Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. https://dependencytrack.org/
Find a file
2026-06-12 12:33:51 +00:00
.github Merge pull request #6229 from DependencyTrack/dependabot/github_actions/docker/login-action-4.2.0 2026-06-02 12:08:16 +02:00
.idea Rename container image and add tag policy 2026-05-28 17:45:10 +02:00
.mvn Always run manifest generation for DN plugin, even when restoring from cache 2026-06-04 15:42:34 +02:00
alpine [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
api [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
apiserver [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
cache [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
common [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
coverage-report [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
dev Standardize config property names and remove legacy shims 2026-06-01 00:45:22 +02:00
dex [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
docs/adr Document expected ADR format and writing style 2026-06-05 16:38:15 +02:00
e2e [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
file-storage [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
migration [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
notification [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
package-metadata [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
plugin [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
proto [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
secret-management [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
support [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
vuln-analysis [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
vuln-data-source [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
.gitignore Implement CSAF support (#1462) 2025-11-20 11:28:02 +01:00
AGENTS.md Document expected ADR format and writing style 2026-06-05 16:38:15 +02:00
buf.yaml Leverage conditional revalidation for package metadata resolution 2026-05-04 16:56:51 +02:00
CLAUDE.md Add AGENTS.md 2026-02-27 16:29:35 +01:00
CODE_OF_CONDUCT.md initial commit 2018-10-02 16:03:51 -05:00
CONTRIBUTING.md Document expected ADR format and writing style 2026-06-05 16:38:15 +02:00
DEVELOPING.md Document expected ADR format and writing style 2026-06-05 16:38:15 +02:00
LICENSE.txt Create LICENSE.txt 2017-10-28 15:22:16 -05:00
Makefile Add GHA workflow for nightly e2e tests 2026-05-30 14:27:01 +02:00
pom.xml [maven-release-plugin] prepare release 5.0.1 2026-06-12 12:33:51 +00:00
README.md Update README for GA release 2026-06-07 17:00:13 +02:00
RELEASING.md Prepare 5.0.0-rc.1 release 2026-05-28 20:32:06 +02:00
SECURITY.md Updated email address 2021-10-07 08:00:54 -05:00
V5_MIGRATION.md Add v5 migration notes 2026-05-18 22:19:53 +02:00

OWASP Dependency-Track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM).

Build Status Test Status E2E Test Status Documentation License

Important

Looking for Dependency-Track v4?

Quickstart

Want to kick the tires? Follow the Quickstart tutorial to get a local instance running with Docker Compose in a few minutes.

Documentation

User-facing documentation is rendered at https://dependencytrack.github.io/docs/ and maintained in the docs repository.

Contributing

  1. Code of conduct
  2. Contribution guidelines
  3. Developer guide

Community

Dependency-Track is an open source project maintained by a community of contributors. Join the monthly community meeting to hear project updates, ask questions, and meet other users and maintainers.

See also