Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
-
Updated
Dec 18, 2025 - Java
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
Integrates Dependency-Check reports into SonarQube
Jenkins plugin for OWASP Dependency-Check. Inspects project components for known vulnerabilities (e.g. CVEs).
Maven plugin that integrates with a Dependency Track server to submit dependency manifests and optionally fail execution when vulnerable dependencies are found.
Main repository for the official Dependency-Track Jenkins plugin
ImageJ library to detect and analyse connected components (blobs) in binary images
Integrates dependency-updates-report into SonarQube
Integrates dependency license check into SonarQube
Add a description, image, and links to the component-analysis topic page so that developers can more easily learn about it.
To associate your repository with the component-analysis topic, visit your repo's landing page and select "manage topics."