Skip to content

Dependency-Track

medium

OWASP software supply chain risk platform for SBOM analysis and dependency vulnerability tracking.

2 GB RAM Docker Active Apache-2.0

Replaces

Pros

  • Purpose-built SBOM and dependency risk tracking
  • Good fit for software teams with compliance needs
  • Integrates with CI pipelines and scanners

Cons

  • Requires SBOM generation to be useful
  • More security-program tooling than general app scanner
  • Needs ongoing vulnerability feed and policy tuning

Tags

Need a server? Hosting recommendations

Related

Similar Apps