About Dependency-Track
Dependency-Track is a component analysis platform from the OWASP community that helps organizations identify and reduce risk in their software supply chain. It takes an approach built on the Software Bill of Materials (SBOM), analyzing the components listed for each project.
Repository topics show how it works with CycloneDX SBOMs, Package URLs, the National Vulnerability Database and OSS Index to detect known vulnerabilities in components, supporting software composition analysis, DevSecOps and security automation. A Docker Compose quickstart lets you get a local instance running in a few minutes.
Version 5 is the current line, while version 4 is in maintenance mode on the 4.14.x branch and reaches end-of-life in December 2026, with a migration guide provided. The frontend, documentation and Helm charts live in separate repositories, a monthly community meeting is open to users, and the project is written in Java under the Apache-2.0 license.
Key features
- SBOM-based component analysis
- CycloneDX and Package URL support
- Vulnerability data from NVD and OSS Index
- Software supply chain risk tracking
- Docker Compose quickstart
- Helm charts for deployment
Good fit for
- →Tracking vulnerable open-source dependencies
- →Adding software composition analysis to DevSecOps pipelines
- →Managing SBOMs across projects
- Built with
- Java
- Tags
- sbom
- software-composition-analysis
- supply-chain
- owasp
- vulnerability-management
- cyclonedx
- devsecops
- java
Dependency-Track: questions and answers
- What is Dependency-Track used for?
- Dependency-Track is an OWASP component analysis platform that uses SBOMs to identify and reduce risk in the software supply chain, with vulnerability tracking across projects. It is a good fit for tracking vulnerable open-source dependencies, adding software composition analysis to DevSecOps pipelines and managing SBOMs across projects.
- Is Dependency-Track open source?
- Yes. Dependency-Track is open source under the Apache-2.0 licence. Its source code is on GitHub at DependencyTrack/dependency-track and is written mainly in Java.
- Is Dependency-Track free?
- Yes. Dependency-Track is open source, so the software itself is free to use.
- Can I self-host Dependency-Track?
- Yes. Dependency-Track can be self-hosted on your own server or infrastructure.
- What is Dependency-Track an alternative to?
- Dependency-Track is an open-source alternative to Snyk, Veracode, Checkmarx and Aikido Security. Other open-source alternatives to Snyk include Trivy, Grype and Semgrep.
- Is Dependency-Track actively maintained?
- Yes. The most recent commit to Dependency-Track was on 2 October 2026, and the latest release is 5.1.1, published on 20 September 2026. The project has 4.3k stars on GitHub.
Open-source alternatives to Dependency-Track
See all
Trivy
Security
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code rep
Apache-2.0vs Snyk★ 38k
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
Semgrep
Security
Lightweight static analysis for many languages. Find bug variants with patterns that look
LGPL-2.1vs Snyk★ 17k
Horusec
Security
Horusec is an open source tool that improves identification of vulnerabilities in your pro
Apache-2.0vs Checkmarx★ 1.3k
SonarQube
Developer Tools
Continuous Inspection
LGPL-3.0vs Codacy★ 11k
Gitleaks
Security
Find secrets with Gitleaks 🔑
MITvs GitGuardian★ 30k
SaaS alternatives to Dependency-Track
See all
Snyk
Security
Developer security platform that scans code, dependencies, containers and IaC
SaaSVeracode
Security
Application security testing platform covering static, dynamic and software composition
SaaS
Checkmarx
Security
Application security testing platform with SAST, SCA and API security
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaS
Socket
Security
Supply chain security that detects risky open source packages before install
SaaS
Mend
Security
Application security platform for software composition analysis and code scanning
SaaS

