge">-alpine</code> suffix to the image tag, e.g.:</p>

<ul>
  <li><code class="language-plaintext highlighter-rouge">docker.io/dependencytrack/apiserver:latest-alpine</code></li>
  <li><code class="language-plaintext highlighter-rouge">docker.io/dependencytrack/bundled:4.13.6-alpine</code></li>
</ul>

<p>The previous Debian-based image variant continues to be the default for now,
but will eventually be discontinued in a future release. Users experiencing
issues with <code class="language-plaintext highlighter-rouge">alpine</code> images can safely fall back to non-<code class="language-plaintext highlighter-rouge">alpine</code> variants.</p>

<p><strong>Features:</strong></p>

<ul>
  <li>Add Alpine-based container variants - <a href="https://github.com/DependencyTrack/dependency-track/pull/5533">apiserver/#5533</a></li>
  <li>Update Ukrainian translation - <a href="https://github.com/DependencyTrack/frontend/pull/1385">frontend/#1385</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Improve performance of database migration to v4.13.5 - <a href="https://github.com/DependencyTrack/dependency-track/pull/5419">apiserver/#5419</a></li>
  <li>Ignore stale Lucene index entries - <a href="https://github.com/DependencyTrack/dependency-track/pull/5428">apiserver/#5428</a></li>
  <li>Fix typo in email notification template - <a href="https://github.com/DependencyTrack/dependency-track/pull/5434">apiserver/#5434</a></li>
  <li>Fix referential integrity violation during bulk project deletion - <a href="https://github.com/DependencyTrack/dependency-track/pull/5446">apiserver/#5446</a></li>
  <li>Fix referential integrity violation during team deletion - <a href="https://github.com/DependencyTrack/dependency-track/pull/5447">apiserver/#5447</a></li>
  <li>Fix NPE in Composer component metadata analyzer - <a href="https://github.com/DependencyTrack/dependency-track/pull/5519">apiserver/#5519</a></li>
  <li>Fix XML External Entity injection via validation of CycloneDX BOMs in XML format - <a href="https://github.com/DependencyTrack/dependency-track/pull/5528">apiserver/#5528</a> / <a href="https://github.com/DependencyTrack/dependency-track/security/advisories/GHSA-93r8-3g93-w2gq">GHSA-93r8-3g93-w2gq</a></li>
  <li>Fix OSS Index documentation link - <a href="https://github.com/DependencyTrack/dependency-track/pull/5531">apiserver/#5531</a></li>
  <li>Change <code class="language-plaintext highlighter-rouge">toString()</code> method of <code class="language-plaintext highlighter-rouge">Project</code> to use name and version instead of PURL - <a href="https://github.com/DependencyTrack/dependency-track/pull/5532">apiserver/#5532</a></li>
  <li>Fix broken routing when <code class="language-plaintext highlighter-rouge">BASE_PATH</code> is configured - <a href="https://github.com/DependencyTrack/frontend/pull/1381">frontend/#1381</a></li>
  <li>Fix policy tag selection dialogue using the wrong REST API endpoint - <a href="https://github.com/DependencyTrack/frontend/pull/1382">frontend/#1382</a></li>
  <li>Fix persistent Cross-Site-Scripting via welcome message - <a href="https://github.com/DependencyTrack/frontend/pull/1383">frontend/#1383</a> / <a href="https://github.com/DependencyTrack/frontend/security/advisories/GHSA-7xvh-c266-cfr5">GHSA-7xvh-c266-cfr5</a></li>
  <li>Fix redirect loop when authenticated user is lacking permissions - <a href="https://github.com/DependencyTrack/frontend/pull/1386">frontend/#1386</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/60?closed=1">API server milestone 4.13.6</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/45?closed=1">Frontend milestone 4.13.6</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<p>Special thanks to everyone who contributed code to implement enhancements and fix defects:</p>

<p><a href="https://github.com/ElenaStroebele">@ElenaStroebele</a>, <a href="https://github.com/arjavdongaonkar">@arjavdongaonkar</a>, <a href="https://github.com/aurifi">@aurifi</a>, <a href="https://github.com/ch8matt">@ch8matt</a>, <a href="https://github.com/illenko">@illenko</a>, <a href="https://github.com/sahibamittal">@sahibamittal</a>, <a href="https://github.com/snieguu">@snieguu</a>, <a href="https://github.com/stohrendorf">@stohrendorf</a></p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">3964cf821761609912487077fa41d513dad37d1a</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">8f2aa10424403b2b201d0c48b243ea3bbe458761</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">1048a039391992fc36b23433d8987689baca33e68cc2130254787d1a3d1c66cc</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">ab47deb0c5be2d947d57cf5862fef714023b4ce4d794ac00a855cf7590eb111e</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">525b47c72fb3bdbb675b5c5414319e5f19e43b03</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">84440921692e95c88378e1f82738ccea24c2fb038083b42b3f1c98b1f6702a4a</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.13.6/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.13.6/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Starting with this release, we’re publishing a new container image variant for the apiserver and bundled distributions. The variant is based on Alpine Linux and uses jlink to ship a minimal Java Runtime Environment (JRE). As a result, image size is decreased by over 55% (~350MB vs. ~150MB uncompressed), and attack surface is reduced due to fewer operating system packages. It uses Java 25 and enables compact object headers by default, leading to lower memory footprint.]]></summary></entry><entry><title type="html">v4.13.5</title><link href="https://docs.dependencytrack.org/2025/10/07/v4.13.5/" rel="alternate" type="text/html" title="v4.13.5" /><published>2025-10-07T00:00:00+00:00</published><updated>2025-10-07T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2025/10/07/v4.13.5</id><content type="html" xml:base="https://docs.dependencytrack.org/2025/10/07/v4.13.5/"><![CDATA[<p><strong>Important Notice:</strong></p>

<p>Sonatype has started to enforce an authentication requirement for OSS Index.</p>

<p>The <a href="/datasources/ossindex/">OSS Index analyzer</a> has historically been enabled by default for Dependency-Track,
and configuration of credentials for authentication was not strictly necessary.</p>

<p>This has now changed, and users who wish to continue using OSS Index will
need to register for a free account, and configure credentials in the analyzer’s settings.</p>

<p>Please refer to <a href="https://ossindex.sonatype.org/doc/auth-required">Sonatype’s announcement</a> for further details.</p>

<p>In the midterm, we’ll be looking into enabling OSV per default
to compensate for this change.</p>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix CPE matching not being fully case-insensitive - <a href="https://github.com/DependencyTrack/dependency-track/pull/5299">apiserver/#5299</a></li>
  <li>Improve detection whether version of a github PURL is a commit SHA or release tag - <a href="https://github.com/DependencyTrack/dependency-track/pull/5350">apiserver/#5350</a></li>
  <li>Make OSS Index credentials required - <a href="https://github.com/DependencyTrack/dependency-track/pull/5351">apiserver/#5351</a></li>
  <li>Fix occasional NullPointerException when mirroring the NVD via REST API - <a href="https://github.com/DependencyTrack/dependency-track/pull/5352">apiserver/#5352</a></li>
  <li>Fix <code class="language-plaintext highlighter-rouge">/api/v1/tag/policy/{uuid}</code> endpoint returning more tags than are assigned to a policy - <a href="https://github.com/DependencyTrack/dependency-track/pull/5353">apiserver/#5353</a></li>
  <li>Fix possible failure of NVD mirroring due to corrupted timestamp files - <a href="https://github.com/DependencyTrack/dependency-track/pull/5354">apiserver/#5354</a></li>
  <li>Fix BOM validation failing due to unrecognized new SPDX license IDs - <a href="https://github.com/DependencyTrack/dependency-track/pull/5355">apiserver/#5355</a></li>
  <li>Fix new SPDX license IDs not being recognized - <a href="https://github.com/DependencyTrack/dependency-track/pull/5356">apiserver/#5356</a></li>
  <li>Fix high CPU utilization when watchdog logger is configured - <a href="https://github.com/DependencyTrack/dependency-track/pull/5357">apiserver/#5357</a></li>
  <li>Fix NullPointerException in GithubMetaAnalyzer when analyzing GitHub Actions - <a href="https://github.com/DependencyTrack/dependency-track/pull/5359">apiserver/#5359</a></li>
  <li>Fix connection reset during OSV mirroring - <a href="https://github.com/DependencyTrack/dependency-track/pull/5360">apiserver/#5360</a></li>
  <li>Fix compatibility of custom NuGet repositories with JFrog Artifactory - <a href="https://github.com/DependencyTrack/dependency-track/pull/5381">apiserver/#5381</a></li>
  <li>Fix custom NuGet repositories not working with Sonatype Nexus - <a href="https://github.com/DependencyTrack/dependency-track/pull/5381">apiserver/#5381</a></li>
  <li>Fix possible disclosure of private NuGet repository credentials to api.nuget.org - <a href="https://github.com/DependencyTrack/dependency-track/pull/5381">apiserver/#5381</a> / <a href="https://github.com/DependencyTrack/dependency-track/security/advisories/GHSA-83g2-vgqh-mgxc">GHSA-83g2-vgqh-mgxc</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/59?closed=1">API server milestone 4.13.5</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/44?closed=1">Frontend milestone 4.13.5</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<p>Special thanks to everyone who contributed code to implement enhancements and fix defects:</p>

<p><a href="https://github.com/colinfyfe">@colinfyfe</a>, <a href="https://github.com/framayo">@framayo</a>, <a href="https://github.com/jonbally">@jonbally</a>, <a href="https://github.com/snieguu">@snieguu</a>, <a href="https://github.com/stohrendorf">@stohrendorf</a></p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">f38abe7b93f7cb88f3bba4c78c30a9ce7dc45c0d</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">bf55097e63b46ed16042024636b855f676ba67e6e5824e7da80f3cec863a3f77</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">5aea8e0662f8aa4d9e53b52c14367c5345602e34</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">4a373de4d5aca924fb533ebfc7e1eb4fb5a249d81c948bd367a52fa53125a610</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">e441f28a656b710766a9fd85360872bc9330d14c</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">fb67bf767e2142b72dbd226b984a1faee9e491d108ccfd29860a49e0b5b15a12</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.13.5/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.13.5/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Important Notice:]]></summary></entry><entry><title type="html">v4.13.4</title><link href="https://docs.dependencytrack.org/2025/08/26/v4.13.4/" rel="alternate" type="text/html" title="v4.13.4" /><published>2025-08-26T00:00:00+00:00</published><updated>2025-08-26T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2025/08/26/v4.13.4</id><content type="html" xml:base="https://docs.dependencytrack.org/2025/08/26/v4.13.4/"><![CDATA[<p>This release primarily addresses the <a href="https://www.nist.gov/itl/nvd">removal of NVD 1.1 data feeds</a>, 
which caused Dependency-Track’s NVD mirroring process to fail. With this release, 
Dependency-Track will consume the new 2.0 data feeds.</p>

<p>Users who cannot perform this upgrade immediately can configure NVD mirroring to be performed via
the NVD REST API instead. Refer to the <a href="/datasources/nvd/#mirroring-via-nvd-rest-api">NVD datasource documentation</a> for details.</p>

<p><strong>Features:</strong></p>

<ul>
  <li>Migrate to NVD 2.0 data feeds - <a href="https://github.com/DependencyTrack/dependency-track/pull/5236">apiserver/#5236</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Handle URLs in composer package metadata pattern - <a href="https://github.com/DependencyTrack/dependency-track/pull/5234">apiserver/#5234</a></li>
  <li>Fix failing TrivyAnalysisTaskIntegrationTest - <a href="https://github.com/DependencyTrack/dependency-track/pull/5241">apiserver/#5241</a></li>
  <li>Handle <code class="language-plaintext highlighter-rouge">adduser</code> / <code class="language-plaintext highlighter-rouge">addgroup</code> removal in Debian base image - <a href="https://github.com/DependencyTrack/dependency-track/pull/5246">apiserver/#5246</a></li>
  <li>Fix inconsistent ordering in findings endpoints - <a href="https://github.com/DependencyTrack/dependency-track/pull/5247">apiserver/#5247</a></li>
  <li>Fix failing Trivy OS matching for distro versions with special characters - <a href="https://github.com/DependencyTrack/dependency-track/pull/5249">apiserver/#5249</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/58?closed=1">API server milestone 4.13.4</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/43?closed=1">Frontend milestone 4.13.4</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">048b46829358cfde1f4d90b9298984224c75f6ae</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">2ca674108a08bf71642ddec6704125fae720161c4c40268fd19557e8b116d9d0</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">b3eb198254783462dc7d147791537fa50b11483e</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">a8252f66f9b3c9253553e1d2a40fb0169f90c31895e36f57bc5992068ff473f5</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">827522ca8079450a8560a58a1b4e71add0a5d630</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">d0e604300d52047c32a98a51aa32e1cf2276525fa81557c4c95f1ad49f30d820</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.13.4/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.13.4/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[This release primarily addresses the removal of NVD 1.1 data feeds, which caused Dependency-Track’s NVD mirroring process to fail. With this release, Dependency-Track will consume the new 2.0 data feeds.]]></summary></entry><entry><title type="html">v4.13.3</title><link href="https://docs.dependencytrack.org/2025/08/04/v4.13.3/" rel="alternate" type="text/html" title="v4.13.3" /><published>2025-08-04T00:00:00+00:00</published><updated>2025-08-04T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2025/08/04/v4.13.3</id><content type="html" xml:base="https://docs.dependencytrack.org/2025/08/04/v4.13.3/"><![CDATA[<p><strong>Features:</strong></p>

<ul>
  <li>Add AWS Cognito configuration example - <a href="https://github.com/DependencyTrack/dependency-track/pull/5172">apiserver/#5172</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix too many query parameters when retrieving vuln aliases - <a href="https://github.com/DependencyTrack/dependency-track/pull/5167">apiserver/#5167</a></li>
  <li>Add apiserver health check to Compose files - <a href="https://github.com/DependencyTrack/dependency-track/pull/5171">apiserver/#5171</a></li>
  <li>Fix OSV ubuntu advisory containing severity without type - <a href="https://github.com/DependencyTrack/dependency-track/pull/5168">apiserver/#5168</a></li>
  <li>Handle dangling SPDX expression operators - <a href="https://github.com/DependencyTrack/dependency-track/pull/5173">apiserver/#5173</a></li>
  <li>Fix BOM export failing for projects of type NONE - <a href="https://github.com/DependencyTrack/dependency-track/pull/5178">apiserver/#5178</a></li>
  <li>Add whitespace sanitization in fuzzySearch CPE to fix CPE validation errors - <a href="https://github.com/DependencyTrack/dependency-track/pull/5176">apiserver/#5176</a></li>
  <li>Ensure VulnerableSoftware query is able to leverage indexes - <a href="https://github.com/DependencyTrack/dependency-track/pull/5177">apiserver/#5177</a></li>
  <li>Bulk load component relationships for BOM export - <a href="https://github.com/DependencyTrack/dependency-track/pull/5179">apiserver/#5179</a></li>
  <li>Improve Composer meta analyzer’s ability to deal with minified metadata - <a href="https://github.com/DependencyTrack/dependency-track/pull/5175">apiserver/#5175</a></li>
  <li>Fix failing v4.13.1 migration for H2 deployments that pre-date v4.11.0 - <a href="https://github.com/DependencyTrack/dependency-track/pull/5180">apiserver/#5180</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/57?closed=1">API server milestone 4.13.3</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/42?closed=1">Frontend milestone 4.13.3</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<p>Special thanks to everyone who contributed code to implement enhancements and fix defects:</p>

<p><a href="https://github.com/ch8matt">@ch8matt</a>, <a href="https://github.com/jonbally">@jonbally</a>, <a href="https://github.com/vdieieva">@vdieieva</a></p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">ba7866fa7b8be30f2058606ee77539b126ab61f1</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">8b6b2f29bdfd6f3e81ed2c9754a3ab2b4e27bbb9c33e52f720700d7e73558adb</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">70ac64f18c4b219d283df0c056e74f001287159b</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">1ae9984304854845cc5741d1dd1288e7b0a748539f448e0d0899ef635bb33c28</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">5eeea5e7bd1db7c40f45380580518eea7bdc53d7</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">f5bdf91803fb99b966f38be60b937adec96036b80bf7a793d32bb51b67f6fd7b</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.13.3/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.13.3/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Features:]]></summary></entry><entry><title type="html">v4.13.2</title><link href="https://docs.dependencytrack.org/2025/05/09/v4.13.2/" rel="alternate" type="text/html" title="v4.13.2" /><published>2025-05-09T00:00:00+00:00</published><updated>2025-05-09T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2025/05/09/v4.13.2</id><content type="html" xml:base="https://docs.dependencytrack.org/2025/05/09/v4.13.2/"><![CDATA[<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix failing v4.13.1 migration for MSSQL deployments that pre-date v4.11.0 - <a href="https://github.com/DependencyTrack/dependency-track/pull/4911">apiserver/#4911</a></li>
  <li>Fix summary notifications not sent when “skip if unchanged” is enabled - <a href="https://github.com/DependencyTrack/dependency-track/pull/4913">apiserver/#4913</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/56?closed=1">API server milestone 4.13.2</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/41?closed=1">Frontend milestone 4.13.2</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">845f970ba9c00a26d6d0b5a77c24cd12ee5feeea</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">f1d66b81a44d7d3528fad42d1e1fb498e2151c2c5e78c1070942be54456bf7d1</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">61d5c535ab19a6f67e48ee8efa20bf9656d084f7</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">4494b0090cd699db2099248c0fdd67a07d130731bbc476287251aa84d008bfa4</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">987a3b3a37fad4143b295ff9a7fcbacef7e915f4</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">94fc935e62a657e5f10bff9b9a8657841f0c2f2e53fd234c881580874bb95f14</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.13.2/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.13.2/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Fixes:]]></summary></entry><entry><title type="html">v4.13.1</title><link href="https://docs.dependencytrack.org/2025/04/30/v4.13.1/" rel="alternate" type="text/html" title="v4.13.1" /><published>2025-04-30T00:00:00+00:00</published><updated>2025-04-30T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2025/04/30/v4.13.1</id><content type="html" xml:base="https://docs.dependencytrack.org/2025/04/30/v4.13.1/"><![CDATA[<p><strong>Features:</strong></p>

<ul>
  <li>Show collection projects using a tag in the tags list - <a href="https://github.com/DependencyTrack/frontend/pull/1241">frontend/#1241</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix <code class="language-plaintext highlighter-rouge">NEW_VULNERABILITIES_SUMMARY</code> notification dispatch failing for PostgreSQL - <a href="https://github.com/DependencyTrack/dependency-track/pull/4859">apiserver/#4859</a></li>
  <li>Fix team email addresses not being available when publishing scheduled notification emails - <a href="https://github.com/DependencyTrack/dependency-track/pull/4860">apiserver/#4860</a></li>
  <li>Prevent duplicate tag names and relationships - <a href="https://github.com/DependencyTrack/dependency-track/pull/4861">apiserver/#4861</a></li>
  <li>Fix missing <code class="language-plaintext highlighter-rouge">NONE</code> value in classifier check constraint - <a href="https://github.com/DependencyTrack/dependency-track/pull/4887">apiserver/#4887</a></li>
  <li>Improve stability of tag binding - <a href="https://github.com/DependencyTrack/dependency-track/pull/4885">apiserver/#4885</a></li>
  <li>Fix tag deletion failing when tag is used by project collection logic - <a href="https://github.com/DependencyTrack/dependency-track/pull/4888">apiserver/#4888</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/55?closed=1">API server milestone 4.13.1</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/40?closed=1">Frontend milestone 4.13.1</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">b5e613f1f484179e770333828ef25c020ed9f03a</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">c88b2e7879b1d534741ce5483f96621b650d6a4dcacabb470eeeeb43e7c7c627</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">173511869286b1335950bd07477421d684c96251</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">53c7fca478125fad1c35d6732815a6c09e120abc6ea57a8a88eb2af3ed2efab2</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">ad0926abed617069934cf198670d7dba4e3f6867</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">0ae8950c4aa0713dc52812225720cb27cf2da17d32badcda9c2be8c3872720e6</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.13.1/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.13.1/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Features:]]></summary></entry><entry><title type="html">v4.13.0</title><link href="https://docs.dependencytrack.org/2025/04/07/v4.13.0/" rel="alternate" type="text/html" title="v4.13.0" /><published>2025-04-07T00:00:00+00:00</published><updated>2025-04-07T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2025/04/07/v4.13.0</id><content type="html" xml:base="https://docs.dependencytrack.org/2025/04/07/v4.13.0/"><![CDATA[<p><strong>Highlights:</strong></p>

<ul>
  <li><strong>API Key Overhaul</strong>. API keys are no longer stored as plain text values in the database,
but as SHA3-256 hashes. It will no longer be possible to view the full, plain text API keys
in the administration panel. Instead, full keys will only be shown <em>once</em> after their
creation. To allow keys to be identifiable despite this change, the API key format was adjusted
to include a <em>public identifier</em> portion. Keys generated by version 4.13.0 and later will follow
the format <code class="language-plaintext highlighter-rouge">odt_&lt;publicId&gt;_&lt;key&gt;</code>, where <code class="language-plaintext highlighter-rouge">publicId</code> consists of 8 random characters, and <code class="language-plaintext highlighter-rouge">key</code>
of the usual 32 random characters. The public ID is intended to identify API keys without disclosing
their secret. It will be visible in the UI, and it will also appear in logs.
    <ul>
      <li>Keys generated by earlier versions of Dependency-Track will continue to work,
in their case the first 5 characters are assumed to be the public ID.</li>
      <li><em>This feature was discussed and demoed in our February community meeting! Watch it <a href="https://www.youtube.com/watch?v=UphB2IDv1Rk&amp;t=280s">here</a></em></li>
    </ul>
  </li>
  <li><strong>Collection Projects</strong>. Dependency-Track has had support for project hierarchies for a while,
but until now their utility was still somewhat limited. Collection projects change this,
as they allow parent projects to act as aggregates of their children. While they are a major improvement
to the project hierarchy mechanism, there is still more work to be done. And the team is always
looking for feedback on how to make it better.
    <ul>
      <li><em>This feature was discussed and demoed in our January community meeting! Watch it <a href="https://www.youtube.com/watch?v=DSyf-g2FF_w&amp;t=745s">here</a></em></li>
    </ul>
  </li>
  <li><strong>Scheduled Summary Notifications</strong>. Instead of publishing notifications immediately when
a new vulnerability or policy violation is identified, it is now possible to configure scheduled
summary notifications. This aids in reducing alert fatigue. Refer to the <a href="/integrations/notifications/#configuring-scheduled-notifications">notifications documentation</a>
for more details.</li>
  <li><strong>Reduced Memory Footprint</strong>. The persistence framework used by Dependency-Track to interact with the database
comes with overambitious caching enabled per default. Disabling this cache mechanism has been a recommendation
the team gave to users struggling with memory requirements for a while. After evaluating whether it provides
any justifiable benefit at all, it was decided to turn this feature off entirely. Users with large portfolios
should see a noticeable drop in heap utilization and pressure on the garbage collector.</li>
  <li><strong>Observability Improvements</strong>. Logs emitted while handling REST API requests now include context about
the authenticated user, the path of the endpoint being called, as well as the request method.
This makes it easier to trace <em>where</em> problems are occurring, and <em>who</em> initiated the requests that cause them.</li>
</ul>

<p><strong>Features:</strong></p>

<ul>
  <li>Introduce collection projects for better utilization of project hierarchies - <a href="https://github.com/DependencyTrack/dependency-track/pull/3258">apiserver/#3258</a></li>
  <li>Add property to control <code class="language-plaintext highlighter-rouge">verified</code> flag in DefectDojo integration - <a href="https://github.com/DependencyTrack/dependency-track/pull/4273">apiserver/#4273</a></li>
  <li>Disable DataNucleus L2 cache globally - <a href="https://github.com/DependencyTrack/dependency-track/pull/4310">apiserver/#4310</a></li>
  <li>Optimize vulnerability synchronization logic to not perform redundant writes - <a href="https://github.com/DependencyTrack/dependency-track/pull/4359">apiserver/#4359</a></li>
  <li>Add REST API endpoint for batch deletion of projects - <a href="https://github.com/DependencyTrack/dependency-track/pull/4383">apiserver/#4383</a></li>
  <li>Update link to Azure DevOps Extension in docs - <a href="https://github.com/DependencyTrack/dependency-track/pull/4423">apiserver/#4423</a></li>
  <li>Reduce database round-trips during BOM processing - <a href="https://github.com/DependencyTrack/dependency-track/pull/4486">apiserver/#4486</a></li>
  <li>Postpone deprecation of unauthenticated access to Badge API - <a href="https://github.com/DependencyTrack/dependency-track/pull/4502">apiserver/#4502</a></li>
  <li>Clarify descriptions of component analysis cache properties - <a href="https://github.com/DependencyTrack/dependency-track/pull/4504">apiserver/#4504</a></li>
  <li>Add debug logging for Composer meta analyzer - <a href="https://github.com/DependencyTrack/dependency-track/pull/4546">apiserver/#4546</a></li>
  <li>Clarify OpenAPI endpoint location in the docs - <a href="https://github.com/DependencyTrack/dependency-track/pull/4556">apiserver/#4556</a></li>
  <li>Migrate API keys to new format - <a href="https://github.com/DependencyTrack/dependency-track/pull/4566">apiserver/#4566</a>, <a href="https://github.com/DependencyTrack/dependency-track/pull/4682">apiserver/#4682</a></li>
  <li>Update quickstart Compose file to use Postgres instead of H2 - <a href="https://github.com/DependencyTrack/dependency-track/pull/4576">apiserver/#4576</a></li>
  <li>Add SecObserve to community integrations - <a href="https://github.com/DependencyTrack/dependency-track/pull/4580">apiserver/#4580</a></li>
  <li>Track “last vulnerability analysis” timestamp for projects - <a href="https://github.com/DependencyTrack/dependency-track/pull/4642">apiserver/#4642</a></li>
  <li>Implement basic telemetry collection - <a href="https://github.com/DependencyTrack/dependency-track/pull/4651">apiserver/#4651</a></li>
  <li>Prevent application startup when migrations fail - <a href="https://github.com/DependencyTrack/dependency-track/pull/4681">apiserver/#4681</a></li>
  <li>Add support for Snyk API version 2024-10-15 - <a href="https://github.com/DependencyTrack/dependency-track/pull/4715">apiserver/#4715</a></li>
  <li>Add REST API endpoint for bulk creation of tags - <a href="https://github.com/DependencyTrack/dependency-track/pull/4766">apiserver/#4766</a></li>
  <li>Update Azure AD configuration docs to Entra ID - <a href="https://github.com/DependencyTrack/dependency-track/pull/4778">apiserver/#4778</a></li>
  <li>Make it configurable whether Trivy should scan only OS packages, only libraries, or both - <a href="https://github.com/DependencyTrack/dependency-track/pull/4782">apiserver/#4782</a></li>
  <li>Add support for scheduled summary notifications - <a href="https://github.com/DependencyTrack/dependency-track/pull/4783">apiserver/#4783</a></li>
  <li>Add ability to configure the DefectDojo test title - <a href="https://github.com/DependencyTrack/dependency-track/pull/4796">apiserver/#4796</a></li>
  <li>Bump SPDX license list to v3.26.0 - <a href="https://github.com/DependencyTrack/dependency-track/pull/4800">apiserver/#4800</a></li>
  <li>Bump CWE dictionary to v4.16 - <a href="https://github.com/DependencyTrack/dependency-track/pull/4801">apiserver/#4801</a></li>
  <li>Add new optional column <em>Classifier</em> in project component view - <a href="https://github.com/DependencyTrack/frontend/pull/1058">frontend/#1058</a></li>
  <li>Remove deprecation notice of toggle for unauthenticated access to SVG badges - <a href="https://github.com/DependencyTrack/frontend/pull/1129">frontend/#1129</a></li>
  <li>Add timestamp formatting to chart tooltips - <a href="https://github.com/DependencyTrack/frontend/pull/1152">frontend/#1152</a></li>
  <li>Handle new API key format and generation process - <a href="https://github.com/DependencyTrack/frontend/pull/1157">frontend/#1157</a></li>
  <li>Add telemetry admin view - <a href="https://github.com/DependencyTrack/frontend/pull/1164">frontend/#1164</a></li>
  <li>Add autocomplete to project collection logic tag dropdown - <a href="https://github.com/DependencyTrack/frontend/pull/1198">frontend/#1198</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix failure to synchronize vulnerability aliases when the source of a vulnerability is unrecognized - <a href="https://github.com/DependencyTrack/dependency-track/pull/4767">apiserver/#4767</a></li>
  <li>Fix possible NPE during affected version attribution sync - <a href="https://github.com/DependencyTrack/dependency-track/pull/4798">apiserver/#4798</a></li>
  <li>Fix occasional JsonParseException during NVD API mirroring - <a href="https://github.com/DependencyTrack/dependency-track/pull/4814">apiserver/#4814</a></li>
  <li>Fix UpgradeInitializer halting the entire process upon failure - <a href="https://github.com/DependencyTrack/dependency-track/pull/4818">apiserver/#4818</a></li>
  <li>Fix column visibility preference not considered for project list - <a href="https://github.com/DependencyTrack/frontend/pull/1169">frontend/#1169</a></li>
  <li>Fix tag autocomplete dropdown library style overriding issue - <a href="https://github.com/DependencyTrack/frontend/pull/1213">frontend/#1213</a></li>
</ul>

<p><strong>Upgrade Notes:</strong></p>

<p><strong>Please make a database backup before upgrading!</strong> Some changes in this release are <strong>irreversible</strong>,<br />
and you won’t be able to roll back simply by downgrading the application version!</p>

<ul>
  <li>Existing API keys will be automatically hashed during this upgrade. It will not be possible
to view them in plain text ever again after the upgrade completed. Outside of making a database
backup, consider noting down all the keys you might need somewhere safe before performing this upgrade.</li>
  <li>Dependency-Track instances will automatically share minimal telemetry information on a daily basis.
Find a list of collected data, as well as instructions for opting out, in the <a href="/getting-started/telemetry/">telemetry documentation</a>.</li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/38?closed=1">API server milestone 4.13.0</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/23?closed=1">Frontend milestone 4.13.0</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<p>Special thanks to everyone who contributed code to implement enhancements and fix defects:</p>

<p><a href="https://github.com/2000rosser">@2000rosser</a>, <a href="https://github.com/AndreVirtimo">@AndreVirtimo</a>, <a href="https://github.com/Gepardgame">@Gepardgame</a>, <a href="https://github.com/Granjow">@Granjow</a>, <a href="https://github.com/LaVibeX">@LaVibeX</a>, <a href="https://github.com/MM-msr">@MM-msr</a>, <a href="https://github.com/Malaydewangan09">@Malaydewangan09</a>, <a href="https://github.com/Rudra-Garg">@Rudra-Garg</a>,
<a href="https://github.com/SaberStrat">@SaberStrat</a>, <a href="https://github.com/StefanFl">@StefanFl</a>, <a href="https://github.com/VinodAnandan">@VinodAnandan</a>, <a href="https://github.com/Zargath">@Zargath</a>, <a href="https://github.com/ad8-adriant">@ad8-adriant</a>, <a href="https://github.com/dhfherna">@dhfherna</a>, <a href="https://github.com/jayolee">@jayolee</a>, <a href="https://github.com/mge-mm">@mge-mm</a>,
<a href="https://github.com/mikael-carneholm-2-wcar">@mikael-carneholm-2-wcar</a>, <a href="https://github.com/mjwrona">@mjwrona</a>, <a href="https://github.com/rbt-mm">@rbt-mm</a>, <a href="https://github.com/rkg-mm">@rkg-mm</a>, <a href="https://github.com/stohrendorf">@stohrendorf</a>, <a href="https://github.com/valentijnscholten">@valentijnscholten</a></p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">c5ef70f1e8df186a929a7c2ad24962a3b97af379</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">0f2af7a93a21850da62c2b2e86babfb0b0f18abd80f380dfb80bf84c59f605e4</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">feeac3362ae6ea5d42cf6dde7e5e079599372eaa</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">a81e61f1e21a732474a11345d71e7853d50ec2faea1f7d44bacfb29902673ebd</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">5f18d23205cff4627ff6330bca9f70f71810da89</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">e64676821351096cce62735d28a15b2ae62c4ba66c1b295ab119a9b83f94eef0</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.13.0/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.13.0/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Highlights:]]></summary></entry><entry><title type="html">v4.12.7</title><link href="https://docs.dependencytrack.org/2025/03/12/v4.12.7/" rel="alternate" type="text/html" title="v4.12.7" /><published>2025-03-12T00:00:00+00:00</published><updated>2025-03-12T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2025/03/12/v4.12.7</id><content type="html" xml:base="https://docs.dependencytrack.org/2025/03/12/v4.12.7/"><![CDATA[<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix NPE during NVD mirroring via REST API when encountering invalid CPEs - <a href="https://github.com/DependencyTrack/dependency-track/pull/4734">apiserver/#4734</a></li>
  <li>Remove erroneous client-side caching in Trivy analyzer - <a href="https://github.com/DependencyTrack/dependency-track/pull/4736">apiserver/#4736</a></li>
  <li>Fix notification limiting to tags not working reliably - <a href="https://github.com/DependencyTrack/dependency-track/pull/4737">apiserver/#4737</a></li>
  <li>Fix tags from BOM upload request not being applied for existing projects - <a href="https://github.com/DependencyTrack/dependency-track/pull/4740">apiserver/#4740</a></li>
  <li>Fix component properties not being cloned - <a href="https://github.com/DependencyTrack/dependency-track/pull/4746">apiserver/#4746</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/54?closed=1">API server milestone 4.12.7</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/39?closed=1">Frontend milestone 4.12.7</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">a3a30181b15a14bcd3ea3ef7ed338d2ce5e86bb5</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">cc271be5577eee0a562c19acd60a693accbe6b8b1a24294472a43462f6aa94fd</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">2c416320eda0aee60a268047643da006ad7edf24</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">48defc20ebe19214bb7cf73bf61f8c09f467d0c8585a5e6c0671ad563bbd4884</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">4d42a3251d35746bb198018fec273b17a91761e6</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">8c808d7d4ec2442970e8a79f8bb67b9422a69e377a682a4fe47057e7b0cad642</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.12.7/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.12.7/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Fixes:]]></summary></entry></feed>