<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://docs.dependencytrack.org/feed.xml" rel="self" type="application/atom+xml" /><link href="https://docs.dependencytrack.org/" rel="alternate" type="text/html" /><updated>2026-09-08T11:41:53+00:00</updated><id>https://docs.dependencytrack.org/feed.xml</id><title type="html">Dependency-Track</title><subtitle>Product documentation</subtitle><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><entry><title type="html">v4.14.3</title><link href="https://docs.dependencytrack.org/2026/07/20/v4.14.3/" rel="alternate" type="text/html" title="v4.14.3" /><published>2026-07-20T00:00:00+00:00</published><updated>2026-07-20T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2026/07/20/v4.14.3</id><content type="html" xml:base="https://docs.dependencytrack.org/2026/07/20/v4.14.3/"><![CDATA[<p><strong>Features:</strong></p>

<ul>
  <li>Improve VEX import performance - <a href="https://github.com/DependencyTrack/dependency-track/pull/6141">apiserver/#6141</a></li>
  <li>Include <code class="language-plaintext highlighter-rouge">groupBy</code> parameter in DefectDojo finding upload - <a href="https://github.com/DependencyTrack/dependency-track/pull/6130">apiserver/#6130</a></li>
  <li>Include analysis detail in DefectDojo finding payload - <a href="https://github.com/DependencyTrack/dependency-track/pull/6181">apiserver/#6181</a></li>
  <li>Improve performance of OSV mirroring - <a href="https://github.com/DependencyTrack/dependency-track/pull/6345">apiserver/#6345</a></li>
  <li>Show exploit predictions from all sources - <a href="https://github.com/DependencyTrack/frontend/pull/1523">frontend/#1523</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Reject parent objects with null UUID when creating, updating or patching projects - <a href="https://github.com/DependencyTrack/dependency-track/pull/6355">apiserver/#6355</a></li>
  <li>Fix NPE and redundant queries in VEX / VDR export - <a href="https://github.com/DependencyTrack/dependency-track/pull/6614">apiserver/#6614</a></li>
  <li>Prevent duplicate downloads when using export and download buttons - <a href="https://github.com/DependencyTrack/frontend/pull/1659">frontend/#1659</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/65?closed=1">API server milestone 4.14.3</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/48?closed=1">Frontend milestone 4.14.3</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<p>Special thanks to everyone who contributed code to implement enhancements and fix defects:</p>

<p><a href="https://github.com/ElenaStroebele">@ElenaStroebele</a>, <a href="https://github.com/heyiamwahab236">@heyiamwahab236</a>, <a href="https://github.com/webdevred">@webdevred</a>, <a href="https://github.com/yuwwx">@yuwwx</a></p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">40db3eb67df441382971c8fb6566b86bc65976f4</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">11a5c85616b745803b5653016d9da2195f2e23ac66fe6a85d2ae2b4661d393a9</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">71a8e224166a55efb163922bb9874c151b3d95eb</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">4cbedd435f0f07b520216e4c30b9c81ca9a43044c569285ed1aa2e4f1533f5be</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">be91ca477d92f492cdd4e5d215e3154f97c50be5</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">de3d76d978689d0fe571683cfeedf7fea095a1fd03f86cf622a099b5b72f4477</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.14.3/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.14.3/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Features:]]></summary></entry><entry><title type="html">v4.14.2</title><link href="https://docs.dependencytrack.org/2026/05/07/v4.14.2/" rel="alternate" type="text/html" title="v4.14.2" /><published>2026-05-07T00:00:00+00:00</published><updated>2026-05-07T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2026/05/07/v4.14.2</id><content type="html" xml:base="https://docs.dependencytrack.org/2026/05/07/v4.14.2/"><![CDATA[<p><strong>Features:</strong></p>

<ul>
  <li>Improve performance of vuln data source mirroring - <a href="https://github.com/DependencyTrack/dependency-track/pull/6040">apiserver/#6040</a></li>
  <li>Handle epoch PURL qualifier for version comparison - <a href="https://github.com/DependencyTrack/dependency-track/pull/6083">apiserver/#6083</a></li>
  <li>Add project filters to component identity search - <a href="https://github.com/DependencyTrack/dependency-track/pull/6087">apiserver/#6087</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix incorrect format of Composer packages being sent to Trivy - <a href="https://github.com/DependencyTrack/dependency-track/pull/6117">apiserver/#6117</a></li>
  <li>Fix incorrect version comparison of NuGet packages when v-prefix is present - <a href="https://github.com/DependencyTrack/dependency-track/pull/6116">apiserver/#6116</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/64?closed=1">API server milestone 4.14.2</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/36?closed=1">Frontend milestone 4.14.2</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<p>Special thanks to everyone who contributed code to implement enhancements and fix defects:</p>

<p><a href="https://github.com/Abdelmonem-BEN-NACEUR">@Abdelmonem-BEN-NACEUR</a>, <a href="https://github.com/hoobio">@hoobio</a></p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">953074d95757bea162931b7811885945bbe992aa</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">3ff379380d35b9ff924014b680e7f3718c119f59b2cc4ee6ece4345a3ca1c110</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">53f3198f5422e1117f53859c5f42403f48a4a4e3</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">fca1c0c69d543f4be3501f04d3293beef5b5db9fbad24d55cfc70ea2cc8e2b4f</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">3ee09446776c3f65503fa7183e95ef8864b19946</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">2cb995d67f13b9d909609978f715c0649e717794ff231825089bfaf2ccd79516</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.14.2/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.14.2/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Features:]]></summary></entry><entry><title type="html">v4.14.1</title><link href="https://docs.dependencytrack.org/2026/04/03/v4.14.1/" rel="alternate" type="text/html" title="v4.14.1" /><published>2026-04-03T00:00:00+00:00</published><updated>2026-04-03T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2026/04/03/v4.14.1</id><content type="html" xml:base="https://docs.dependencytrack.org/2026/04/03/v4.14.1/"><![CDATA[<p><strong>Features:</strong></p>

<ul>
  <li>Add support for NuGet versioning scheme - <a href="https://github.com/DependencyTrack/dependency-track/pull/5958">apiserver/#5958</a></li>
  <li>Add support for Composer versioning scheme - <a href="https://github.com/DependencyTrack/dependency-track/pull/5963">apiserver/#5963</a></li>
  <li>Document age and version distance operational policy criteria - <a href="https://github.com/DependencyTrack/dependency-track/pull/5964">apiserver/#5964</a></li>
  <li>Use ecosystem-aware version comparison for latest version detection - <a href="https://github.com/DependencyTrack/dependency-track/pull/5995">apiserver/#5995</a></li>
  <li>Support Sonatype Guide tokens for OSS Index analyzer - <a href="https://github.com/DependencyTrack/dependency-track/pull/5996">apiserver/#5996</a></li>
  <li>Improve Chinese translations - <a href="https://github.com/DependencyTrack/frontend/pull/1490">frontend/#1490</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix PURL-specific version matching being bypassed for components with CPE - <a href="https://github.com/DependencyTrack/dependency-track/pull/5959">apiserver/#5959</a></li>
  <li>Fix wasteful existence queries - <a href="https://github.com/DependencyTrack/dependency-track/pull/5960">apiserver/#5960</a></li>
  <li>Fix potentially wrong version being used for CPE comparison - <a href="https://github.com/DependencyTrack/dependency-track/pull/5962">apiserver/#5962</a></li>
  <li>Fix scheduled notification query failing when ID columns are not of type BIGINT - <a href="https://github.com/DependencyTrack/dependency-track/pull/5979">apiserver/#5979</a></li>
  <li>Avoid NPE when computing Trivy pkgType - <a href="https://github.com/DependencyTrack/dependency-track/pull/5987">apiserver/#5987</a></li>
  <li>Remove leading whitespace from vulnerability badge SVG template - <a href="https://github.com/DependencyTrack/dependency-track/pull/6000">apiserver/#6000</a></li>
  <li>Fix Japanese Trivy analyzer strings - <a href="https://github.com/DependencyTrack/frontend/pull/1489">frontend/#1489</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/50?closed=1">API server milestone 4.14.1</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/35?closed=1">Frontend milestone 4.14.1</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<p>Special thanks to everyone who contributed code to implement enhancements and fix defects:</p>

<p><a href="https://github.com/Zureno">@Zureno</a>, <a href="https://github.com/jonbally">@jonbally</a>, <a href="https://github.com/retanoj">@retanoj</a>, <a href="https://github.com/shayFoo">@shayFoo</a>, <a href="https://github.com/stohrendorf">@stohrendorf</a></p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">750b0c768208d7c6b7e32e8f1a7500eb94788069</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">142bdfa36defffc2304d03f9ef7ecd162f1185dcbc00933a73529cac7f12980c</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">61eac5828458dfea46507c26f3384bb452ebeefe</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">6cedc727a3f8eb2343397e50a1b5515a99c2a361b7c55aa60dbeff85c1f4af2d</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">a08b4280aad4e9946908ca6fd05e1fbc0ad0f1af</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">e13d9b729d2082fcfb440bc1deb6f373290d1ead414447d8834368b4dbceec27</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.14.1/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.14.1/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Features:]]></summary></entry><entry><title type="html">v4.14.0</title><link href="https://docs.dependencytrack.org/2026/03/09/v4.14.0/" rel="alternate" type="text/html" title="v4.14.0" /><published>2026-03-09T00:00:00+00:00</published><updated>2026-03-09T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2026/03/09/v4.14.0</id><content type="html" xml:base="https://docs.dependencytrack.org/2026/03/09/v4.14.0/"><![CDATA[<p><strong>Highlights:</strong></p>

<ul>
  <li><strong>Ecosystem-aware version matching</strong>. Vulnerability analysis now uses version comparison algorithms
native to the component’s ecosystem, rather than relying on generic semantic versioning.
For example, Debian versions are compared using the <a href="https://manpages.debian.org/stretch/dpkg-dev/deb-version.5.en.html#Sorting_algorithm">dpkg sorting algorithm</a>.
Supported ecosystems are Alpine Linux, Debian, Go, Maven, NPM, PyPI, and RPM.</li>
  <li><strong>Distro-aware vulnerability matching</strong>. Linux distributions like Debian backport security fixes
to older releases, meaning a component may be vulnerable in one distro release but not another.
Dependency-Track now uses the <code class="language-plaintext highlighter-rouge">distro</code> qualifier of package URLs (e.g.,
<code class="language-plaintext highlighter-rouge">pkg:deb/debian/libcurl4t64@8.14.1-2%2Bdeb13u2?distro=debian-13.3</code>) to determine the OS release
and match vulnerabilities accordingly. Currently supported for Alpine Linux, Debian, and Ubuntu.
    <ul>
      <li><strong>Note</strong>: Requires vulnerability data from OSV, as the NVD does not contextualize
version ranges by OS release. Not all BOM generators populate the <code class="language-plaintext highlighter-rouge">distro</code> PURL qualifier today.</li>
    </ul>
  </li>
  <li><strong>CVSSv4 support</strong>. Upstream vulnerability sources are increasingly publishing CVSSv4 scores.
Dependency-Track now ingests and displays CVSSv4 vectors and derived severities alongside existing
CVSSv2 and CVSSv3 data.</li>
</ul>

<p><strong>Features:</strong></p>

<ul>
  <li>Include project UUID in log messages - <a href="https://github.com/DependencyTrack/dependency-track/pull/5500">apiserver/#5500</a></li>
  <li>Add support for incremental mirroring of OSV - <a href="https://github.com/DependencyTrack/dependency-track/pull/5537">apiserver/#5537</a></li>
  <li>Add internal status policy condition support - <a href="https://github.com/DependencyTrack/dependency-track/pull/5570">apiserver/#5570</a></li>
  <li>Implement VERS approach for PURL version matching - <a href="https://github.com/DependencyTrack/dependency-track/pull/5591">apiserver/#5591</a></li>
  <li>Add projectUuid via MDC to logger statements within VEX upload - <a href="https://github.com/DependencyTrack/dependency-track/pull/5615">apiserver/#5615</a></li>
  <li>Specify newer version of Docker Compose in README - <a href="https://github.com/DependencyTrack/dependency-track/pull/5648">apiserver/#5648</a></li>
  <li>Add configurable base URL for OSS Index API - <a href="https://github.com/DependencyTrack/dependency-track/pull/5736">apiserver/#5736</a></li>
  <li>Update OSS Index documentation - <a href="https://github.com/DependencyTrack/dependency-track/pull/5774">apiserver/#5774</a></li>
  <li>Improve efficiency and caching behaviour of OSS Index analyzer - <a href="https://github.com/DependencyTrack/dependency-track/pull/5793">apiserver/#5793</a></li>
  <li>Switch to G1GC and limit default Docker Compose memory to 4GB - <a href="https://github.com/DependencyTrack/dependency-track/pull/5794">apiserver/#5794</a></li>
  <li>Add EPSS score support for GitHub Advisory vulnerabilities - <a href="https://github.com/DependencyTrack/dependency-track/pull/5829">apiserver/#5829</a></li>
  <li>Add page on users and permissions to documentation - <a href="https://github.com/DependencyTrack/dependency-track/pull/5831">apiserver/#5831</a></li>
  <li>Include CVSS vectors and metadata in Finding model - <a href="https://github.com/DependencyTrack/dependency-track/pull/5844">apiserver/#5844</a></li>
  <li>Tweak vulnerability persistence logic - <a href="https://github.com/DependencyTrack/dependency-track/pull/5862">apiserver/#5862</a></li>
  <li>Add CVSSv4 support - <a href="https://github.com/DependencyTrack/dependency-track/pull/5863">apiserver/#5863</a></li>
  <li>Delete NVD feed timestamp files during v4.14.0 upgrade - <a href="https://github.com/DependencyTrack/dependency-track/pull/5886">apiserver/#5886</a></li>
  <li>Bump SPDX license list to v3.28.0 - <a href="https://github.com/DependencyTrack/dependency-track/pull/5888">apiserver/#5888</a></li>
  <li>Bump CWE dictionary to v4.19.1 - <a href="https://github.com/DependencyTrack/dependency-track/pull/5889">apiserver/#5889</a></li>
  <li>Make username optional for Repositories Bearer Auth - <a href="https://github.com/DependencyTrack/frontend/pull/1128">frontend/#1128</a></li>
  <li>Improve German Translation - <a href="https://github.com/DependencyTrack/frontend/pull/1227">frontend/#1227</a></li>
  <li>Add suffix to vulnerability locale keys - <a href="https://github.com/DependencyTrack/frontend/pull/1276">frontend/#1276</a></li>
  <li>Add match mode selector to internal component config - <a href="https://github.com/DependencyTrack/frontend/pull/1283">frontend/#1283</a></li>
  <li>Display license ID - <a href="https://github.com/DependencyTrack/frontend/pull/1311">frontend/#1311</a></li>
  <li>Support for scope mentioned in CycloneDX format - <a href="https://github.com/DependencyTrack/frontend/pull/1319">frontend/#1319</a></li>
  <li>Add support for IS_INTERNAL policy condition - <a href="https://github.com/DependencyTrack/frontend/pull/1394">frontend/#1394</a></li>
  <li>Add Traditional Chinese (zh-TW) language support - <a href="https://github.com/DependencyTrack/frontend/pull/1412">frontend/#1412</a></li>
  <li>Remove database information from About dialogue - <a href="https://github.com/DependencyTrack/frontend/pull/1421">frontend/#1421</a></li>
  <li>Add OSS Index Base URL configuration field - <a href="https://github.com/DependencyTrack/frontend/pull/1431">frontend/#1431</a></li>
  <li>Add CVSSv4 support - <a href="https://github.com/DependencyTrack/frontend/pull/1455">frontend/#1455</a></li>
  <li>Add missing internal_status i18n key for zh-TW locale - <a href="https://github.com/DependencyTrack/frontend/pull/1456">frontend/#1456</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix sneaky double quote - <a href="https://github.com/DependencyTrack/dependency-track/pull/5420">apiserver/#5420</a></li>
  <li>Fix incorrect UTF-8 encoding in notification payload - <a href="https://github.com/DependencyTrack/dependency-track/pull/5574">apiserver/#5574</a></li>
  <li>Fix excessive memory usage of Nix analyzer - <a href="https://github.com/DependencyTrack/dependency-track/pull/5653">apiserver/#5653</a></li>
  <li>Fix wrong NPM component coordinate separator for Trivy analysis - <a href="https://github.com/DependencyTrack/dependency-track/pull/5679">apiserver/#5679</a></li>
  <li>Fix performance issue with PURL lookups - <a href="https://github.com/DependencyTrack/dependency-track/pull/5711">apiserver/#5711</a></li>
  <li>Fall back to generic versioning scheme if no PURL is available - <a href="https://github.com/DependencyTrack/dependency-track/pull/5714">apiserver/#5714</a></li>
  <li>Fix incorrect URL for VulnDB analyzer - <a href="https://github.com/DependencyTrack/dependency-track/pull/5751">apiserver/#5751</a></li>
  <li>Ensure container zombie processes are reaped - <a href="https://github.com/DependencyTrack/dependency-track/pull/5758">apiserver/#5758</a></li>
  <li>Fix singleton events not being labelled as such - <a href="https://github.com/DependencyTrack/dependency-track/pull/5775">apiserver/#5775</a></li>
  <li>Consider OS distro during vulnerability matching - <a href="https://github.com/DependencyTrack/dependency-track/pull/5783">apiserver/#5783</a></li>
  <li>Fix re-initialization of teams when opening create-modal - <a href="https://github.com/DependencyTrack/frontend/pull/1410">frontend/#1410</a></li>
</ul>

<p><strong>Upgrade Notes:</strong></p>

<ul>
  <li>To backfill CVSSv4 and EPSS data, mirror watermarks for NVD and GitHub Advisories will be reset,                                                                                                    <br />
triggering a full re-mirror on next invocation.</li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/49?closed=1">API server milestone 4.14.0</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/34?closed=1">Frontend milestone 4.14.0</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<p>Special thanks to everyone who contributed code to implement enhancements and fix defects:</p>

<p><a href="https://github.com/anantk24">@anantk24</a>, <a href="https://github.com/AndreVirtimo">@AndreVirtimo</a>, <a href="https://github.com/arjavdongaonkar">@arjavdongaonkar</a>, <a href="https://github.com/brianf">@brianf</a>, <a href="https://github.com/ch8matt">@ch8matt</a>, <a href="https://github.com/ElenaStroebele">@ElenaStroebele</a>,
<a href="https://github.com/fupgang">@fupgang</a>, <a href="https://github.com/Granjow">@Granjow</a>, <a href="https://github.com/jonbally">@jonbally</a>, <a href="https://github.com/jvirgovic">@jvirgovic</a>, <a href="https://github.com/setchy">@setchy</a>, <a href="https://github.com/snieguu">@snieguu</a>, <a href="https://github.com/stohrendorf">@stohrendorf</a>,
<a href="https://github.com/tobiasgies">@tobiasgies</a>, <a href="https://github.com/valentijnscholten">@valentijnscholten</a>, <a href="https://github.com/WoozyMasta">@WoozyMasta</a>, <a href="https://github.com/wengct">@wengct</a></p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">a06d7f57876befc80b6653fcc44b321958388f12</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">2e3d5bcfb7b5d4ad4daf789bc5ca3802ef05d012c516090e8bc5323f46585f53</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">6573a4522dd84520859ab951d86d8a9e4dd43fb2</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">a8edd7c94ba811bae73d9213d769687c493e1bd95435dbe39dfeee28ff1f8008</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">8a822e22c6c087b0e46f9478f9b342d2e2bad162</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">9a96be982a80c6c8714ad8d22a932d013a6b3593744083d551a7fb2b4a281aa3</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.14.0/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.14.0/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Highlights:]]></summary></entry><entry><title type="html">v4.13.6</title><link href="https://docs.dependencytrack.org/2025/11/17/v4.13.6/" rel="alternate" type="text/html" title="v4.13.6" /><published>2025-11-17T00:00:00+00:00</published><updated>2025-11-17T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2025/11/17/v4.13.6</id><content type="html" xml:base="https://docs.dependencytrack.org/2025/11/17/v4.13.6/"><![CDATA[<p>Starting with this release, we’re publishing a new container image variant for the
<em>apiserver</em> and <em>bundled</em> distributions. The variant is based on <a href="https://www.alpinelinux.org/">Alpine Linux</a> and uses
<a href="https://dev.java/learn/jlink/">jlink</a> to ship a minimal Java Runtime Environment (JRE). As a result, image size is decreased
by over 55% (~350MB vs. ~150MB uncompressed), and attack surface is reduced due to fewer
operating system packages. It uses Java 25 and enables <a href="https://openjdk.org/jeps/519">compact object headers</a> by default,
leading to lower memory footprint.</p>

<p>To use the new image variant, append the <code class="language-plaintext highlighter-rouge">-alpine</code> suffix to the image tag, e.g.:</p>

<ul>
  <li><code class="language-plaintext highlighter-rouge">docker.io/dependencytrack/apiserver:latest-alpine</code></li>
  <li><code class="language-plaintext highlighter-rouge">docker.io/dependencytrack/bundled:4.13.6-alpine</code></li>
</ul>

<p>The previous Debian-based image variant continues to be the default for now,
but will eventually be discontinued in a future release. Users experiencing
issues with <code class="language-plaintext highlighter-rouge">alpine</code> images can safely fall back to non-<code class="language-plaintext highlighter-rouge">alpine</code> variants.</p>

<p><strong>Features:</strong></p>

<ul>
  <li>Add Alpine-based container variants - <a href="https://github.com/DependencyTrack/dependency-track/pull/5533">apiserver/#5533</a></li>
  <li>Update Ukrainian translation - <a href="https://github.com/DependencyTrack/frontend/pull/1385">frontend/#1385</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Improve performance of database migration to v4.13.5 - <a href="https://github.com/DependencyTrack/dependency-track/pull/5419">apiserver/#5419</a></li>
  <li>Ignore stale Lucene index entries - <a href="https://github.com/DependencyTrack/dependency-track/pull/5428">apiserver/#5428</a></li>
  <li>Fix typo in email notification template - <a href="https://github.com/DependencyTrack/dependency-track/pull/5434">apiserver/#5434</a></li>
  <li>Fix referential integrity violation during bulk project deletion - <a href="https://github.com/DependencyTrack/dependency-track/pull/5446">apiserver/#5446</a></li>
  <li>Fix referential integrity violation during team deletion - <a href="https://github.com/DependencyTrack/dependency-track/pull/5447">apiserver/#5447</a></li>
  <li>Fix NPE in Composer component metadata analyzer - <a href="https://github.com/DependencyTrack/dependency-track/pull/5519">apiserver/#5519</a></li>
  <li>Fix XML External Entity injection via validation of CycloneDX BOMs in XML format - <a href="https://github.com/DependencyTrack/dependency-track/pull/5528">apiserver/#5528</a> / <a href="https://github.com/DependencyTrack/dependency-track/security/advisories/GHSA-93r8-3g93-w2gq">GHSA-93r8-3g93-w2gq</a></li>
  <li>Fix OSS Index documentation link - <a href="https://github.com/DependencyTrack/dependency-track/pull/5531">apiserver/#5531</a></li>
  <li>Change <code class="language-plaintext highlighter-rouge">toString()</code> method of <code class="language-plaintext highlighter-rouge">Project</code> to use name and version instead of PURL - <a href="https://github.com/DependencyTrack/dependency-track/pull/5532">apiserver/#5532</a></li>
  <li>Fix broken routing when <code class="language-plaintext highlighter-rouge">BASE_PATH</code> is configured - <a href="https://github.com/DependencyTrack/frontend/pull/1381">frontend/#1381</a></li>
  <li>Fix policy tag selection dialogue using the wrong REST API endpoint - <a href="https://github.com/DependencyTrack/frontend/pull/1382">frontend/#1382</a></li>
  <li>Fix persistent Cross-Site-Scripting via welcome message - <a href="https://github.com/DependencyTrack/frontend/pull/1383">frontend/#1383</a> / <a href="https://github.com/DependencyTrack/frontend/security/advisories/GHSA-7xvh-c266-cfr5">GHSA-7xvh-c266-cfr5</a></li>
  <li>Fix redirect loop when authenticated user is lacking permissions - <a href="https://github.com/DependencyTrack/frontend/pull/1386">frontend/#1386</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/60?closed=1">API server milestone 4.13.6</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/45?closed=1">Frontend milestone 4.13.6</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<p>Special thanks to everyone who contributed code to implement enhancements and fix defects:</p>

<p><a href="https://github.com/ElenaStroebele">@ElenaStroebele</a>, <a href="https://github.com/arjavdongaonkar">@arjavdongaonkar</a>, <a href="https://github.com/aurifi">@aurifi</a>, <a href="https://github.com/ch8matt">@ch8matt</a>, <a href="https://github.com/illenko">@illenko</a>, <a href="https://github.com/sahibamittal">@sahibamittal</a>, <a href="https://github.com/snieguu">@snieguu</a>, <a href="https://github.com/stohrendorf">@stohrendorf</a></p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">3964cf821761609912487077fa41d513dad37d1a</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">8f2aa10424403b2b201d0c48b243ea3bbe458761</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">1048a039391992fc36b23433d8987689baca33e68cc2130254787d1a3d1c66cc</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">ab47deb0c5be2d947d57cf5862fef714023b4ce4d794ac00a855cf7590eb111e</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">525b47c72fb3bdbb675b5c5414319e5f19e43b03</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">84440921692e95c88378e1f82738ccea24c2fb038083b42b3f1c98b1f6702a4a</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.13.6/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.13.6/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Starting with this release, we’re publishing a new container image variant for the apiserver and bundled distributions. The variant is based on Alpine Linux and uses jlink to ship a minimal Java Runtime Environment (JRE). As a result, image size is decreased by over 55% (~350MB vs. ~150MB uncompressed), and attack surface is reduced due to fewer operating system packages. It uses Java 25 and enables compact object headers by default, leading to lower memory footprint.]]></summary></entry><entry><title type="html">v4.13.5</title><link href="https://docs.dependencytrack.org/2025/10/07/v4.13.5/" rel="alternate" type="text/html" title="v4.13.5" /><published>2025-10-07T00:00:00+00:00</published><updated>2025-10-07T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2025/10/07/v4.13.5</id><content type="html" xml:base="https://docs.dependencytrack.org/2025/10/07/v4.13.5/"><![CDATA[<p><strong>Important Notice:</strong></p>

<p>Sonatype has started to enforce an authentication requirement for OSS Index.</p>

<p>The <a href="/datasources/ossindex/">OSS Index analyzer</a> has historically been enabled by default for Dependency-Track,
and configuration of credentials for authentication was not strictly necessary.</p>

<p>This has now changed, and users who wish to continue using OSS Index will
need to register for a free account, and configure credentials in the analyzer’s settings.</p>

<p>Please refer to <a href="https://ossindex.sonatype.org/doc/auth-required">Sonatype’s announcement</a> for further details.</p>

<p>In the midterm, we’ll be looking into enabling OSV per default
to compensate for this change.</p>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix CPE matching not being fully case-insensitive - <a href="https://github.com/DependencyTrack/dependency-track/pull/5299">apiserver/#5299</a></li>
  <li>Improve detection whether version of a github PURL is a commit SHA or release tag - <a href="https://github.com/DependencyTrack/dependency-track/pull/5350">apiserver/#5350</a></li>
  <li>Make OSS Index credentials required - <a href="https://github.com/DependencyTrack/dependency-track/pull/5351">apiserver/#5351</a></li>
  <li>Fix occasional NullPointerException when mirroring the NVD via REST API - <a href="https://github.com/DependencyTrack/dependency-track/pull/5352">apiserver/#5352</a></li>
  <li>Fix <code class="language-plaintext highlighter-rouge">/api/v1/tag/policy/{uuid}</code> endpoint returning more tags than are assigned to a policy - <a href="https://github.com/DependencyTrack/dependency-track/pull/5353">apiserver/#5353</a></li>
  <li>Fix possible failure of NVD mirroring due to corrupted timestamp files - <a href="https://github.com/DependencyTrack/dependency-track/pull/5354">apiserver/#5354</a></li>
  <li>Fix BOM validation failing due to unrecognized new SPDX license IDs - <a href="https://github.com/DependencyTrack/dependency-track/pull/5355">apiserver/#5355</a></li>
  <li>Fix new SPDX license IDs not being recognized - <a href="https://github.com/DependencyTrack/dependency-track/pull/5356">apiserver/#5356</a></li>
  <li>Fix high CPU utilization when watchdog logger is configured - <a href="https://github.com/DependencyTrack/dependency-track/pull/5357">apiserver/#5357</a></li>
  <li>Fix NullPointerException in GithubMetaAnalyzer when analyzing GitHub Actions - <a href="https://github.com/DependencyTrack/dependency-track/pull/5359">apiserver/#5359</a></li>
  <li>Fix connection reset during OSV mirroring - <a href="https://github.com/DependencyTrack/dependency-track/pull/5360">apiserver/#5360</a></li>
  <li>Fix compatibility of custom NuGet repositories with JFrog Artifactory - <a href="https://github.com/DependencyTrack/dependency-track/pull/5381">apiserver/#5381</a></li>
  <li>Fix custom NuGet repositories not working with Sonatype Nexus - <a href="https://github.com/DependencyTrack/dependency-track/pull/5381">apiserver/#5381</a></li>
  <li>Fix possible disclosure of private NuGet repository credentials to api.nuget.org - <a href="https://github.com/DependencyTrack/dependency-track/pull/5381">apiserver/#5381</a> / <a href="https://github.com/DependencyTrack/dependency-track/security/advisories/GHSA-83g2-vgqh-mgxc">GHSA-83g2-vgqh-mgxc</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/59?closed=1">API server milestone 4.13.5</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/44?closed=1">Frontend milestone 4.13.5</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<p>Special thanks to everyone who contributed code to implement enhancements and fix defects:</p>

<p><a href="https://github.com/colinfyfe">@colinfyfe</a>, <a href="https://github.com/framayo">@framayo</a>, <a href="https://github.com/jonbally">@jonbally</a>, <a href="https://github.com/snieguu">@snieguu</a>, <a href="https://github.com/stohrendorf">@stohrendorf</a></p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">f38abe7b93f7cb88f3bba4c78c30a9ce7dc45c0d</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">bf55097e63b46ed16042024636b855f676ba67e6e5824e7da80f3cec863a3f77</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">5aea8e0662f8aa4d9e53b52c14367c5345602e34</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">4a373de4d5aca924fb533ebfc7e1eb4fb5a249d81c948bd367a52fa53125a610</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">e441f28a656b710766a9fd85360872bc9330d14c</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">fb67bf767e2142b72dbd226b984a1faee9e491d108ccfd29860a49e0b5b15a12</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.13.5/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.13.5/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Important Notice:]]></summary></entry><entry><title type="html">v4.13.4</title><link href="https://docs.dependencytrack.org/2025/08/26/v4.13.4/" rel="alternate" type="text/html" title="v4.13.4" /><published>2025-08-26T00:00:00+00:00</published><updated>2025-08-26T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2025/08/26/v4.13.4</id><content type="html" xml:base="https://docs.dependencytrack.org/2025/08/26/v4.13.4/"><![CDATA[<p>This release primarily addresses the <a href="https://www.nist.gov/itl/nvd">removal of NVD 1.1 data feeds</a>, 
which caused Dependency-Track’s NVD mirroring process to fail. With this release, 
Dependency-Track will consume the new 2.0 data feeds.</p>

<p>Users who cannot perform this upgrade immediately can configure NVD mirroring to be performed via
the NVD REST API instead. Refer to the <a href="/datasources/nvd/#mirroring-via-nvd-rest-api">NVD datasource documentation</a> for details.</p>

<p><strong>Features:</strong></p>

<ul>
  <li>Migrate to NVD 2.0 data feeds - <a href="https://github.com/DependencyTrack/dependency-track/pull/5236">apiserver/#5236</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Handle URLs in composer package metadata pattern - <a href="https://github.com/DependencyTrack/dependency-track/pull/5234">apiserver/#5234</a></li>
  <li>Fix failing TrivyAnalysisTaskIntegrationTest - <a href="https://github.com/DependencyTrack/dependency-track/pull/5241">apiserver/#5241</a></li>
  <li>Handle <code class="language-plaintext highlighter-rouge">adduser</code> / <code class="language-plaintext highlighter-rouge">addgroup</code> removal in Debian base image - <a href="https://github.com/DependencyTrack/dependency-track/pull/5246">apiserver/#5246</a></li>
  <li>Fix inconsistent ordering in findings endpoints - <a href="https://github.com/DependencyTrack/dependency-track/pull/5247">apiserver/#5247</a></li>
  <li>Fix failing Trivy OS matching for distro versions with special characters - <a href="https://github.com/DependencyTrack/dependency-track/pull/5249">apiserver/#5249</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/58?closed=1">API server milestone 4.13.4</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/43?closed=1">Frontend milestone 4.13.4</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">048b46829358cfde1f4d90b9298984224c75f6ae</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">2ca674108a08bf71642ddec6704125fae720161c4c40268fd19557e8b116d9d0</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">b3eb198254783462dc7d147791537fa50b11483e</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">a8252f66f9b3c9253553e1d2a40fb0169f90c31895e36f57bc5992068ff473f5</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">827522ca8079450a8560a58a1b4e71add0a5d630</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">d0e604300d52047c32a98a51aa32e1cf2276525fa81557c4c95f1ad49f30d820</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.13.4/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.13.4/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[This release primarily addresses the removal of NVD 1.1 data feeds, which caused Dependency-Track’s NVD mirroring process to fail. With this release, Dependency-Track will consume the new 2.0 data feeds.]]></summary></entry><entry><title type="html">v4.13.3</title><link href="https://docs.dependencytrack.org/2025/08/04/v4.13.3/" rel="alternate" type="text/html" title="v4.13.3" /><published>2025-08-04T00:00:00+00:00</published><updated>2025-08-04T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2025/08/04/v4.13.3</id><content type="html" xml:base="https://docs.dependencytrack.org/2025/08/04/v4.13.3/"><![CDATA[<p><strong>Features:</strong></p>

<ul>
  <li>Add AWS Cognito configuration example - <a href="https://github.com/DependencyTrack/dependency-track/pull/5172">apiserver/#5172</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix too many query parameters when retrieving vuln aliases - <a href="https://github.com/DependencyTrack/dependency-track/pull/5167">apiserver/#5167</a></li>
  <li>Add apiserver health check to Compose files - <a href="https://github.com/DependencyTrack/dependency-track/pull/5171">apiserver/#5171</a></li>
  <li>Fix OSV ubuntu advisory containing severity without type - <a href="https://github.com/DependencyTrack/dependency-track/pull/5168">apiserver/#5168</a></li>
  <li>Handle dangling SPDX expression operators - <a href="https://github.com/DependencyTrack/dependency-track/pull/5173">apiserver/#5173</a></li>
  <li>Fix BOM export failing for projects of type NONE - <a href="https://github.com/DependencyTrack/dependency-track/pull/5178">apiserver/#5178</a></li>
  <li>Add whitespace sanitization in fuzzySearch CPE to fix CPE validation errors - <a href="https://github.com/DependencyTrack/dependency-track/pull/5176">apiserver/#5176</a></li>
  <li>Ensure VulnerableSoftware query is able to leverage indexes - <a href="https://github.com/DependencyTrack/dependency-track/pull/5177">apiserver/#5177</a></li>
  <li>Bulk load component relationships for BOM export - <a href="https://github.com/DependencyTrack/dependency-track/pull/5179">apiserver/#5179</a></li>
  <li>Improve Composer meta analyzer’s ability to deal with minified metadata - <a href="https://github.com/DependencyTrack/dependency-track/pull/5175">apiserver/#5175</a></li>
  <li>Fix failing v4.13.1 migration for H2 deployments that pre-date v4.11.0 - <a href="https://github.com/DependencyTrack/dependency-track/pull/5180">apiserver/#5180</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/57?closed=1">API server milestone 4.13.3</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/42?closed=1">Frontend milestone 4.13.3</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<p>Special thanks to everyone who contributed code to implement enhancements and fix defects:</p>

<p><a href="https://github.com/ch8matt">@ch8matt</a>, <a href="https://github.com/jonbally">@jonbally</a>, <a href="https://github.com/vdieieva">@vdieieva</a></p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">ba7866fa7b8be30f2058606ee77539b126ab61f1</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">8b6b2f29bdfd6f3e81ed2c9754a3ab2b4e27bbb9c33e52f720700d7e73558adb</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">70ac64f18c4b219d283df0c056e74f001287159b</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">1ae9984304854845cc5741d1dd1288e7b0a748539f448e0d0899ef635bb33c28</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">5eeea5e7bd1db7c40f45380580518eea7bdc53d7</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">f5bdf91803fb99b966f38be60b937adec96036b80bf7a793d32bb51b67f6fd7b</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.13.3/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.13.3/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Features:]]></summary></entry><entry><title type="html">v4.13.2</title><link href="https://docs.dependencytrack.org/2025/05/09/v4.13.2/" rel="alternate" type="text/html" title="v4.13.2" /><published>2025-05-09T00:00:00+00:00</published><updated>2025-05-09T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2025/05/09/v4.13.2</id><content type="html" xml:base="https://docs.dependencytrack.org/2025/05/09/v4.13.2/"><![CDATA[<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix failing v4.13.1 migration for MSSQL deployments that pre-date v4.11.0 - <a href="https://github.com/DependencyTrack/dependency-track/pull/4911">apiserver/#4911</a></li>
  <li>Fix summary notifications not sent when “skip if unchanged” is enabled - <a href="https://github.com/DependencyTrack/dependency-track/pull/4913">apiserver/#4913</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/56?closed=1">API server milestone 4.13.2</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/41?closed=1">Frontend milestone 4.13.2</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">845f970ba9c00a26d6d0b5a77c24cd12ee5feeea</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">f1d66b81a44d7d3528fad42d1e1fb498e2151c2c5e78c1070942be54456bf7d1</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">61d5c535ab19a6f67e48ee8efa20bf9656d084f7</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">4494b0090cd699db2099248c0fdd67a07d130731bbc476287251aa84d008bfa4</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">987a3b3a37fad4143b295ff9a7fcbacef7e915f4</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">94fc935e62a657e5f10bff9b9a8657841f0c2f2e53fd234c881580874bb95f14</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.13.2/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.13.2/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Fixes:]]></summary></entry><entry><title type="html">v4.13.1</title><link href="https://docs.dependencytrack.org/2025/04/30/v4.13.1/" rel="alternate" type="text/html" title="v4.13.1" /><published>2025-04-30T00:00:00+00:00</published><updated>2025-04-30T00:00:00+00:00</updated><id>https://docs.dependencytrack.org/2025/04/30/v4.13.1</id><content type="html" xml:base="https://docs.dependencytrack.org/2025/04/30/v4.13.1/"><![CDATA[<p><strong>Features:</strong></p>

<ul>
  <li>Show collection projects using a tag in the tags list - <a href="https://github.com/DependencyTrack/frontend/pull/1241">frontend/#1241</a></li>
</ul>

<p><strong>Fixes:</strong></p>

<ul>
  <li>Fix <code class="language-plaintext highlighter-rouge">NEW_VULNERABILITIES_SUMMARY</code> notification dispatch failing for PostgreSQL - <a href="https://github.com/DependencyTrack/dependency-track/pull/4859">apiserver/#4859</a></li>
  <li>Fix team email addresses not being available when publishing scheduled notification emails - <a href="https://github.com/DependencyTrack/dependency-track/pull/4860">apiserver/#4860</a></li>
  <li>Prevent duplicate tag names and relationships - <a href="https://github.com/DependencyTrack/dependency-track/pull/4861">apiserver/#4861</a></li>
  <li>Fix missing <code class="language-plaintext highlighter-rouge">NONE</code> value in classifier check constraint - <a href="https://github.com/DependencyTrack/dependency-track/pull/4887">apiserver/#4887</a></li>
  <li>Improve stability of tag binding - <a href="https://github.com/DependencyTrack/dependency-track/pull/4885">apiserver/#4885</a></li>
  <li>Fix tag deletion failing when tag is used by project collection logic - <a href="https://github.com/DependencyTrack/dependency-track/pull/4888">apiserver/#4888</a></li>
</ul>

<p>For a complete list of changes, refer to the respective GitHub milestones:</p>

<ul>
  <li><a href="https://github.com/DependencyTrack/dependency-track/milestone/55?closed=1">API server milestone 4.13.1</a></li>
  <li><a href="https://github.com/DependencyTrack/frontend/milestone/40?closed=1">Frontend milestone 4.13.1</a></li>
</ul>

<p>We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub &amp; Slack to testing of fixes.</p>

<h6 id="dependency-track-apiserverjar">dependency-track-apiserver.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">b5e613f1f484179e770333828ef25c020ed9f03a</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">c88b2e7879b1d534741ce5483f96621b650d6a4dcacabb470eeeeb43e7c7c627</td>
    </tr>
  </tbody>
</table>

<h6 id="dependency-track-bundledjar">dependency-track-bundled.jar</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">173511869286b1335950bd07477421d684c96251</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">53c7fca478125fad1c35d6732815a6c09e120abc6ea57a8a88eb2af3ed2efab2</td>
    </tr>
  </tbody>
</table>

<h6 id="frontend-distzip">frontend-dist.zip</h6>

<table>
  <thead>
    <tr>
      <th style="text-align: left">Algorithm</th>
      <th style="text-align: left">Checksum</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td style="text-align: left">SHA-1</td>
      <td style="text-align: left">ad0926abed617069934cf198670d7dba4e3f6867</td>
    </tr>
    <tr>
      <td style="text-align: left">SHA-256</td>
      <td style="text-align: left">0ae8950c4aa0713dc52812225720cb27cf2da17d32badcda9c2be8c3872720e6</td>
    </tr>
  </tbody>
</table>

<h6 id="software-bill-of-materials-sbom">Software Bill of Materials (SBOM)</h6>

<ul>
  <li>API Server: <a href="https://github.com/DependencyTrack/dependency-track/releases/download/4.13.1/bom.json">bom.json</a></li>
  <li>Frontend: <a href="https://github.com/DependencyTrack/frontend/releases/download/4.13.1/bom.json">bom.json</a></li>
</ul>]]></content><author><name>Steve Springett</name><email>steve.springett@owasp.org</email></author><summary type="html"><![CDATA[Features:]]></summary></entry></feed>