Release Notes: Black Duck Binary Analysis

Black Duck Binary Analysis Release Notes

Version
latest

2026.6.0

End of Life for Debian 11 support for Virtual Appliance

  • As of the 2025.12.0 version of the virtual appliance, we are migrating from Debian 11 to Debian 13 Trixie.
  • Debian 11 Bullseye reached the end of its regular support on August 14, 2024. It then entered the Long-Term Support (LTS) phase on August 15, 2024, which will continue until August 31, 2026.
  • During the LTS phase, Debian 11 will receive critical security updates and essential bug fixes, but not all packages are covered. After August 31, 2026, Debian 11 will be considered fully end-of-life.
  • BDBA will be offering 2 versions of the virtual appliance in a Debian 11 and 13 software option for the next 2 releases 2025.12.0 and 2026.3.0 releases.
  • As of 2026.6.0 version, we will only support the Debian 13 virtual appliance image.
  • Customers should plan to migrate their images to a Debian 13 virtual machine by June of 2026.
  • BDBA 2025.9.0 Base image will be the final Debian 11 based base image. As of BDBA 2025.12.0 the base image will be based on Debian 13.

Rapid Scan Static Default Setting Update

Starting in version 2026.6.0, Rapid Scan Static (Sigma) is disabled by default for both new and existing scans.

Worker/Frontend

Enhancements

Jira No. Description
PROTSC-3906 Show search result count in applications-page
PROTSC-3856 Edit Triage -page: Add weblinks to BDSA and CVE data

Bug Fixes

Jira No. Description
PSC-5207 BDBA detects version 2.7.7 for antlr component but should detect 2.7.7.redhat-7
PSC-5180 UI crashes when loading result from 2023
PSC-5168 glibc versionless should be 2.36-9+deb12u8 - child of libnsl
PSC-5157 BDBA incorrectly identifies log4j-core 2.25.0 as log4j 1.2.17
PSC-5155 BDBA incorrectly identifies ANTLR runtime libraries as full ANTLR tools
PSC-5153 Potential False Debian Attribution on NTP Component +dfsg-4, Suffix Incorrect
PSC-5152 (chainguard) - BDBA incorrectly detects log4j-core 2.25.3 as apache-log4j 1.2.17
PSC-5151 commons-text-1.10.0.jar misidentified as commons-lang3-3.12.0
PSC-5149 Missing pagination and "Could not fetch custom data" for large subgroup counts (~4000+)
PSC-5148 UI taking longer when searching for the word Linux in components
PSC-5146 (chainguard) commons-io 1.3.2 - wrong version
PSC-5145 OpenSearch artifacts in image are being identified as Elasticsearch
PSC-5144 moby/moby Go sub-modules incorrectly mapped to docker:docker CPE
PSC-5142 netty 1.75.0 - wrong version
PSC-5140 (chainguard) c-ares 1.3.2 and 1.5.0 - wrong versions
PSC-5128 (chainguard) python image - versionless components
PSC-5118 BDBA incorrectly reports outstanding CVEs for SUSE Linux distro
PSC-5103 Docker Hardened Images (DHI) - FP Security Vulnerabilities
PSC-5080 BDBA Go module parser ignores replace directives and reports incorrect version
PSC-5078 Document the option disable the GO legacy signature matching optio
PSC-5074 False positive CVE-2026-25537 in NPM jsonwebtoken component
PSC-5070 False positive components on pch file, libatomic and visual_studio_runtime
PSC-5069 BDBA installation- and Administrator guide not up to date
PSC-5067 Triage comment has no limit on UI or API, but has one with configuration file
PSC-5040 APR 1.2.5 mismatch in binary standalone and integrated
PSC-5026 Incorrect distro identification (Rocky vs RHEL)
PSC-5023 rpm file defaults to rhel as the distro even when no vendor info is present
PSC-5021 Fetch with additional auth headers fails on pre-signed S3 redirect
PSC-5016 CVSS fallback is not applied when exporting vulnerabilities report
PSC-5010 Wrong version matched for util-linux
PSC-5009 BDBA Integrated - Boost DLL version detection extracts MSVC toolset (14.2) instead of library version (1.88.0)
PSC-4971 FP: CVE-2022-4899 on zstd 1.5.4
PSC-4952 Scanner failing to process signed binary, unsigned extracts as expected
PSC-4937 SBOM sha1sum from wrong file in Python components
PSC-4916 package-lock.json file showing no artifacts
PSC-4888 BDBA reports .NET Core when we don't use it
PROTSC-4638 Scans failing in BDBA-appliance
PROTSC-4635 Exporting critical and high vulnerabilities exports all
PROTSC-4633 API - Bootstrap airgapped installation upload not working
PROTSC-4628 Sales view user is unable to view vulnerability analysis
PROTSC-4627 Upload vendor lib is broken
PROTSC-4624 Issue with component search
PROTSC-4593 BOM API lists BDSAs even if BDSA is disabled
PROTSC-4424 Sending technical notification emails fails in production