What is OWASP Dependency-Track?
Provides organizations with a centralized inventory of software components across their entire technology stack and identifies security vulnerabilities from multiple authoritative sources. Designed for continuous monitoring and risk assessment within CI/CD pipelines, with policies to enforce compliance and team notifications.
OWASP Dependency-Track pricing
We don't have OWASP Dependency-Track's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.
Platform & deployment
Independently observed- CLI
- Web
- On-premise
- Self-hosted
Integrations (15)
Independently observed- NVD
- Sonatype OSS Index
- GitHub Advisories
- Snyk
- OSV
- Trivy
- VulnDB
- Slack
- Teams
- Mattermost
- Webhooks
- OpenID Connect
- Active Directory
- LDAP
Security & compliance
Known vulnerabilities: 0 (0 in the last 12 months) sourcea count reflects scale & disclosure, not quality
OWASP Dependency-Track alternatives
Other dependency management we track, ranked by the same independent score.
- GitHub DependabotAutomatically scan dependencies for vulnerabilities and create pull requests to keep them updatedhigh · 76%
- OWASP Dependency-Checklow · 10%
- FOSSAAutomated open source dependency, license, and vulnerability management platform for controlling software supply chainsmedium · 56%
- pip-auditlow · 26%
- TideliftStatic code analysis platform for identifying security vulnerabilities, quality issues, and technical debt in software developmentlow · 29%
- Sonatype LifecycleAutomatically manage open source dependencies and identify vulnerabilities across your software supply chainlow · 15%
Compare OWASP Dependency-Track
Side by side against other dependency management, attribute by attribute, with a source on every value.
The Vioscale score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for OWASP Dependency-Track, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Pricing transparency | 80 | 0.08 | 6.7 | ✓ |
| Development activity | 63 | 0.09 | 5.9 | ✓ |
| Price level | 100 | 0.05 | 5.2 | ✓ |
| Release cadence | 88 | 0.05 | 4.6 | ✓ |
| Integrations | 35 | 0.09 | 3.2 | ✓ |
| Stars | 68 | 0.03 | 1.8 | ✓ |
| Reliability | 0 | 0.07 | 0.0 | - |
| Capabilities | 0 | 0.08 | 0.0 | - |
| Dependent projects | 0 | 0.06 | 0.0 | ✓ |
| Security posture | 0 | 0.07 | 0.0 | - |
| Package downloads | 0 | 0.14 | 0.0 | - |
| Security score | 0 | 0.04 | 0.0 | - |
| Developer Q&A activity | 0 | 0.06 | 0.0 | - |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Activity
| Attribute | Value | Evidence |
|---|---|---|
| Commits last 30d | 100 | mediumsource · 2026-08-26 · 65% |
Adoption
Integrations
| Attribute | Value | Evidence |
|---|---|---|
| Count | 15 | mediumsource · 2026-08-18 · 60% |
Language
| Attribute | Value | Evidence |
|---|---|---|
| Primary | Java | highsource · 2026-08-26 · 90% |
License
| Attribute | Value | Evidence |
|---|---|---|
| Spdx | Apache-2.0 | highsource · 2026-08-26 · 95% |
Pricing
Release
Security
| Attribute | Value | Evidence |
|---|---|---|
| Vulnerabilities | Count: 0 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=nixpkgs&package_name=dependency-track&per_page=100 · Last 12m: 0 | highsource · 2026-08-26 · 90% |