Ross ROSS = Recommend OSS · open-source software intelligence for agents

DependencyTrack/dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. observed · 2026-08-28

github.com/DependencyTrack/dependency-track · homepage · Java · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

99/100

  • Activity 99
  • Release rhythm 99
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 24.0
  • age_days: 4796
  • days_rel: 9
  • days_push: 7
  • n_releases_24m: 25

Full methodology

Adoption not part of the score

4145 stars · 808 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

OWASP Dependency-Track is an open-source component analysis platform that ingests CycloneDX SBOMs to continuously identify vulnerabilities, license risk, and integrity issues across an organization's software portfolio. It provides a REST API, policy enforcement, EPSS-based prioritization, and audit workflows for software supply chain security.

Use cases

  • track vulnerabilities in third-party dependencies across all projects
  • ingest and analyze SBOMs from CI/CD pipelines
  • enforce security policy on software components and break builds on violations
  • monitor software supply chain risk across an enterprise portfolio
  • detect typosquatting and tampered packages via integrity verification
  • audit and triage vulnerability findings with an exportable trail
  • generate software bill of materials compliance reports

When to choose

  • you need continuous, portfolio-wide component vulnerability monitoring driven by SBOMs
  • you want CycloneDX-native SBOM ingestion with policy enforcement and audit workflows
  • you need an API-first platform that integrates with CI/CD and multiple vulnerability data sources

When to avoid

  • you only need a quick one-off scan of a single project's dependencies rather than a platform
  • you cannot operate a self-hosted server or containerized deployment
  • you require SCA for languages or ecosystems outside CycloneDX/SBOM-based workflows

Facets

application · maturity active

security vulnerability-scanning monitoring api-framework self-hosted dependency-audit security developer-tools apis self-hosted jvm sbom cyclonedx software-composition-analysis software-supply-chain owasp devsecops component-analysis vex license-compliance devops docker web-server

3 sources

Member repositories

RepositoryRoleHealth v2
DependencyTrack/dependency-trackmain99

For agents

markdown · JSON · MCP: product_card(name="DependencyTrack/dependency-track")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem