Dependency-Track is the open source platform to inventory components, find vulnerabilities, and enforce policy across the software supply chain.
Dependency-Track identifies and reduces risk in the software supply chain, from a single team to enterprise portfolios of hundreds of thousands of projects. Its capabilities fall into four areas: inventory, analysis, governance, and operation at scale.
Build a complete, continuously updated record of everything an organization ships, from one SBOM standard.
Full-stack inventory. Tracks libraries, frameworks, applications, containers, operating systems, firmware, hardware, and services.
CycloneDX native. Consumes, analyzes, and produces CycloneDX SBOM, HBOM, VEX, and VDR, an international standard.
Project hierarchies. Models a portfolio by product, team, or environment with parent and child project hierarchies.
Collection projects. Rolls up metrics across versions, services, and environments without forcing a single tag scheme.
Version history. Keeps every release of a project side by side and flags the current one as the latest version.
API-first design. A documented REST API supports use in modern CI/CD pipelines.
Surface vulnerabilities, integrity failures, and risk as they emerge, rather than on a periodic scan.
Vulnerability detection. Matches components against the NVD, GitHub Advisories, and OSV, plus Sonatype OSS Index, Snyk, Trivy, and VulnDB.
Reproducible analysis. The internal analyzer matches against mirrored data with no outbound calls, so analysis is fast and repeatable.
Integrity verification (v5). Flags components whose published hashes diverge from the upstream registry, catching typosquatting and tampering.
Exploit prediction. Prioritizes mitigation with integrated support for the Exploit Prediction Scoring System (EPSS).
Auditing workflow. Triages every finding with an analysis state, justification, and a permanent, exportable audit trail.
Time-series metrics. Trends the risk score and finding counts of every project and the whole portfolio over
Turn standards into enforceable policy and the machine-readable evidence regulators now expect.
Expression-based policy. A Common Expression Language (CEL) engine evaluates component policies and can break the build on a failure.
Vulnerability policies. Automatically audit or suppress findings before they reach analysts or trigger a notification.
License compliance. Ban copyleft licenses, allow-list with SPDX expressions, and group licenses into readable rules.
VEX and VDR. Produces and consumes CycloneDX Vulnerability Exploitability eXchange and Vulnerability Disclosure Reports.
Portfolio access control. Least-privilege access by team and project hierarchy, generally available with bounded overhead at scale.
Notifications. Route alerts to Slack, Microsoft Teams, Mattermost, email, and webhooks, filtered on any field with CEL.
The version 5 redesign rebuilt the engine to stay up, avoid silent data loss, and run from a single team to an enterprise portfolio.
Horizontal scaling and high availability. Stateless instances coordinate through PostgreSQL alone, with no broker, for active/active high availability across zones.
Durable processing. BOM processing, analysis, and notifications resume from the exact step they reached and retry automatically with backoff.
One database. Standardizes on PostgreSQL and moves search, caching, and metrics into the database, retiring the local index.
Built for operations. A dedicated management port exposes Prometheus metrics and Kubernetes liveness and readiness probes.
Centralized secrets. Integration credentials live behind one pluggable provider, so they can be rotated and audited in a single place.
Enterprise ready. Single sign-on via OpenID Connect, with Active Directory and LDAP, plus configurable data retention.