KernelScan now has a native analyzer plugin for
Dependency-Track 5. It’s open-source, runs in-process in
your DT apiserver, and surfaces the kernel CVEs KernelScan has determined are
reachable in your build’s .config — under native
CVE-* / NVD identity, so findings merge with DT’s own
NVD records instead of adding to the thousand-CVE version-match flood.
Here’s the part that’s easy to miss: Dependency-Track 5 (codename Hyades) only reached general availability on June 9, 2026 — the platform’s most extensive redesign since it launched, and recent enough that plenty of teams haven’t upgraded yet. One of its headline additions is a proper plugin extension point — and we moved on it early: KernelScan is already a first-class analyzer in DT 5, right alongside its built-in vulnerability sources.
The plugin’s findings in a Dependency-Track project — the
config-reachable kernel CVEs, attributed to the kernelscan analyzer.
Why this matters
Dependency-Track’s built-in matching keys off CPE and OSV version ranges. For the Linux kernel that’s config-blind: it flags every CVE for your kernel version, whether or not the vulnerable code is even compiled into your build. A typical appliance ends up with thousands of “applicable” kernel CVEs — the overwhelming majority in subsystems it never ships.
KernelScan already answers the only question that matters: is this CVE reachable in my kernel, built the way I built it? The new plugin brings that answer natively into Dependency-Track.
What the plugin does
- Only what’s reachable. KernelScan works out which CVEs are
actually reachable in your build’s
.config; the plugin reports exactly that set. A typical appliance drops from thousands of NVD matches to the few hundred that apply. - Native CVE / NVD identity. Findings carry the plain
CVE-…id under sourceNVD, so they merge with DT’s own NVD records — no duplicate rows, one audit trail. - Catches what NVD misses. The plugin surfaces kernel CVEs before
NVD’s matching catches up — including stable-branch backports
NVD’s data doesn’t reflect. Take
CVE-2024-26655, a posix-clock memory leak backported into the 5.15, 6.1 and 6.6 LTS branches: NVD’s version data tracks only the mainline 6.7 introduction and misses those kernels entirely. The plugin flags them; DT’s stock analyzer doesn’t. - One click to the full picture. Every finding links straight to its KernelScan CVE page — per-branch fix versions, the config-mapping reasoning, and more.
Findings from the plugin, verdicts from a VEX import
DT’s v5 analyzers produce findings only — so the plugin reports the
reachable CVEs, and that’s where its job ends. To get the config-gated CVEs
marked Not Affected, you import KernelScan’s product VEX into
Dependency-Track (a one-line PUT /api/v1/vex from a small in-network
job). DT’s own VEX importer then applies each verdict — with the exact
CONFIG_* justification — onto the plugin’s findings. The
plugin never pushes or applies the VEX; that’s DT’s import doing what it
already does. Together you get a short, actionable audit view instead of a wall of
noise.
Get started
The plugin is open-source under Apache-2.0. Grab the JAR from the latest release,
mount it into your apiserver’s lib/ directory, and configure it
with your KernelScan API key under Administration → Analyzers.
- Source, releases & docs: github.com/kernelscan/kernelscan-dt-plugin
- Setup walkthrough: Dependency-Track in the KernelScan docs