logo

OWASP's Dependency-Track tool update: Key changes — and limitations

ID: bad5094f-05c1-5df1-9a43-9d1a8ba44281

STIX ID: report--bad5094f-05c1-5df1-9a43-9d1a8ba44281

Feed Name: ReversingLabs Blog

Date Published: 2024-10-22

Date Updated: 2026-04-29

Author: [email protected] (John P. Mello Jr.)

...
...

OWASP released Dependency-Track 4.12.0 with more granular tag-based controls, a global policy violation audit view, authenticated badges, and a modernized tech stack (Java 21, Jakarta EE 10, Jetty 12, OpenAPI v3) to improve performance and security. Experts commend the usability and visibility gains but stress that SCA and SBOM-only workflows have notable gaps—such as reliance on manual tagging, limited prioritization by business context or reachability, and lack of artifact/binary analysis—recommending organizations augment SCA with techniques like binary analysis and reproducible builds to better mitigate evolving software supply chain risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.