# dependency-track **Repository Path**: huashan_mountain123/dependency-track ## Basic Information - **Project Name**: dependency-track - **Description**: No description available - **Primary Language**: Unknown - **License**: Apache-2.0 - **Default Branch**: master - **Homepage**: None - **GVP Project**: No ## Statistics - **Stars**: 0 - **Forks**: 0 - **Created**: 2021-01-14 - **Last Updated**: 2021-01-14 ## Categories & Tags **Categories**: Uncategorized **Tags**: None ## README [](https://github.com/DependencyTrack/dependency-track/actions?workflow=CI+Build) [](https://www.codacy.com/gh/DependencyTrack/dependency-track/dashboard?utm_source=github.com&utm_medium=referral&utm_content=DependencyTrack/dependency-track&utm_campaign=Badge_Grade) [](https://github.com/stevespringett/Alpine) [![License][license-image]][license-url] [](https://www.owasp.org/index.php/OWASP_Dependency_Track_Project) [](https://dependencytrack.org/) [](https://docs.dependencytrack.org/) [](https://dependencytrack.org/slack) [](https://dependencytrack.org/discussion) [](https://dependencytrack.org/youtube) [](https://twitter.com/dependencytrack) [](https://github.com/DependencyTrack/dependency-track/releases) [](https://github.com/DependencyTrack/dependency-track/releases) [](https://hub.docker.com/r/owasp/dependency-track/)  Dependency-Track is an intelligent [Component Analysis] platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of [Software Bill of Materials] (SBOM). This approach provides capabilities that traditional Software Composition Analysis (SCA) solutions cannot achieve. Dependency-Track monitors component usage across all versions of every application in its portfolio in order to proactively identify risk across an organization. The platform has an API-first design and is ideal for use in CI/CD environments.
## Ecosystem Overview  ## Features * Tracks application, library, framework, operating system, container, firmware, and hardware components * Tracks component usage across every application in an organizations portfolio * Identifies multiple forms of risk including * Components with known vulnerabilities * Out-of-date components * Modified components * License risk * More coming soon... * Integrates with multiple sources of vulnerability intelligence including: * [National Vulnerability Database] (NVD) * [NPM Public Advisories] * [Sonatype OSS Index] * [VulnDB] from [Risk Based Security] * More coming soon. * Robust policy engine with support for global and per-project policies * Security risk and compliance * License risk and compliance * Operational risk and compliance * Ecosystem agnostic with built-in repository support for: * Composer (PHP) * Gems (Ruby) * Hex (Erlang/Elixir) * Maven (Java) * NPM (Javascript) * NuGet (.NET) * Pypi (Python) * More coming soon. * Includes a comprehensive auditing workflow for triaging results * Configurable notifications supporting Slack, Microsoft Teams, Webhooks, and Email * Supports standardized SPDX license ID’s and tracks license use by component * Supports importing [CycloneDX] and [SPDX] Software Bill of Materials (SBOM) formats * Easy to read metrics for components, projects, and portfolio * Native support for Kenna Security, Fortify SSC, ThreadFix and DefectDojo * API-first design facilitates easy integration with other systems * API documentation available in OpenAPI format * OAuth 2.0 + OpenID Connect (OIDC) support for single sign-on (authN/authZ) * Supports internally managed users, Active Directory/LDAP, and API Keys * Simple to install and configure. Get up and running in just a few minutes