Today, Liquibase is proud to release the open source Liquibase CVE Library (Common Vulnerabilities and Exposures Library) to foster security and transparency across the Liquibase Community. The free, publicly available library helps users of older versions of Liquibase Community identify existing vulnerabilities and get a clearer sense of their security posture. By tying vulnerability data directly to Liquibase releases, the CVE Library helps teams see their risk exposure, compare versions, and take informed action to secure the software they run.
Attackers need only to find a single exploit to breach a network and IT infrastructure, making comprehensive CVE libraries increasingly invaluable to security teams seeking to stay ahead of Mythos-class threat capabilities by patching all known weaknesses before they can be targeted.
To date, the Liquibase Community project has been downloaded over 100 million times.
How does the Liquibase CVE Library work?
Every time Liquibase ships a new release, automated security scanning tools analyze both the Docker image and the Liquibase binary for known vulnerabilities. Scanning also runs against previously published images, maintaining an up-to-date view of the evolving threat landscape and catching anything that surfaces post-release. The site organizes everything by image and version. You can see a high-level security grade and CVE counts for the latest release, drill into any specific version for the full vulnerability list, or use the comparison tool to see exactly which CVEs were resolved, or introduced, between two releases.
Which environments are supported?
- Docker images: The official Liquibase Community Docker image.
- Liquibase binary: Vulnerabilities in the Liquibase JARs themselves, regardless of how you install it.
What you’ll see
For each vulnerability, the CVE Library shows:
- CVE ID, Severity, and CVSS score: Presented with clear information and links to learn more.
- Affected package: The specific details needed to understand what is vulnerable.
- Fix available: The package version that resolves it, if one exists; and where applicable, the first Liquibase image version where the CVE no longer appears.
- Component type: Additional vulnerability details to help understand the risk.
- First-party vs. third-party: Whether the vulnerability is in Liquibase’s own code or an upstream dependency.
The full list is filterable by severity, component type, and keyword search, and can be exported as CSV or PDF. (Please also see figures with press release link on Business Wire, linked above.)
Part of a broader commitment to the Community
The CVE Library doesn’t stand alone. Since September of 2025, Liquibase has released a steady stream of enhancements and fixes for the Liquibase Community. Recently, in May of 2026, Liquibase standardized on two clear paths to updates: quarterly Community releases and continuous nightly builds on GitHub (available at github.com/liquibase/liquibase/releases/tag/nightly). The CVE Library now makes that ongoing work readily visible so users don’t have to just trust that issues are being addressed, they can see it, release by release.
For teams that need enterprise assurance
The Liquibase CVE Library gives Community users clear visibility into known vulnerability exposure. For organizations running Liquibase in regulated, mission-critical, AI-enabled, or enterprise production environments, visibility is often the first step. Liquibase Secure provides a fully supported enterprise distribution with SLA-backed support, tested components, policy checks, drift detection, structured audit logs, and governance controls for teams that need to reduce risk while maintaining delivery velocity.
Take a look and get involved
The Liquibase Community thrives because people around the world step up to contribute. Here’s how to get in touch and take part:
- Explore the CVE Library today at https://cve-library.liquibase.com.
- Ask questions or start a discussion on the Liquibase Forum.
- Report a bug or request a feature in the GitHub issue tracker at github.com/liquibase/liquibase.
Liquibase Expands Global Partner Ecosystem
Posted in Commentary with tags Liquibase on July 21, 2026 by itnerdLiquibase today announced a major expansion of its global partner ecosystem and the appointment of Phil Robinson as Vice President of Global Channels and Alliances. The move builds on strong momentum for Liquibase Secure and growing enterprise demand for governed database change as AI, modernization, security, and compliance reshape software delivery.
Robinson brings more than two decades of channel, alliance, and enterprise open-source experience to Liquibase. Most recently, he served as Vice President of Global Channels at Digital.ai, where he helped redesign and relaunch the company’s channel program globally. Before that, he spent more than eight years at Atlassian, where he built and scaled global alliance programs with GSIs and Federal SIs, including Accenture, Deloitte, PwC, and Capgemini. His experience also includes leadership roles at Magento, Alfresco, and Hewlett Packard Enterprise across open source, cloud, systems integration, and enterprise software.
Trusted by 20 of the Fortune 100 and supported by a global community with more than 100 million downloads, Liquibase is investing in partners to help enterprises close the database delivery gap and build new services around Database Change Governance.
Robinson will lead Liquibase’s global partner strategy across partner recruitment, enablement, joint marketing, and partner-led services around Database Change Governance, while deepening the company’s engagement with cloud marketplaces and government partners.
AI is exposing the database delivery gap
Modern application and data delivery has accelerated in waves. Agile increased release velocity. Cloud spread applications, databases, and data platforms across more teams, tools, and environments. Enterprises responded by investing in CI/CD, automated testing, infrastructure-as-code, and security controls. But database change often remained governed through tickets, manual reviews, disconnected scripts, and processes that varied across teams, tools, and database platforms.
That disconnect has made the database one of the last major constraints on modern application and data delivery. Application code, infrastructure, and security increasingly move together, while database change is still treated as a separate process in many organizations. The result is fragmented governance, slower releases, and limited visibility into what changed, who approved it, and whether it is safe to deploy.
AI is not creating the database delivery gap. It is exposing it. As AI assistants and agents generate more software, they also increase the volume and speed of database change flowing through delivery systems that were never designed to operate at that scale. The challenge is no longer simply automating deployments. It is keeping database change synchronized with application code, infrastructure, and security before it reaches production.
The governance gap is widening. According to Liquibase’s 2026 State of Database Change Governance Report, 96% of organizations now have AI interacting with production databases, and 70% ship database changes weekly or faster. Yet only 28% enforce governance through automated controls and evidence, while 39% say they cannot reliably track what changed where.
For partners, this represents a significant opportunity to help customers modernize database delivery, govern AI-assisted development, strengthen compliance, reduce production risk, and bring database change into the same DevSecOps practices already established for application code. As enterprises look to scale AI safely, they need partners who can help modernize the processes that AI is exposing as bottlenecks.
Database Change Governance provides the control plane that keeps database change synchronized with application code, infrastructure, and security across the software delivery lifecycle. Liquibase Secure operationalizes that control plane across development teams, CI/CD pipelines, AI agents, and more than 65 database platforms, enabling enterprises to accelerate software delivery without sacrificing governance.
Why this is a partner opportunity now
For partners, this shift is a chance to become indispensable to their most complex customers. As database change outruns the ability to govern it, enterprises need a partner who can restore control at the exact point where developer velocity, compliance, and AI readiness collide. Liquibase provides an opportunity for partners to turn that challenge into a repeatable practice spanning advisory, implementation and managed services, reaching every environment a customer runs, from mainframe to cloud to lakehouse.
At the center of the opportunity is Liquibase Secure, which helps enterprises automate, secure, and govern database change across complex environments. With policy checks to deliver standardized change, advanced drift detection, structured audit trails, always-on evidence gathering, and more, Liquibase Secure gives developers, platform teams, security leaders, and compliance teams a governed path for every database change.
Liquibase already works with a robust group of consulting, cloud, public sector, and technology partners. Under Robinson’s leadership, the company plans to expand partner coverage both geographically and into specific industry sectors, creating clear paths for partners to build solutions and deliver Liquibase Secure, Database
Organizations interested in joining the Liquibase partner ecosystem can learn more at liquibase.com/partners.
Leave a comment »