Dependency Track 4.x — End of Life

Active
EOL: Dec 9, 2026in 134d8 releases in this series0 CVEs

Dependency Track 4.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
4.14Mar 9, 2026Dec 9, 20264.14.3Active
4.13Apr 7, 2025Mar 9, 20264.13.6EOL
4.12Oct 1, 2024Apr 7, 20254.12.7EOL
4.11May 7, 2024Oct 1, 20244.11.7EOL
4.10Dec 8, 2023May 7, 20244.10.1EOL
4.9Oct 16, 2023Dec 8, 20234.9.1EOL
4.8Apr 18, 2023Oct 16, 20234.8.2EOL
4.7Dec 16, 2022Apr 18, 20234.7.1EOL

CVEs affecting Dependency Track 4.x (0)

No CVEs tracked for Dependency Track 4.x.

Dependency Track 4.x will reach end of life — migrate to Dependency Track 5.x

Dependency Track 5.x is the next major release. Plan your upgrade before Dependency Track 4.x stops receiving security patches.

See Dependency Track 5.x

Frequently asked questions

Is Dependency Track 4 end of life?

Partially. Some Dependency Track 4.x releases have reached EOL. Check the version table above for the exact status of each sub-release.

What CVEs affect Dependency Track 4?

No CVEs are currently tracked for Dependency Track 4.x in our database. This may mean no vulnerabilities have been recorded yet, or the data is still syncing.

What is the latest Dependency Track 4 version?

The latest Dependency Track 4.x patch release is 4.14.3, released on July 20, 2026. Always run the latest patch to benefit from all security fixes.

How to migrate from Dependency Track 4 to Dependency Track 5?

To migrate from Dependency Track 4 to Dependency Track 5: (1) review the official Dependency Track 5 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Dependency Track 4 in production?

Dependency Track 4 is still supported and safe for production use until December 9, 2026. Ensure you are running the latest patch version (4.14.3) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA