OWASP
owasp.org โบ www-project-dependency-track
OWASP Dependency-Track | OWASP Foundation
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities ...
HOME
OWASP Foundation, the Open Source Foundation for Application Security on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
ABOUT
About the OWASP Foundation on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
PROJECTS
Projects on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
CHAPTERS
OWASP Local Chapters on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
Dependency-Track
dependencytrack.org
Dependency-Track | Software Bill of Materials (SBOM) Analysis | OWASP
Dependency-Track is the open source platform that over 20,000 organizations use to inventory components, find vulnerabilities, and enforce policy across the software supply chain.
Videos
08:04
OWASP DependencyTrack Walkthrough - YouTube
Dependency Track Community Meeting (2026-07-01)
15:57
Dependency Track Community Meeting (2026-06-03) - YouTube
Dependency Track Community Meeting (2026-05-06)
23:17
Dependency-Track Community Meeting (2026-02-04) - YouTube
Dependency-Track
docs.dependencytrack.org
Introduction | Dependency-Track
Dependency-Track monitors component usage across all versions of every application in its portfolio in order to proactively identify risk across an organization.
GitHub
github.com โบ DependencyTrack โบ dependency-track
GitHub - DependencyTrack/dependency-track: Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. ยท GitHub
May 19, 2026 - Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. - DependencyTrack/dependency-track
Starred by 4K users
Forked by 779 users
Languages ย Java 97.5% | PLpgSQL 1.3% | TSQL 0.8% | JavaScript 0.1% | Makefile 0.1% | Dockerfile 0.1%
Owasp
devguide.owasp.org โบ en โบ 05-implementation โบ 02-dependencies โบ 02-dependency-track
Dependency-Track - OWASP Developer Guide
The Dependency-Track is an OWASP Flagship project and can be installed using a docker-compose file from the Dependency-Track website.
Jenkins
plugins.jenkins.io โบ dependency-track
OWASP Dependency-Track | Jenkins plugin
June 9, 2026 - Dependency-Track is an intelligent Software Supply Chain Component Analysis platform that allows organizations to identify and reduce risk from the use of third-party and open source components.
OWASP
owasp.org โบ www-project-dependency-check
OWASP Dependency-Check | OWASP Foundation
Dependency-Check has a command line interface, a Maven plugin, a Gradle plugin, an Ant task and a number of integrations with build tooling such as Jenkins, GitHub Actions and Azure DevOps. The core engine contains a series of analyzers that inspect the project dependencies, collect pieces of information about the dependencies (referred to as evidence within the tool).
Defectdojo
defectdojo.com โบ integrations โบ owasp-dependency-track
OWASP Dependency Track
Dependency-Track is an intelligent continuous SBOM (Software Bill of Materials) analysis platform that enables organizations to identify and reduce risk in the software supply chain by monitoring component usage across all application versions and integrating with multiple sources of vulnerability ...
ReversingLabs
reversinglabs.com โบ blog โบ owasp-dependency-track-update-key-changes-and-limitations-on-software-risk-management
OWASP's Dependency-Track tool update: Key changes โ and limitations | RL Blog
July 31, 2025 - The Open Web Application Security Project (OWASP) has released a new version of its dependency tracking tool, which can identify known vulnerabilities in third-party software components, measure and enforce policy compliance, respond to identified vulnerabilities, prioritize vulnerability mitigation, triage findings and policy violations, and produce a CycloneDX-based software bill of materials (SBOM).
Docker Hub
hub.docker.com โบ r โบ owasp โบ dependency-track
owasp/dependency-track - Docker Image
Dependency-Track monitors component usage across all versions of every application in its portfolio in order to proactively identify risk across an organization. The platform has an API-first design and is ideal for use in Continuous Integration (CI) and Continuous Delivery (CD) environments. ...
Dependency-Track
dependencytrack.org โบ home โบ news โบ owasp dependency-track 5.0 is now generally available
OWASP Dependency-Track 5.0 Is Now Generally Available | Dependency-Track
June 9, 2026 - OWASP Dependency-Track, the open source platform that organizations use to identify and reduce risk in the software supply chain, today announced the general availability of version 5.0. Developed under the codename Hyades, v5 is the most extensive ...
Dependency-Track
dependencytrack.org โบ home โบ download
Download | Dependency-Track
Download and deploy OWASP Dependency-Track 5.0. Container images, system requirements, breaking changes, and the v4 to v5 migration path.
YouTube
youtube.com โบ watch
Setting up OWASP Dependency-Track: Protect Your Supply Chain - YouTube
A new vulnerability drops โ do you know if your software is at risk? In this video, we show how to use CycloneDX to generate SBOMs and OWASP Dependency-Track...
Published ย January 7, 2026
Medium
blog.diatomlabs.com โบ dependency-track-securing-your-software-supply-chain-and-meeting-compliance-standards-9351972236cc
Dependency Track: Securing your software supply chain and meeting compliance standards | by Altin Ukshini | Diatom Labs
March 19, 2025 - Visualization Tools: Use data via Dependency Track API to build custom visualizations (e.g., live application trees or heatmaps showing vulnerability severity). For example, our GitHub Action, OWASP Dependency-Track Checker, integrates Dependency Track scan results directly into your CI/CD pipelines.
OWASP
owasp.org โบ www-project-developer-guide โบ release-es โบ implementaciรณn โบ dependencias โบ dependency_track
Guรญa del Desarrollador OWASP | Dependency-Track | OWASP Foundation
Dependency-Track on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.