The default of 4GB is too low for a production setup and causes DependencyTrack to hit java.lang.OutOfMemoryError. This causes Dependency Track to enter a weird state where it will throw 502 and 504 errors. The initial 4GB was set to make Dependency Track run in the (too small) VM in the NixOS integration test. Move the explicit heap configuration there. For the service itself, we now don't set a limit. This means the JVM will choose its maximum heap on its own, which does a much better job for realistic scenarios. I added a release note, because people who run Dependency Track on very tiny VMs/machines may experience issues.
2.1 KiB
2.1 KiB