# FOSSA vs OWASP Dependency-Check

| Attribute | FOSSA | OWASP Dependency-Check |
|---|---|---|
| **Vioscale score** | 49.4 (56% (medium)) | 58.1 (10% (low)) |
| activity.commits_last_30d | - | 55 |
| adoption.dependent_repos | - | 121 |
| adoption.github_stars | - | 7,672 |
| deployment.options | `{"cloud":true,"on_prem":true,"self_hosted":true}` | `{"self_hosted":true}` |
| description.long | A platform that helps teams identify and manage open source dependencies across their codebase, enforce license compliance policies, detect and remediate security vulnerabilities, and generate regulatory-compliant software bills of materials (SBOMs). | A tool that scans software dependencies to identify publicly known vulnerabilities by cross-referencing them with vulnerability databases. It generates reports that link discovered issues to relevant security advisories. |
| features.capabilities | `{"ci_gating":true,"open_source":true,"vuln_scanning":true,"sbom_generation":true,"auto_merge_policy":false,"update_automation":true,"license_compliance":true,"reachability_analysis":false,"container_image_scanning":true}` | - |
| integrations.count | 10 | - |
| integrations.list | `[{"name":"GitHub"},{"name":"CI/CD platforms"},{"name":"Gradle"},{"name":"Maven"},{"name":"JavaScript/TypeScript ecosystems"},{"name":"Python"},{"name":"Golang"},{"name":"Ruby"},{"name":"Rust"},{"name":"Kotlin"}]` | - |
| language.primary | - | Java |
| license.spdx | - | Apache-2.0 |
| market.availability | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | - |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true}` |
| pricing | `{"type":"subscription","plans":[{"free":true,"name":"Free","summary":"Free forever","features":["Container scanning","Identify dependencies at any depth","Basic email support","API access","SaaS (multi-tenant cloud)","Limited Filters","Export SBOMs"],"components":[{"kind":"fixed","amount":0,"period":"month","currency":"USD"}],"description":"For individuals and small teams getting started.","contactSales":false,"includedLimits":{"projects":"5","imported_sboms":"5","quality_checks":"1","dependency_levels":"5"}},{"free":false,"name":"Business","summary":"$20/project/month billed annually","features":["Everything in Free, plus:","Unlimited imported SBOMs","Automated license and vulnerability scanning","Multi-project reporting","Priority support","Full suite of quality checks"],"minSeats":10,"commitment":"annual","components":[{"kind":"per_unit","unit":"project","amount":20,"period":"month","currency":"USD"}],"description":"For growing teams needing advanced compliance and security.","contactSales":false,"includedLimits":{"projects":"10","imported_sboms":"Unlimited","release_groups":"1","contributing_developers":"10"}},{"free":false,"name":"Enterprise","summary":"Custom pricing","features":["Everything in Business, plus:","Enterprise-grade SLAs","Custom retention policies","Advanced compliance reporting","Enterprise-grade APIs","Custom deployment options","SSO","Rules based access controls (RBAC)"],"description":"For organizations needing custom deployment and enterprise features.","contactSales":true,"includedLimits":{"projects":"Unlimited","dependency_levels":"Unlimited"}}],"addOns":[{"name":"Snippet Scanning Add-On"},{"name":"Binary Scanning Add-On"}],"summary":"Free plan available; Business from $20/project/month billed annually; Enterprise custom pricing","currency":"USD","freeTier":true,"sourceUrl":"https://fossa.com/pricing/","retrievedAt":"2026-08-25T08:26:28.708Z","startingPrice":{"unit":"project","amount":20,"period":"month","currency":"USD"},"billingPeriods":["month","year"]}` | - |
| pricing.free_tier | yes | - |
| pricing.model | freemium | commercial |
| pricing.price_level | mid | - |
| pricing.starting_price | `{"amount":20,"currency":"USD"}` | - |
| pricing.transparent | no | - |
| release.cadence_days | - | 28 |
| release.history | - | `[{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v13.0.0","date":"2026-08-03T10:43:02Z","type":"stable","version":"v13.0.0"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.2.2","date":"2026-05-03T11:14:06Z","type":"stable","version":"v12.2.2"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.2.1","date":"2026-04-11T16:29:37Z","type":"stable","version":"v12.2.1"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.2.0","date":"2026-01-09T13:48:40Z","type":"stable","version":"v12.2.0"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.1.9","date":"2025-11-11T12:54:03Z","type":"stable","version":"v12.1.9"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.1.8","date":"2025-10-13T15:14:09Z","type":"stable","version":"v12.1.8"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.1.7","date":"2025-10-12T14:09:07Z","type":"stable","version":"v12.1.7"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.1.6","date":"2025-09-24T12:39:10Z","type":"stable","version":"v12.1.6"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.1.5","date":"2025-09-20T13:18:54Z","type":"stable","version":"v12.1.5"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.1.3","date":"2025-06-10T11:54:06Z","type":"stable","version":"v12.1.3"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.1.2","date":"2025-06-07T11:11:56Z","type":"stable","version":"v12.1.2"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.1.1","date":"2025-04-05T11:56:54Z","type":"stable","version":"v12.1.1"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.1.0","date":"2025-02-16T14:39:29Z","type":"stable","version":"v12.1.0"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.0.2","date":"2025-01-30T12:54:57Z","type":"stable","version":"v12.0.2"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.0.1","date":"2025-01-19T13:49:18Z","type":"stable","version":"v12.0.1"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v12.0.0","date":"2025-01-11T15:41:16Z","type":"stable","version":"v12.0.0"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v11.1.1","date":"2024-12-04T11:10:47Z","type":"stable","version":"v11.1.1"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v11.1.0","date":"2024-10-30T10:11:27Z","type":"stable","version":"v11.1.0"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v11.0.0","date":"2024-10-21T11:07:39Z","type":"stable","version":"v11.0.0"},{"url":"https://github.com/dependency-check/DependencyCheck/releases/tag/v10.0.4","date":"2024-09-01T12:14:16Z","type":"stable","version":"v10.0.4"}]` |
| security.soc2 | yes | - |
| security.vulnerabilities | - | `{"count":2,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=maven&package_name=org.owasp%3Adependency-check-maven&per_page=100","last_12m":0,"max_severity":"HIGH"}` |

## Capabilities (Dependency Management)

| Capability | FOSSA | OWASP Dependency-Check |
|---|:--:|:--:|
| **Capabilities** |  |  |
| Update automation | ✓ | - |
| Vuln scanning | ✓ | - |
| Reachability analysis | ✗ | - |
| License compliance | ✓ | - |
| Sbom generation | ✓ | - |
| Ci gating | ✓ | - |
| Container image scanning | ✓ | - |
| Auto merge policy | ✗ | - |
| Open source | ✓ | - |

*Source: Vioscale. Generated 2026-09-01T17:26:55.750Z. "-" = undocumented, not absent.*
