Ross ROSS = Recommend OSS · open-source software intelligence for agents

owasp-dep-scan/dep-scan

OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration. observed · 2026-08-28

github.com/owasp-dep-scan/dep-scan · homepage · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

97/100

  • Activity 98
  • Release rhythm 94
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 23
  • age_days: 2409
  • days_rel: 41
  • days_push: 17
  • n_releases_24m: 10

Full methodology

Adoption not part of the score

1281 stars · 138 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

OWASP dep-scan is a security and risk audit CLI tool that scans project dependencies in local repositories and container images for known CVEs, license issues, and maintenance risks. It performs reachability analysis across multiple language ecosystems and generates SBOM, VDR, and VEX reports for CI integration.

Use cases

  • scan project dependencies for known cves
  • audit container images for vulnerabilities
  • generate sbom with vulnerability disclosure report
  • perform reachability analysis on vulnerable packages
  • detect dependency confusion attacks
  • integrate dependency scanning into ci pipeline
  • generate vex documents for compliance

When to choose

  • you need local, fast dependency vulnerability scanning without a server
  • you want SBOM/VEX/VDR generation for compliance
  • you need reachability analysis to prioritize real exploitable vulnerabilities
  • you scan multiple ecosystems including containers and Linux distro packages

When to avoid

  • you need dynamic application security testing or runtime protection
  • you want a hosted SaaS vulnerability management platform with dashboards
  • you only need license compliance without vulnerability data

Facets

cli-tool · maturity active

vulnerability-scanning dependency-audit security developer-tools ci-cd security developer-tools windows cli python sbom sca vex cyclonedx supply-chain-security reachability-analysis container-scanning owasp devops linux macos docker

2 sources

Member repositories

RepositoryRoleHealth v2
owasp-dep-scan/dep-scanmain97

For agents

markdown · JSON · MCP: product_card(name="owasp-dep-scan/dep-scan")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem