Introducing the KernelScan Analyzer Plugin for Dependency-Track 5

Dependency-TrackLinux kernelSBOMCVE triageOpen source

KernelScan now has a native analyzer plugin for Dependency-Track 5. It’s open-source, runs in-process in your DT apiserver, and surfaces the kernel CVEs KernelScan has determined are reachable in your build’s .config — under native CVE-* / NVD identity, so findings merge with DT’s own NVD records instead of adding to the thousand-CVE version-match flood.

Here’s the part that’s easy to miss: Dependency-Track 5 (codename Hyades) only reached general availability on June 9, 2026 — the platform’s most extensive redesign since it launched, and recent enough that plenty of teams haven’t upgraded yet. One of its headline additions is a proper plugin extension point — and we moved on it early: KernelScan is already a first-class analyzer in DT 5, right alongside its built-in vulnerability sources.

KernelScan findings in a Dependency-Track project

The plugin’s findings in a Dependency-Track project — the config-reachable kernel CVEs, attributed to the kernelscan analyzer.

Why this matters

Dependency-Track’s built-in matching keys off CPE and OSV version ranges. For the Linux kernel that’s config-blind: it flags every CVE for your kernel version, whether or not the vulnerable code is even compiled into your build. A typical appliance ends up with thousands of “applicable” kernel CVEs — the overwhelming majority in subsystems it never ships.

KernelScan already answers the only question that matters: is this CVE reachable in my kernel, built the way I built it? The new plugin brings that answer natively into Dependency-Track.

What the plugin does

  • Only what’s reachable. KernelScan works out which CVEs are actually reachable in your build’s .config; the plugin reports exactly that set. A typical appliance drops from thousands of NVD matches to the few hundred that apply.
  • Native CVE / NVD identity. Findings carry the plain CVE-… id under source NVD, so they merge with DT’s own NVD records — no duplicate rows, one audit trail.
  • Catches what NVD misses. The plugin surfaces kernel CVEs before NVD’s matching catches up — including stable-branch backports NVD’s data doesn’t reflect. Take CVE-2024-26655, a posix-clock memory leak backported into the 5.15, 6.1 and 6.6 LTS branches: NVD’s version data tracks only the mainline 6.7 introduction and misses those kernels entirely. The plugin flags them; DT’s stock analyzer doesn’t.
  • One click to the full picture. Every finding links straight to its KernelScan CVE page — per-branch fix versions, the config-mapping reasoning, and more.

Findings from the plugin, verdicts from a VEX import

DT’s v5 analyzers produce findings only — so the plugin reports the reachable CVEs, and that’s where its job ends. To get the config-gated CVEs marked Not Affected, you import KernelScan’s product VEX into Dependency-Track (a one-line PUT /api/v1/vex from a small in-network job). DT’s own VEX importer then applies each verdict — with the exact CONFIG_* justification — onto the plugin’s findings. The plugin never pushes or applies the VEX; that’s DT’s import doing what it already does. Together you get a short, actionable audit view instead of a wall of noise.

Get started

The plugin is open-source under Apache-2.0. Grab the JAR from the latest release, mount it into your apiserver’s lib/ directory, and configure it with your KernelScan API key under Administration → Analyzers.