Releasing OWASP Dependency-Track
August 18, 2026 ยท View on GitHub
This document describes the process of releasing a new version of Dependency-Track.
Patch Releases
Patch releases (e.g. 5.0.1) ship bugfixes and security fixes off a release branch.
No new features, no breaking changes.
Important
Backport, don't forward-port. Merge the fix on main first, then cherry-pick onto the patch branch.
Direct commits on the patch branch are fine for fixes that no longer apply to main.
1. Cut or check out the patch branch
First patch in a series, branched from the GA tag:
git checkout -b 5.0.x 5.0.0
git push -u origin 5.0.x
Subsequent patches:
git checkout 5.0.x
git pull
2. Bump the Maven version (first patch only)
Run from the repository root:
mvn versions:set -DnewVersion=5.0.1-SNAPSHOT -DgenerateBackupPoms=false
Commit (signed off, i.e. with --signoff). Follow-up patches are bumped automatically by the Release CI.
3. Cherry-pick backports
Open one PR per backport against the patch branch, using the branch name backport-pr-<original-PR-number>:
git checkout -b backport-pr-1234 5.0.x
git cherry-pick -x -s <sha>
Resolve any conflicts, then git cherry-pick --continue.
Tip
Claude Code users can run /backport <original-PR-number> [target-branch] to automate
steps 3 and 4. See .claude/skills/backport.
4. Flyway migrations
When backporting a migration, cherry-pick the file as-is. Do not rename or re-timestamp it.
Out-of-order execution is enabled, so users upgrading from a patch release to the next minor
will still get any older mainline migrations applied. See Flyway: outOfOrder.
Prefer cherry-picking the same migration from main over authoring a new patch-only one.
5. Run the release
Once CI is green on the patch branch, follow the Stable Version workflow below,
selecting the patch branch (e.g. 5.0.x) for the Branch parameter.
Releasing
Stable Version
To release a new stable version such as 5.7.0 or 5.7.1:
- Ensure the current state in the target branch is ready to be released.
- Navigate to the Release CI workflow.
- Run the workflow with the following parameters:
- Branch: Select the branch to release from (e.g.
mainfor new releases,5.6.xfor bugfixes, see Patch Releases). - Release version: Leave empty to use current
SNAPSHOTversion (e.g.5.7.0-SNAPSHOTbecomes5.7.0), or specify a custom version. - Development version: Leave empty (in which case the patch version will be bumped, e.g.
5.7.0->5.7.1-SNAPSHOT), or specify a custom nextSNAPSHOTversion. - Dry run: Enable to test the release process without making any changes.
- Branch: Select the branch to release from (e.g.
Release Candidate
To release a prerelease such as 5.7.0-rc.1:
- Ensure the current state in the target branch is ready to be released.
- Navigate to the Release CI workflow.
- Run the workflow with the following parameters:
- Branch: Select the branch (usually
main). - Release version: Enter the prerelease version (e.g.
5.7.0-rc.1). - Development version: Leave empty (in which case it will be bumped to
5.7.0-rc.2-SNAPSHOT), or explicitly set to5.7.0-SNAPSHOT.
- Branch: Select the branch (usually