Skip to content

Commit 8a6251f

Browse files
authored
Merge pull request #5251 from nscuro/changelog-v4.13.4
2 parents afb0291 + 4f9c844 commit 8a6251f

1 file changed

Lines changed: 65 additions & 0 deletions

File tree

docs/_posts/2025-08-26-v4.13.4.md

Lines changed: 65 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,65 @@
1+
---
2+
title: v4.13.4
3+
type: patch
4+
---
5+
6+
This release primarily addresses the [removal of NVD 1.1 data feeds](https://www.nist.gov/itl/nvd),
7+
which caused Dependency-Track's NVD mirroring process to fail. With this release,
8+
Dependency-Track will consume the new 2.0 data feeds.
9+
10+
Users who cannot perform this upgrade immediately can configure NVD mirroring to be performed via
11+
the NVD REST API instead. Refer to the [NVD datasource documentation] for details.
12+
13+
**Features:**
14+
15+
* Migrate to NVD 2.0 data feeds - [apiserver/#5236]
16+
17+
**Fixes:**
18+
19+
* Handle URLs in composer package metadata pattern - [apiserver/#5234]
20+
* Fix failing TrivyAnalysisTaskIntegrationTest - [apiserver/#5241]
21+
* Handle `adduser` / `addgroup` removal in Debian base image - [apiserver/#5246]
22+
* Fix inconsistent ordering in findings endpoints - [apiserver/#5247]
23+
* Fix failing Trivy OS matching for distro versions with special characters - [apiserver/#5249]
24+
25+
For a complete list of changes, refer to the respective GitHub milestones:
26+
27+
* [API server milestone 4.13.4](https://github.com/DependencyTrack/dependency-track/milestone/58?closed=1)
28+
* [Frontend milestone 4.13.4](https://github.com/DependencyTrack/frontend/milestone/43?closed=1)
29+
30+
We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub & Slack to testing of fixes.
31+
32+
###### dependency-track-apiserver.jar
33+
34+
| Algorithm | Checksum |
35+
|:----------|:---------|
36+
| SHA-1 | |
37+
| SHA-256 | |
38+
39+
###### dependency-track-bundled.jar
40+
41+
| Algorithm | Checksum |
42+
|:----------|:---------|
43+
| SHA-1 | |
44+
| SHA-256 | |
45+
46+
###### frontend-dist.zip
47+
48+
| Algorithm | Checksum |
49+
|:----------|:-----------------------------------------------------------------|
50+
| SHA-1 | 827522ca8079450a8560a58a1b4e71add0a5d630 |
51+
| SHA-256 | d0e604300d52047c32a98a51aa32e1cf2276525fa81557c4c95f1ad49f30d820 |
52+
53+
###### Software Bill of Materials (SBOM)
54+
55+
* API Server: [bom.json](https://github.com/DependencyTrack/dependency-track/releases/download/4.13.4/bom.json)
56+
* Frontend: [bom.json](https://github.com/DependencyTrack/frontend/releases/download/4.13.4/bom.json)
57+
58+
[NVD datasource documentation]: {{ site.baseurl }}{% link _docs/datasources/nvd.md %}#mirroring-via-nvd-rest-api
59+
60+
[apiserver/#5234]: https://github.com/DependencyTrack/dependency-track/pull/5234
61+
[apiserver/#5236]: https://github.com/DependencyTrack/dependency-track/pull/5236
62+
[apiserver/#5241]: https://github.com/DependencyTrack/dependency-track/pull/5241
63+
[apiserver/#5246]: https://github.com/DependencyTrack/dependency-track/pull/5246
64+
[apiserver/#5247]: https://github.com/DependencyTrack/dependency-track/pull/5247
65+
[apiserver/#5249]: https://github.com/DependencyTrack/dependency-track/pull/5249

0 commit comments

Comments
 (0)