In this release:

Release date: May 14, 2025

Enhancements

License Server Enhancements

Support for Jtest Unit Test Bulk Creation Tiers

Jtest Unit Test Bulk Creation Tiers license feature enables users to create unit test cases for more than one file at a time. When hosted on a License Server, this license allows centralized tracking of token availability and usage across your team. See Types of Licenses for more information.

Support for Contributing Developers Usage Data

License Server collects statistics on analyzed files and their associated Git repositories, as reported by the C/C++test CT tool. Users can download a ZIP archive containing the full dataset or view a summarized version of the usage data directly in the UI. See Contributing Developers - Usage Data for more information.

Improved Widget Search when Adding New Widgets

Users can now search for widgets by category, name, or keywords in their descriptions when adding a new widget. See Adding Widgets for more information.

External System Integration Enhancements

Integration with Azure Key Vault

DTP can now retrieve and use its database password stored in Azure Key Vault, enabling secure and centralized credential management. See Configuring the Database Connection for more information.

Integration with DOORS Next

Users can create a task or defect in DOORS Next from the Violations and Test Explorers. See Manually Creating Tasks or Defects in DOORS Next for more information.

Integrating with External Systems via CSV File

You can now track requirements from nearly any external system using simple CSV files. This feature allows you to monitor traceability between Parasoft DTP tests and requirements stored in any external system not natively supported by DTP by associating projects with a CSV output from your external system that is published to an HTTP server. With it, you can track how your system's requirements are tested and view test execution statuses in DTP through DTP reports. In addition, associations can be seamlessly imported into Parasoft testing products like SOAtest and C++test. See Integrating with Other External Systems for more information.

Other Notes

  • Support for PostgreSQL 17 has been added.
  • Support for Windows Server 2025 has been added.
  • Support for codeBeamer 2.1 has been added.
  • Support for Polarion 2404 has been added.
  • Polarion Requirement Traceability widget now supports filtering data by specific requirement types.
  • Added REST endpoints to review and delete users in the User Administration database who were originally imported from LDAP but are no longer present in the directory. See Configuring LDAP for more information.
  • Improved logging of errors to provide clearer diagnostics when issues occur with OpenID Connect (OIDC) configuration.
  • When creating a new Filter, the "Do not show" priority is now selected by default in the Included Priorities section of Filter Settings.
  • Added instructions for deploying DTP in Kubernetes environments that enforce volume mount security policies.
  • Redesigned the Deviations Report in Compliance Packs to support displaying more than 1000 deviations.
  • Introduced a more flexible versioning scheme for Extension Packs, allowing older versions of Extension Packs to be compatible with newer versions of DTP.
  • Added support for CWE 4.17 and CWE Top 25 2024 (Jtest and dotTEST).
  • Added support for MISRA C 2025.

Deprecated or No Longer Supported

  • Support for Oracle 18c has ended.
  • Support for MySQL 5.7 has ended.
  • Support for Windows 10 has been deprecated.
  • Java 11 is no longer supported for OWASP Dependency-Check Pack. Java 17 is required.
  • "Do not show" priority in Violations and Test Explorers and Filter Settings will be removed in the next release.

Software Shipped with DTP

The following software is shipped with DTP 2025.1:

  • Apache Tomcat 10.1.40
  • Java Azul OpenJDK 17.0.14 (17.56.15)

Resolved PRs and FRs

IDDescription
LS-2560

Cannot remove license reservations with invalid patterns

LS-2559User cannot use automatically created user-locked reservation
DTP-28087/metadata/{entityType} POST in Swagger documentation does not work
DEP-5471MISRA compliance deviation report - 1000 deviations limit

Updates in 2025.1.1

Resolved PRs and FRs

IDDescription
CVE-2025-66614
CVE-2026-29145
Vulnerability resolved by upgrading to tomcat 10.1.53
CVE-2026-22732Vulnerability resolved by upgrading to spring-security 6.5.9
CVE-2026-25896

Vulnerability resolved by upgrading to fast-xml-parser 5.5.8

CVE-2026-33228

Vulnerability resolved by upgrading to flatted 3.4.2

CVE-2026-33937Vulnerability resolved by upgrading to handlebars 4.7.9

Updates in 2025.1.2

Resolved PRs and FRs

IDDescription
CVE-2026-2332

Vulnerability resolved by upgrading to Jetty 12.0.34

CVE-2026-41691
CVE-2026-48713

Vulnerability resolved by upgrading to i18next-fs-backend 2.6.6

CVE-2026-41691

Vulnerability resolved by upgrading to i18next-http-backend 3.0.6

CVE-2026-41842

Vulnerability resolved by upgrading to Spring 6.2.19

CVE-2026-42043

Vulnerability resolved by upgrading to axios 1.15.2 and form-data 4.0.5

CVE-2026-43515

Vulnerability resolved by upgrading to Tomcat 10.1.56

CVE-2026-48714

Vulnerability resolved by upgrading to i18next-http-middleware 3.9.7

CVE-2025-48734

Vulnerability resolved by upgrading to commons-beanutils 1.11.0

CVE-2026-47838

Vulnerability resolved by upgrading to Spring Security 6.5.11

CVE-2025-48976

Vulnerability resolved by upgrading to commons-fileupload2-core 2.0.0-M4

CVE-2026-54512
CVE-2026-54513

Vulnerability resolved by upgrading Jackson to 2.18.8

Updates in 2025.1.3

  • Upgraded NodeJS to version 18.20.8

Resolved PRs and FRs

IDDescription
CVE-2025-14813Vulnerability resolved by upgrading BouncyCastle to version 1.84
CVE-2025-66168
CVE-2026-34197
CVE-2026-39304
CVE-2026-40466
CVE-2026-41044
CVE-2026-42588
CVE-2026-45505
CVE-2026-49157
CVE-2026-49432
CVE-2026-49434
CVE-2026-49877
CVE-2026-50734
CVE-2026-53916
CVE-2026-53917
CVE-2026-54475
Vulnerability resolved by upgrading ActiveMQ to version 6.2.7
CVE-2026-39244Vulnerability resolved by upgrading adm-zip to version 0.6.0
CVE-2026-52746Vulnerability resolved by upgrading jsonata to version 2.2.1
CVE-2026-53914Vulnerability resolved by upgrading kotlin-stdlib to version 2.4.20
CVE-2026-55276
CVE-2026-53434
CVE-2026-59083
CVE-2026-59084

Vulnerability resolved by upgrading Tomcat to version 10.1.57

CVE-2026-59724Vulnerability resolved by upgrading socket.io to version 4.8.3
CVE-2026-59869Vulnerability resolved by upgrading js-yaml to version 4.3.0

Updates in 2025.1.4

  • Upgraded Azul JRE to 17.0.20.1+1
  • Upgraded Apache Tomcat to 10.1.59

Resolved PRs and FRs

IDDescription
CVE‐2026‐8763Vulnerability resolved by upgrading Bouncy Castle to 1.85
CVE-2026-59870Vulnerability resolved by upgrading js-yaml to 4.3.1
CVE-2026-59878Vulnerability resolved by upgrading ActiveMQ to 6.2.8
CVE-2026-68497Vulnerability resolved by upgrading Jackson to 2.18.10
CVE-2026-69185Vulnerability resolved by upgrading socket.io-parser to 4.2.7
CVE-2026-73566Vulnerability resolved by upgrading tar to 7.5.22
GHSA-2fvj-hgj9-j2grVulnerability resolved by upgrading Jetty to 12.0.37
GHSA-gcfj-64vw-6mp9Vulnerability resolved by upgrading axios to 1.18.1



  • No labels