DependencyTrack/dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

4,176

stars

8,734

commits

Java

primary language

Sep 4, 2026

updated

dependencytrack.org/
appsec
bill-of-materials
bom
component-analysis
cyclonedx
devsecops
hacktoberfest
nvd
ossindex
owasp
package-url
purl
sbom
sca
security
security-automation
software-composition-analysis
software-security
vulnerabilities
vulnerability-detection
Browse cluster: Security scanning and penetration testing tools

README

OWASP Dependency-Track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM).

Website Documentation Docker Pulls License

Build Tests E2E Tests Coverage

LinkedIn Bluesky Mastodon YouTube

[!IMPORTANT] Looking for Dependency-Track v4?

Quickstart

Want to kick the tires? Follow the Quickstart tutorial to get a local instance running with Docker Compose in a few minutes.

Documentation

User-facing documentation is rendered at https://dependencytrack.github.io/docs/ and maintained in the docs repository.

Contributing

  1. Code of conduct
  2. Contribution guidelines
  3. Developer guide

Community

Dependency-Track is an open source project maintained by a community of contributors. Join the monthly community meeting to hear project updates, ask questions, and meet other users and maintainers.

See also

Contributors

(top 30 of 112)

nscuro

3,899 commits

stevespringett

2,365 commits

dependabot[bot]

1,220 commits

sahibamittal

483 commits

DependencyTrack/dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

4,176

stars

8,734

commits

Java

primary language

Sep 4, 2026

updated

dependencytrack.org/
appsec
bill-of-materials
bom
component-analysis
cyclonedx
devsecops
hacktoberfest
nvd
ossindex
owasp
package-url
purl
sbom
sca
security
security-automation
software-composition-analysis
software-security
vulnerabilities
vulnerability-detection
Browse cluster: Security scanning and penetration testing tools

README

OWASP Dependency-Track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM).

Website Documentation Docker Pulls License

Build Tests E2E Tests Coverage

LinkedIn Bluesky Mastodon YouTube

[!IMPORTANT] Looking for Dependency-Track v4?

Quickstart

Want to kick the tires? Follow the Quickstart tutorial to get a local instance running with Docker Compose in a few minutes.

Documentation

User-facing documentation is rendered at https://dependencytrack.github.io/docs/ and maintained in the docs repository.

Contributing

  1. Code of conduct
  2. Contribution guidelines
  3. Developer guide

Community

Dependency-Track is an open source project maintained by a community of contributors. Join the monthly community meeting to hear project updates, ask questions, and meet other users and maintainers.

See also

Contributors

(top 30 of 112)

nscuro

3,899 commits

stevespringett

2,365 commits

dependabot[bot]

1,220 commits

sahibamittal

483 commits

Languages

Java

98.1%