7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Dependency-Track

Open source

An OWASP component analysis platform that uses SBOMs to identify and reduce risk in the software supply chain, with vulnerability tracking across projects.

dependencytrack.org
Dependency-Track homepage screenshot
GitHub stars
4.3k
Last commit
today
Repository age
13 years
Version
5.1.1
Licence
Apache-2.0
Self-hosted
Yes

About Dependency-Track

Dependency-Track is a component analysis platform from the OWASP community that helps organizations identify and reduce risk in their software supply chain. It takes an approach built on the Software Bill of Materials (SBOM), analyzing the components listed for each project.

Repository topics show how it works with CycloneDX SBOMs, Package URLs, the National Vulnerability Database and OSS Index to detect known vulnerabilities in components, supporting software composition analysis, DevSecOps and security automation. A Docker Compose quickstart lets you get a local instance running in a few minutes.

Version 5 is the current line, while version 4 is in maintenance mode on the 4.14.x branch and reaches end-of-life in December 2026, with a migration guide provided. The frontend, documentation and Helm charts live in separate repositories, a monthly community meeting is open to users, and the project is written in Java under the Apache-2.0 license.

Key features

  • SBOM-based component analysis
  • CycloneDX and Package URL support
  • Vulnerability data from NVD and OSS Index
  • Software supply chain risk tracking
  • Docker Compose quickstart
  • Helm charts for deployment

Good fit for

  • →Tracking vulnerable open-source dependencies
  • →Adding software composition analysis to DevSecOps pipelines
  • →Managing SBOMs across projects
Built with
Java
Tags
sbom
software-composition-analysis
supply-chain
owasp
vulnerability-management
cyclonedx
devsecops
java

Dependency-Track: questions and answers

What is Dependency-Track used for?
Dependency-Track is an OWASP component analysis platform that uses SBOMs to identify and reduce risk in the software supply chain, with vulnerability tracking across projects. It is a good fit for tracking vulnerable open-source dependencies, adding software composition analysis to DevSecOps pipelines and managing SBOMs across projects.
Is Dependency-Track open source?
Yes. Dependency-Track is open source under the Apache-2.0 licence. Its source code is on GitHub at DependencyTrack/dependency-track and is written mainly in Java.
Is Dependency-Track free?
Yes. Dependency-Track is open source, so the software itself is free to use.
Can I self-host Dependency-Track?
Yes. Dependency-Track can be self-hosted on your own server or infrastructure.
What is Dependency-Track an alternative to?
Dependency-Track is an open-source alternative to Snyk, Veracode, Checkmarx and Aikido Security. Other open-source alternatives to Snyk include Trivy, Grype and Semgrep.
Is Dependency-Track actively maintained?
Yes. The most recent commit to Dependency-Track was on 2 October 2026, and the latest release is 5.1.1, published on 20 September 2026. The project has 4.3k stars on GitHub.

Open-source alternatives to Dependency-Track

See all

SaaS alternatives to Dependency-Track

See all