DependencyTrack / dependency-track
OWASP-backed open source platform for software supply chain security through SBOM analysis and vulnerability management
正常维护 Apache 2.0 Java Tracked
4.2k 807 12 小时前
CI
owasp appsec security bom vulnerabilities component-analysis nvd software-security software-composition-analysis sca bill-of-materials package-url purl vulnerability-detection ossindex sbom devsecops security-automation cyclonedx hacktoberfest
星标趋势
数据积累中,暂无足够数据生成趋势图
AI 分析
项目摘要
OWASP Dependency-Track is a mature component analysis platform for software supply chain security that leverages Software Bill of Materials (SBOM) to identify and track vulnerabilities in dependencies. It supports multiple vulnerability databases and integrates into DevSecOps pipelines.
为什么值得关注
As an OWASP project with nearly 4,000 stars and active development, it provides a vendor-neutral, open-source solution for SBOM-based vulnerability management at a time when software supply chain security is becoming critical for compliance and risk management.
优势
- OWASP-backed with strong community and governance
- SBOM-first approach aligned with modern supply chain security standards
- Active development with frequent releases and CI/CD integration
- Supports multiple vulnerability sources (NVD, OSSIndex) and CycloneDX format
局限性
- Not an AI/ML project - purely a security/SCA tool
- High number of open issues (958) suggests maintenance challenges
- v4 in maintenance mode requiring migration to v5
使用场景
- Software supply chain risk management and compliance
- SBOM generation, analysis, and monitoring across projects
- Vulnerability tracking and policy enforcement in CI/CD pipelines
- Open source license compliance and component inventory management
目标用户: Security engineers, DevSecOps teams, compliance officers, and development organizations managing open source dependencies
学习曲线: 中
分析模型:LongCat-2.0 | 分析时间:1 个月前