Skip to content

Commit

Permalink
docs: mandatory upgrade notice
Browse files Browse the repository at this point in the history
  • Loading branch information
jeremylong committed Jul 6, 2024
1 parent bcbbe1c commit f22ebf1
Show file tree
Hide file tree
Showing 2 changed files with 12 additions and 9 deletions.
13 changes: 8 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,15 +12,18 @@ Documentation and links to production binary releases can be found on the [githu

This product uses the NVD API but is not endorsed or certified by the NVD.

## 9.0.0 Upgrade Notice
## Mandatory Upgrade Notive

**Upgrading to 9.0.0 or later is mandatory**; previous versions of dependency-check
utilize the NVD data feeds which will be deprecated on Dec 15th, 2023. Versions
earlier then 9.0.0 are no longer supported and could fail to work after Dec 15th, 2023.
**Upgrading to 10.0.2 or later is mandatory**

Older versions of dependency-check are causing numerous, duplicative requests that
end in processing failures are causing unnecassary load on the NVD API. Dependency-check
10.0.2 uses an updated `User-Agent` header that will allow the NVD to block calls
from the older client.

### NVD API Key Highly Recommended

With 9.0.0 dependency-check has moved from using the NVD data-feed to the NVD API.
Dependency-check has moved from using the NVD data-feed to the NVD API.
Users of dependency-check are **highly** encouraged to obtain an NVD API Key; see https://nvd.nist.gov/developers/request-an-api-key
Without an NVD API Key dependency-check's updates will be **extremely slow**.
Please see the documentation for the cli, maven, gradle, or ant integrations on
Expand Down
8 changes: 4 additions & 4 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@

## Supported Versions

| Version | Supported |
| ---------|--------------------|
| 10.0.0+ | :white_check_mark: |
| <= 9.2.0 | :x: |
| Version | Supported |
| ----------|--------------------|
| 10.0.2+ | :white_check_mark: |
| <= 10.0.1 | :x: |

## Reporting a Vulnerability

Expand Down

0 comments on commit f22ebf1

Please sign in to comment.