Dependency Track is an open source component analysis platform from OWASP. You upload the SBOM of your application, and Dependency Track keeps track of the components inside it. It checks those components against vulnerability sources like the National Vulnerability Database, GitHub Advisories and OSV. It also lets you define policies and send notifications when something new shows up. In short: it tells you which of your applications are affected when the next vulnerable library hits the news. Recently Dependency Track got an upgrade and version 5 was released. So, time to upgrade! However, that turned out not to be as easy as expected. It took us 2 attempts. Our first attempt failed completely, so we took a different route. Here is what we tried and the two things that cost us the most time. Big shout out to Jef, who looked over my shoulder during the upgrade and helped tackling the issues when we got stuck. Two approaches in the documentation The Dependency Track documenta...
Recently I tried to spin up a new container and Docker refused with this error: OSError: [Errno 28] No space left on device: Not the most helpful message, but the root cause was simple: the disk used by the Docker engine was full. As you can see in the screenshot below, I was eating up almost the full 250GB available for Docker: Where did my disk space go? Before deleting anything, let's find out what is actually using the space. Docker has a built-in command for this: docker system df This gives you a summary of the space used by images, containers, local volumes and build cache. Want more detail per item? Add the verbose flag: docker system df -v In my case, the usual suspects were to blame: old images, stopped containers and build cache that had been piling up for months. Cleaning up Start with the safest options and work your way up. Remove all stopped containers: docker container prune Remove dangling images (untagged layers that are no longer refer...