Dependency-Track
Open source · SBOM analysis
Dependency-Track is a server rather than a scanner: you feed it SBOMs from your builds and it tracks the components and their risk across every project and release. Where Syft produces an SBOM once, Dependency-Track is where they accumulate, so new vulnerabilities in an old release are flagged after it ships.
Key facts
| Vendor | OWASP |
|---|---|
| Licence | Apache-2.0 |
| Latest release | 5.1.1, 20 Sept 2026 |
| Repository since | 2013 |
| Does | SBOM management, Vulnerability matching, Licence tracking |
| Reads | SBOM files |
| Website | dependencytrack.org |
| Source | github.com/DependencyTrack/dependency-track |
Sources
Checked 21 Sept 2026. Spotted something out of date? Tell us.
Other SBOM analysis tools
Need the product tested as well? See Cyber Resilience Act compliance testing providers.