OWASP Releases Enhanced Dependency-Check Tool with Advanced Tagging and Policy Management Features
OWASP has released an updated version of its dependency-check tool, version 4.12.0, which identifies vulnerabilities in third-party software components, enforces policy compliance, and generates a CycloneDX-based Software Bill of Materials (SBOM). Key updates include enhanced tag features for improved control over security alerts and SBOM validation, a new tag management view, a global policy violation audit view, and authorization for security status badges. These changes offer more granular control over managing third-party dependencies, though experts note that managing software risk remains an ongoing challenge despite these improvements.
https://securityboulevard.com/2024/10/owasps-dependency-check-tool-update-key-changes-and-limitations/
ps. I think Security Boulevard (https://securityboulevard.com/) is a little bit confused here.
https://securityboulevard.com/2024/10/owasps-dependency-check-tool-update-key-changes-and-limitations/
The original news links to Dependency Track instead of Dependency Check.
It talks about a new release of Dependency TRACK (4.12.0), which is not new (3 weeks ago) and all the changes (improved SBOM support, Java version update etc)
However, the news talks about Dependency CHECK (11.0.0), which actually had a major release 2 days ago (so this is news), however, the article talks about all the latest Dependency Track improvements...
In fact, the site is a proxy to the original article from https://www.reversinglabs.com/blog/owasp-dependency-track-update-key-changes-and-limitations-on-software-risk-management
I am contacting the writer BTW.
That's the problem when news portals simply repeat what they read, without checking the contents.
Comments
Post a Comment