Dependency-Track is the open source platform to inventory components, find vulnerabilities, and enforce policy across the software supply chain.
Dependency-Track 5.0 is free and open source under the Apache 2.0 license, available now as container images from Docker Hub and the GitHub Container Registry. Version 5 separates the backend and the web interface so each scales and updates independently:
API server (dependencytrack/apiserver): the stateless backend; run one or many behind a load balancer for high availability.
Frontend (dependencytrack/frontend): the single-page web interface, served as static assets from its own container.
A Docker Compose file brings up a full deployment; once it is running, open http://localhost:8081 and sign in with the default credentials admin / admin.
curl -LO https://dependencytrack.org/docker-compose.yml
docker compose up -d
PostgreSQL. Dependency-Track v5 standardizes on PostgreSQL; H2, MySQL, and Microsoft SQL Server are no longer supported.
Container runtime. Docker or any OCI-compatible runtime; Kubernetes is fully supported with liveness and readiness probes.
Resources. Scale horizontally by adding stateless API server instances; smaller deployments run comfortably on modest hardware.