OWASP Dependency-Track

Also known as
owasp-dependency-track

What is OWASP Dependency-Track?

Provides organizations with a centralized inventory of software components across their entire technology stack and identifies security vulnerabilities from multiple authoritative sources. Designed for continuous monitoring and risk assessment within CI/CD pipelines, with policies to enforce compliance and team notifications.

Independently observed

OWASP Dependency-Track pricing

We don't have OWASP Dependency-Track's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

Platform & deployment

Independently observed
Platforms
  • CLI
  • Web
Deployment
  • On-premise
  • Self-hosted

Integrations (15)

Independently observed
  • NVD
  • Sonatype OSS Index
  • GitHub Advisories
  • Snyk
  • OSV
  • Trivy
  • VulnDB
  • Slack
  • Teams
  • Mattermost
  • Email
  • Webhooks
  • OpenID Connect
  • Active Directory
  • LDAP

Security & compliance

Known vulnerabilities: 0 (0 in the last 12 months) sourcea count reflects scale & disclosure, not quality

OWASP Dependency-Track alternatives

Other dependency management we track, ranked by the same independent score.

All OWASP Dependency-Track alternatives, ranked →

Compare OWASP Dependency-Track

Side by side against other dependency management, attribute by attribute, with a source on every value.

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for OWASP Dependency-Track, not the verdict.

Balanced composite 59 / 100
low · 28%updating
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Pricing transparency800.086.7
Development activity630.095.9
Price level1000.055.2
Release cadence880.054.6
Integrations350.093.2
Stars680.031.8
Reliability00.070.0-
Capabilities00.080.0-
Dependent projects00.060.0
Security posture00.070.0-
Package downloads00.140.0-
Security score00.040.0-
Developer Q&A activity00.060.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d100mediumsource · 2026-08-26 · 65%

Adoption

AttributeValueEvidence
Github stars4,146highsource · 2026-08-26 · 90%
Dependent repos0highsource · 2026-08-26 · 85%

Integrations

AttributeValueEvidence
Count15mediumsource · 2026-08-18 · 60%

Language

AttributeValueEvidence
PrimaryJavahighsource · 2026-08-26 · 90%

License

AttributeValueEvidence
SpdxApache-2.0highsource · 2026-08-26 · 95%

Pricing

AttributeValueEvidence
Modelcommerciallowsource · 2026-08-26 · 40%
Free tierYesmediumsource · 2026-08-18 · 60%
Price levelfreemediumsource · 2026-08-18 · 60%
TransparentYesmediumsource · 2026-08-18 · 60%

Release

AttributeValueEvidence
Cadence days21mediumsource · 2026-08-26 · 70%
History20 itemsmediumsource · 2026-08-26 · 70%

Security

AttributeValueEvidence
VulnerabilitiesCount: 0 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=nixpkgs&package_name=dependency-track&per_page=100 · Last 12m: 0highsource · 2026-08-26 · 90%