GitPedia

Dependency track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

From DependencyTrack·Updated June 25, 2026·View on GitHub·

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM). The project is written primarily in Java, distributed under the Apache License 2.0 license, first published in 2013. It has gained significant community traction with 3,965 stars and 760 forks on GitHub. Key topics include: appsec, bill-of-materials, bom, component-analysis, cyclonedx.

Latest release: 5.0.2
June 18, 2026View Changelog →

OWASP Dependency-Track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk
in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the
capabilities of Software Bill of Materials (SBOM).

Build Status
Test Status
Codacy Badge
E2E Test Status
Documentation
License

[!IMPORTANT]
Looking for Dependency-Track v4?

Quickstart

Want to kick the tires? Follow the Quickstart tutorial
to get a local instance running with Docker Compose in a few minutes.

Documentation

User-facing documentation is rendered at https://dependencytrack.github.io/docs/ and maintained in the docs repository.

Contributing

  1. Code of conduct
  2. Contribution guidelines
  3. Developer guide

Community

Dependency-Track is an open source project maintained by a community of contributors.
Join the monthly community meeting
to hear project updates, ask questions, and meet other users and maintainers.

See also

Contributors

Showing top 12 contributors by commit count.

View all contributors on GitHub →

This article is auto-generated from DependencyTrack/dependency-track via the GitHub API.Last fetched: 6/25/2026