Software Alternatives & Reviews
Table of contents
  1. Social Mentions
  2. Comments

OWASP Dependency-Track

OWASP Dependency-Track is an intelligent Software Composition Analysis (SCA) platform that allows... subtitle

OWASP Dependency-Track Reviews and details

Screenshots and images

  • OWASP Dependency-Track Landing page
    Landing page //
    2023-02-03

Badges

Promote OWASP Dependency-Track. You can add any of these badges on your website.
SaaSHub badge
Show embed code

Social recommendations and mentions

We have tracked the following product recommendations or mentions on various public social media platforms and blogs. They can help you see what people think about OWASP Dependency-Track and what they use it for.
  • Show HN: Pre-alpha tool for analyzing spdx SBOMs generated by GitHub
    I've become interested in SBOM recently, and found there were great tools like https://dependencytrack.org/ for CycloneDX SBOMs, but all I have is SPDX SBOMs generated by GitHub. I decided to have a go at writing my own dependency track esque tool aiming to integrate with the APIs GitHub provides. It's pretty limited in functionality so far, but can give a high level summary of the types of licenses your... - Source: Hacker News / 5 days ago
  • SQL Injection Isn't Dead Yet
    To detect these types of vulnerabilities, we should first and foremost know our dependencies and versions, and which of them have vulnerabilities. The OWASP Top 10 2021 identifies this need as A06:2021-Vulnerable and Outdated Components. OWASP has several tools for this, including Dependency Check and Dependency Track. These tools will warn about the use of components with vulnerabilities. - Source: dev.to / 15 days ago
  • Krita fund has 0 corporate support
    Https://dependencytrack.org/ You just need to use one of the various tools out there to scan. - Source: Hacker News / 7 months ago
  • Friends - needs help choosing solution for SBOM vulnerability
    OWASP Dependency Track - https://dependencytrack.org/. Source: 11 months ago
  • software inventory of my ECS tasks
    I actually want to build the same thing you are after, and I think I’ll go for the setup you describe in idea 2. The tool you can use for this is Trivy (https://trivy.dev), have it generate a SBOM and send it to Dependencytrack (https://dependencytrack.org). Source: over 1 year ago
  • The ultimate guide to Java Security Vulnerabilities (CVE)
    If you like Dependency-Track, consider moving to Dependency-Track ( https://dependencytrack.org ), which makes administration much easier. Source: over 1 year ago
  • The SBOM Frenzy Is Premature
    I don't quite understand the deployment issue. I mean, I understand people might not be tracking what's deployed, but I don't understand what is missing for it to be happening today, other than will. For example: I build some software into a Docker image, version tag it, sign it, and generate an SBOM for it. That image goes into production with signature validation. Even if I've included 100 jar files in there, I... - Source: Hacker News / over 1 year ago
  • CycloneDX SBom (Software Bill of material) Maven Demo
    CycloneDX SBOM file can be used for project vulnerability analysis using the OWASP Dependency Track](https://dependencytrack.org/) application. - Source: dev.to / over 1 year ago
  • 8 top SBOM tools to consider
    It's missing DependencyTrack which has been adopted by OWASP. Source: almost 2 years ago
  • Ask HN: Open-source SBOM generation tools?
    We use this - https://dependencytrack.org/. - Source: Hacker News / almost 2 years ago
  • Microsoft open sources Salus software bill of materials (SBOM) generation tool
    I'm confused. When would I need "https://dependencytrack.org/"? Is it when I've completely lost my marbles and can no longer answer the questions "what does your app run on" and "what are your app's dependencies"? Is the idea that I would then download and install this "dependency tracker", hoping it would give me a list of things I depend on, so that I could inform the end user? What's the use case? - Source: Hacker News / almost 2 years ago
  • Microsoft open sources Salus software bill of materials (SBOM) generation tool
    There is an open source UI for querying based on SBOM called DependencyTrack (https://dependencytrack.org/). Commercial offerings exist from vendors like TideLift (https://tidelift.com/). - Source: Hacker News / almost 2 years ago
  • Security in CICD / DevSecOps
    From OWASP for those class of tools you could look into DependencyCheck and DependencyTrack. Source: about 2 years ago
  • Hi, Any thumb rules or selection criteria to determine appropriate security tools for the DevSecOps pipeline without getting bogged down with so many tools. Please advice. Thanks.
    Dependency Track (SCA) That is if your VCS doesn't already have something baked in. Source: over 2 years ago
  • OWASP CycloneDX – The Open Source SBOM Format
    Submitting it due to the latest Log4J vuln, should go hand in hand with OWASP DepTrack https://dependencytrack.org/ combined they provide pretty much the best SCA experience there is OWASP DepTrack has excellent UI and is enterprise ready with OIDC/SSO support to boot. This is by far the best OWASP project so far and I dare say the best FOSS security project I’ve seen rivaling and beating pretty much every... - Source: Hacker News / over 2 years ago
  • Updating projects
    We do it monthly, and use Dependency Track to not miss out on crucial updates. Source: over 2 years ago
  • Black Duck security pricing
    Dependency Track is a platform that ingests SBOMs (CycloneDX, SPDX formats) and produces component analysis reports for your projects. CycloneDX has support for a wide range of package managers and is able to pull a full list of project dependencies and licenses out of your project. Source: almost 3 years ago
  • CVE Alerting Platform
    There is also https://dependencytrack.org/ which allows you to gather your software dependencies and notifies you when new vulnerabilities are found for them. - Source: Hacker News / about 3 years ago
  • Secure coding for Clojure/Script
    I am particularly interested in scanning vulnerabilities in third party libraries, both in Clojure & ClojureScript — e.g., tools such as the OWASP Dependency Track and Snyk, which have integrations with Maven and NPM. Given the hosted approach of Clojure/Script, I would assume that it is possible to somehow take this route, but before diving too deep into it, I was hoping some of you might share their approach. Source: about 3 years ago

Do you know an article comparing OWASP Dependency-Track to other products?
Suggest a link to a post with product alternatives.

Suggest an article

Generic OWASP Dependency-Track discussion

Log in or Post with

This is an informative page about OWASP Dependency-Track. You can review and discuss the product here. The primary details have not been verified within the last quarter, and they might be outdated. If you think we are missing something, please use the means on this page to comment or suggest changes. All reviews and comments are highly encouranged and appreciated as they help everyone in the community to make an informed choice. Please always be kind and objective when evaluating a product and sharing your opinion.