OWASP Dependency-Track

Dependency-Track is the open source platform to inventory components, find vulnerabilities, and enforce policy across the software supply chain.

Adopted By
20K+ Organizations

About OWASP Dependency-Track

Dependency-Track is an open source software composition analysis platform used by more than 20,000 organizations. It builds an inventory of the components in software from CycloneDX bills of materials, continuously checks those components against vulnerability and policy data, and reports findings.

Capabilities

  • Inventory. Ingests CycloneDX BOMs and tracks libraries, frameworks, applications, containers, operating systems, firmware, hardware, and services across every version of every project in a portfolio.

  • Analysis. Continuously matches every component against multiple vulnerability sources, verifies upstream integrity, and prioritizes findings with the Exploit Prediction Scoring System (EPSS).

  • Governance. Codifies policy in an expression engine, can automatically triage findings and fail a build on a violation, and routes alerts to the systems teams already work in.

Workflow

Dependency-Track operationalizes the SBOM as a continuous pipeline:

  1. Produce. CycloneDX SBOMs are generated during CI/CD or acquired from suppliers.

  2. Ingest. SBOMs are published to Dependency-Track via the REST API, CI plugins, or the web interface.

  3. Analyze. Components are evaluated for security, operational, and license risk against live intelligence.

  4. Monitor. The entire portfolio is continuously re-analyzed as new vulnerabilities and policy changes land.

  5. Respond. Actionable findings flow to the tools teams already use through direct integrations, webhooks, chat, and email.

Sources and Integrations

Vulnerability intelligence is drawn from multiple sources, including the NVD, GitHub Advisories, OSV, Sonatype Guide, Snyk, Trivy, and VulnDB. The platform consumes and produces CycloneDX SBOM, HBOM, VEX, and VDR, and integrates with the tools teams already run, including Jenkins, Jira, DefectDojo, Slack, and Microsoft Teams.

Project Resources

Project Leaders

Steve Springett

Founder and Project Co-Leader

EmailLinkedIn

Niklas Düster

Project Co-Leader and Lead Architect

EmailLinkedIn

Project Information

Language
Java
License
Apache 2.0
Latest Version
v5
Contributors
75
GitHub Stars
3900

Requirements

  • Docker environment
  • PostgreSQL database
  • Network connectivity for vulnerability feeds
  • Adequate storage for component data
Corporate Supporters
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.