Dependency Track is an open source component analysis platform from OWASP. You upload the SBOM of your application, and Dependency Track keeps track of the components inside it. It checks those components against vulnerability sources like the National Vulnerability Database, GitHub Advisories and OSV. It also lets you define policies and send notifications when something new shows up. In short: it tells you which of your applications are affected when the next vulnerable library hits the news. Recently Dependency Track got an upgrade and version 5 was released. So, time to upgrade! However, that turned out not to be as easy as expected. It took us 2 attempts. Our first attempt failed completely, so we took a different route. Here is what we tried and the two things that cost us the most time. Big shout out to Jef, who looked over my shoulder during the upgrade and helped tackling the issues when we got stuck. Two approaches in the documentation The Dependency Track documenta...