DependencyTrackDeveloper tools

Dependency Track

dependency-track

OWASP platform for SBOM-driven component analysis and software supply-chain risk tracking.

  • Self-hostable
  • Docker supported
dependency-track screenshot
Popularity
4.3k Stars
GitHub stars
Recent activity
10/9/2026
Updated in the last 30 days
License
APACHE-2.0
Permissive

Why it matters

We look beyond stars: what problem it solves, whether it creates real utility, and what makes its approach worth noticing.

Last 90 days

Problem

Software supply chain security and component inventory management address vital enterprise compliance and vulnerability defense needs.

Practical value

Provides actionable local instances and containerized deployment to support automated component analysis and continuous tracking.

Innovation / differentiation

Leverages software bills of materials to build a component analysis platform with a systematic risk-tracking path.

Leverage potential

As an OWASP project, it features a complete community ecosystem, separate frontend repository, and Helm charts.

Why now

Currently transitioning from v4 maintenance mode to v5, with clear lifecycle planning extending through late 2026.

Community activity

In the last 90 days there were 160 new issues and 796 pull requests; the bounded issue/PR samples include 69 issue authors and 6 PR contributors, with at least 10 releases.

Maintainer responsiveness

The 100-issue window sample had a 67% close rate, and the 100-pull-request sample had a 96% merge rate. Maintainer-response observations covered 41% of that issue sample, with a 0% response rate and median first response of not enough data.

6 contributors in PR sampleAt least 10 releasesIssue response rate 0% · sample 41 (41% coverage)PR merge rate 96% · 100 sampled in window

Key highlights

  • frontend: Frontend repository
  • docs: Documentation repository
  • helm-charts: Helm charts

Quick start

How it is installed, how hard it is, and where to start.

Docker supportedSelf-hostable

Best for

  • Teams that want data on their own servers
  • People who prefer Docker deploys

Watch outs

  • 3 inferred from materials — review under Sources below

More about it

Dependency-Track is OWASP’s component analysis platform: ingest SBOMs, continuously map vulnerabilities and license data, and turn supply-chain risk into an operable inventory. It sits beside your build system rather than replacing it.

For security and compliance teams, the win is a repeatable audit trail—each build artifact can be tied to a bill of materials and tracked over time, instead of ad-hoc scans of lockfiles. Note that v4 is on a maintenance branch; check which line you deploy.

Sources

Each field shows its status and source — expand to review.

8 · Expand
  • Latest release

    Verified

    5.2.0

    Source: GitHub API · latest_release=5.2.0 · 10/10/2026

  • License

    Verified

    Apache-2.0

    Source: GitHub API · license.spdx_id=Apache-2.0 · 10/10/2026

  • logo url

    Verified

    None

    Source: admin_cms · cms editor · 8/28/2026

  • One-liner

    Verified

    {"en":"OWASP platform for SBOM-driven component analysis and software supply-chain risk tracking.","zh":"Dependency-Track 是 OWASP 旗下的核心开源项目,专注于软件供应链安全与 SBOM(软件物料清单)管理。它通过自动化分析组件风险,帮助企业识别并降低开源依赖带来的安全隐患。"}

    Source: heuristic_batch_publish · batch-publish-tools heuristic write · 8/24/2026

  • Category hint

    Inferred from materials

    developer-tools

    Source: Project README · hint=developer-tools · 8/24/2026

  • screenshot url

    Verified

    None

    Source: admin_cms · cms editor · 8/28/2026

  • supports docker

    Verified

    Yes

    Source: Repository file · dockerfile=true; compose=false · 10/10/2026

  • supports self host

    Inferred from materials

    Yes

    Source: Project README · matched self-host keywords · 8/24/2026

Other verified projects matched by category, capabilities, and intended roles.