# dependency-track
**Repository Path**: trusted-list/dependency-track
## Basic Information
- **Project Name**: dependency-track
- **Description**: Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
- **Primary Language**: Unknown
- **License**: Apache-2.0
- **Default Branch**: main
- **Homepage**: https://dependencytrack.org/
- **GVP Project**: No
## Statistics
- **Stars**: 0
- **Forks**: 0
- **Created**: 2026-03-14
- **Last Updated**: 2026-08-24
## Categories & Tags
**Categories**: Uncategorized
**Tags**: None
## README
# OWASP Dependency-Track
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk
in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the
capabilities of Software Bill of Materials (SBOM).
[](https://dependencytrack.org/)
[](https://dependencytrack.github.io/docs/)
[](https://hub.docker.com/r/dependencytrack/apiserver)
[](LICENSE.txt)
[](https://github.com/DependencyTrack/dependency-track/actions/workflows/ci-build.yaml)
[](https://github.com/DependencyTrack/dependency-track/actions/workflows/ci-test.yaml)
[](https://github.com/DependencyTrack/dependency-track/actions/workflows/ci-test-e2e.yaml)
[](https://app.codacy.com/gh/DependencyTrack/dependency-track/dashboard)
[](https://www.linkedin.com/company/owasp-dependency-track)
[](https://bsky.app/profile/dependencytrack.bsky.social)
[](https://infosec.exchange/@DependencyTrack)
[](https://www.youtube.com/@DependencyTrack)
> [!IMPORTANT]
> **Looking for Dependency-Track v4?**
> * v4 is in maintenance mode on the [`4.14.x` branch](https://github.com/DependencyTrack/dependency-track/tree/4.14.x).
> * v4 documentation: .
> * Migrating from v4 to v5? See [V5_MIGRATION.md](./V5_MIGRATION.md).
> * v4 will reach end-of-life in December 2026, *~6 months* after v5 GA.
## Quickstart
Want to kick the tires? Follow the [Quickstart tutorial](https://dependencytrack.github.io/docs/next/tutorials/quickstart/)
to get a local instance running with Docker Compose in a few minutes.
## Documentation
User-facing documentation is rendered at and maintained in the [docs](https://github.com/DependencyTrack/docs) repository.
## Contributing
1. [Code of conduct](CODE_OF_CONDUCT.md)
2. [Contribution guidelines](CONTRIBUTING.md)
3. [Developer guide](DEVELOPING.md)
## Community
Dependency-Track is an open source project maintained by a community of contributors.
Join the [monthly community meeting](https://github.com/DependencyTrack/community#community-meetings)
to hear project updates, ask questions, and meet other users and maintainers.
## See also
* [frontend](https://github.com/DependencyTrack/frontend): Frontend repository
* [docs](https://github.com/DependencyTrack/docs): Documentation repository
* [helm-charts](https://github.com/DependencyTrack/helm-charts): [Helm](https://helm.sh/) charts
* [community](https://github.com/DependencyTrack/community): Community resources