Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components.
The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity providers via OpenID Connect and LDAP to manage user permissions and team synchronization.
The platform provides a broad set of capabilities including risk analysis, component tracking, and license auditing. It supports a full vulnerability management workflow, from detecting outdated components and cross-referencing public advisories to triaging security findings and monitoring portfolio-wide risk metrics.
Deployment options include Docker Compose, Helm charts for Kubernetes, and standalone executable archives.