Full-Stack Inventory
Track libraries, frameworks, applications, containers, operating systems, firmware, hardware, and services.
Dependency-Track helps organizations identify and reduce risk in the software supply chain, from a single team to enterprise portfolios of hundreds of thousands of projects.
Build a complete, continuously updated record of everything you ship, from one SBOM standard.
Track libraries, frameworks, applications, containers, operating systems, firmware, hardware, and services.
Consume, analyze, and produce CycloneDX SBOM, HBOM, VEX, and VDR, an international standard.
Model your portfolio by product, team, or environment with parent and child project hierarchies.
Roll up metrics across versions, services, and environments without forcing a single tag scheme.
Keep every release of a project side by side and flag the current one as the latest version.
A well documented REST API makes Dependency-Track a natural fit for modern CI/CD pipelines.
Surface vulnerabilities, integrity failures, and risk the moment they emerge, not on a periodic scan.
Match components against the NVD, GitHub Advisories, and OSV, plus OSS Index, Snyk, Trivy, and VulnDB.
The internal analyzer matches against mirrored data with no outbound calls, so analysis is fast and repeatable.
Flag components whose published hashes diverge from the upstream registry, catching typosquatting and tampering.
Prioritize mitigation with integrated support for the Exploit Prediction Scoring System (EPSS).
Triage every finding with analysis state, justification, and a permanent, exportable audit trail.
Trend the risk score and finding counts of every project and the whole portfolio over time.
Turn your standards into enforceable policy and the machine-readable evidence regulators now expect.
A Common Expression Language (CEL) engine evaluates component policies and breaks the build on a fail.
Automatically audit or suppress findings before they reach analysts or trigger a notification.
Ban copyleft licenses, allow-list with SPDX expressions, and group licenses for readable rules.
Produce and consume CycloneDX Vulnerability Exploitability eXchange and Disclosure Reports.
Least-privilege access by team and project hierarchy, now generally available with bounded overhead.
Route alerts to Slack, Teams, Mattermost, email, and webhooks, filtered on any field with CEL.
The v5 redesign rebuilt the engine to stay up, never silently lose work, and run from one team to an enterprise portfolio.
Stateless instances coordinate through PostgreSQL alone, with no broker, for active/active high availability across zones.
BOM processing, analysis, and notifications resume from the exact step they reached and retry automatically with backoff.
Standardizes on PostgreSQL and moves search, caching, and metrics into the database, retiring the local index.
A dedicated management port exposes Prometheus metrics and Kubernetes liveness and readiness probes.
Integration credentials live behind one pluggable provider, so you rotate and audit in a single place.
Single Sign-On via OpenID Connect, with Active Directory and LDAP, plus configurable data retention.
Consumes and produces SBOM, VEX, VDR, and more in the OWASP CycloneDX standard.
Output that meets or exceeds NIST SP 800-161 and CISA minimum SBOM guidance.
Maintain the complete, current inventory the EU Cyber Resilience Act expects.
Connectors & integrations
Dependency-Track is free and open source. Join the teams across more than 20,000 organizations who help shape the project.