Published October 5, 2026 | Version v3.0.1

RADAR-base/ManagementPortal: ManagementPortal 3.0.1

Description

What's Changed

  • Security fixes: same-major dependency bumps for the HIGH/CRITICAL CVEs found in the 2026-09-23 Trivy scan, including Jackson, Spring, snakeyaml and ktor. Also migrated to Kotlin 2.3.20 and radar-commons 1.2.7. The CVEs and how each was fixed are listed in the PR. By @pvannierop in https://github.com/RADAR-base/ManagementPortal/pull/1086
  • Fix login with the internal auth server when the public URL can't be reached from inside the pod by @pvannierop in https://github.com/RADAR-base/ManagementPortal/pull/1087
  • Include the audience when creating Hydra OAuth clients by @mpgxvii in https://github.com/RADAR-base/ManagementPortal/pull/1085, brought into dev by @pvannierop in https://github.com/RADAR-base/ManagementPortal/pull/1089
  • Widen source_type.description so the source-type import from the catalogue server doesn't fail on long descriptions by @pvannierop in https://github.com/RADAR-base/ManagementPortal/pull/1088
  • CI: replace the Snyk scans with Trivy by @pvannierop in https://github.com/RADAR-base/ManagementPortal/pull/1090

Important Notes

  • No configuration changes are needed when upgrading from 3.0.0.
  • The source_type.description column is widened by a Liquibase migration that runs automatically on startup.

Full Changelog: https://github.com/RADAR-base/ManagementPortal/compare/v3.0.0...v3.0.1

Files

RADAR-base/ManagementPortal-v3.0.1.zip

Files (2.2 MB)

Name Size Download all
md5:c890a8666b1b93a4eb725e5bcb27ee63
2.2 MB Preview Download

Additional details

Related works