Dependency-Track logo

Dependency-Track

Open source · SBOM analysis

Dependency-Track is a server rather than a scanner: you feed it SBOMs from your builds and it tracks the components and their risk across every project and release. Where Syft produces an SBOM once, Dependency-Track is where they accumulate, so new vulnerabilities in an old release are flagged after it ships.

Key facts

VendorOWASP
LicenceApache-2.0
Latest release5.1.1, 20 Sept 2026
Repository since2013
DoesSBOM management, Vulnerability matching, Licence tracking
ReadsSBOM files
Websitedependencytrack.org
Sourcegithub.com/DependencyTrack/dependency-track

Sources

Checked 21 Sept 2026. Spotted something out of date? Tell us.

Other SBOM analysis tools

Need the product tested as well? See Cyber Resilience Act compliance testing providers.