Dependency-Track is an open source software composition analysis platform used by more than 20,000 organizations. It builds an inventory of the components in software from CycloneDX bills of materials, continuously checks those components against vulnerability and policy data, and reports findings.
Inventory. Ingests CycloneDX BOMs and tracks libraries, frameworks, applications, containers, operating systems, firmware, hardware, and services across every version of every project in a portfolio.
Analysis. Continuously matches every component against multiple vulnerability sources, verifies upstream integrity, and prioritizes findings with the Exploit Prediction Scoring System (EPSS).
Governance. Codifies policy in an expression engine, can automatically triage findings and fail a build on a violation, and routes alerts to the systems teams already work in.
Dependency-Track operationalizes the SBOM as a continuous pipeline:
Produce. CycloneDX SBOMs are generated during CI/CD or acquired from suppliers.
Ingest. SBOMs are published to Dependency-Track via the REST API, CI plugins, or the web interface.
Analyze. Components are evaluated for security, operational, and license risk against live intelligence.
Monitor. The entire portfolio is continuously re-analyzed as new vulnerabilities and policy changes land.
Respond. Actionable findings flow to the tools teams already use through direct integrations, webhooks, chat, and email.
Vulnerability intelligence is drawn from multiple sources, including the NVD, GitHub Advisories, OSV, Sonatype Guide, Snyk, Trivy, and VulnDB. The platform consumes and produces CycloneDX SBOM, HBOM, VEX, and VDR, and integrates with the tools teams already run, including Jenkins, Jira, DefectDojo, Slack, and Microsoft Teams.