
Dependency-Track
Dependency-Track is a free platform used to analyze SBOMs and track component and vulnerability risk in the software supply chain for AppSec teams.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- Linux
- License
- Open source
- Reviewed
- Last reviewed 6 October 2026
What it is
An OWASP project that takes in CycloneDX software bills of materials and continuously checks each tracked component against several sources of vulnerability data.
What it helps with
- Keeping an inventory of components across every project and version
- Matching components against multiple vulnerability feeds as new issues appear
- Enforcing security, license, and operational policy across the supply chain
Who it's for
Application security and software supply chain teams tracking risk in the components they ship.
Worth knowing
It ships as two parts, an API server and a separate web frontend, often deployed together with Docker Compose. The current version 5 line runs on PostgreSQL, and a separate version 4 line is still maintained.
What can it track besides application libraries?
Containers, operating systems, firmware, and services.
How does it help prioritize findings?
It can rank issues using EPSS exploit prediction scores.
How does it send out results?
Through webhooks, chat tools, and email notifications.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.