Dependency-Track logov4.13

Starting with this release, we’re publishing a new container image variant for the apiserver and bundled distributions. The variant is based on Alpine Linux and uses jlink to ship a minimal Java Runtime Environment (JRE). As a result, image size is decreased by over 55% (~350MB vs. ~150MB uncompressed), and attack surface is reduced due to fewer operating system packages. It uses Java 25 and enables compact object headers by default, leading to lower memory footprint.

To use the new image variant, append the -alpine suffix to the image tag, e.g.:

The previous Debian-based image variant continues to be the default for now, but will eventually be discontinued in a future release. Users experiencing issues with alpine images can safely fall back to non-alpine variants.

Features:

Fixes:

For a complete list of changes, refer to the respective GitHub milestones:

We thank all organizations and individuals who contributed to this release, from logging issues to taking part in discussions on GitHub & Slack to testing of fixes.

Special thanks to everyone who contributed code to implement enhancements and fix defects:

@ElenaStroebele, @arjavdongaonkar, @aurifi, @ch8matt, @illenko, @sahibamittal, @snieguu, @stohrendorf

dependency-track-apiserver.jar
Algorithm Checksum
SHA-1 3964cf821761609912487077fa41d513dad37d1a
SHA-256 8f2aa10424403b2b201d0c48b243ea3bbe458761
dependency-track-bundled.jar
Algorithm Checksum
SHA-1 1048a039391992fc36b23433d8987689baca33e68cc2130254787d1a3d1c66cc
SHA-256 ab47deb0c5be2d947d57cf5862fef714023b4ce4d794ac00a855cf7590eb111e
frontend-dist.zip
Algorithm Checksum
SHA-1 525b47c72fb3bdbb675b5c5414319e5f19e43b03
SHA-256 84440921692e95c88378e1f82738ccea24c2fb038083b42b3f1c98b1f6702a4a
Software Bill of Materials (SBOM)