Looking for a OWASP Dependency-Track alternative? We've compiled the best options based on user reviews, features, and pricing to help you find the right fit.
What is OWASP Dependency-Track? OWASP Dependency-Track is an open source software composition analysis tool that allows organizations to identify and reduce risk from the use of third-party and open source components. It scans project dependencies and generates reports on vulnerabilities, licenses, and other metadata to support policy enforcement and provide visibility into software supply chain risks.
WhiteSource Bolt is an open source management platform that provides visibility and control over open source components in software projects. …
WhiteSource is an open source management platform that provides visibility, security and license compliance for open source components. It automatically …
Mend Renovate is a no-code platform that allows anyone to build internal tools, automate workflows, and create web apps without …
Black Duck Software offers solutions for managing open source security, compliance, and code quality across an organization's applications and containers. …
OWASP Dependency-Track is an open source software composition analysis and software supply chain management tool that allows organizations to identify and reduce risk from the use of third-party and open source components.It works by scanning project dependencies and generating reports on vulnerabilities, licenses, and other metadata to support organizational policy enforcement, facilitate open source governance, and provide visibility into risk associated with software dependencies.Key features include:Identification of all third-party transitive dependencies and associated metadata (CPEs, purls, licenses, cryptographic hashes, etc.)Detection …
Pricing: Open Source
| Software | Pricing | Score |
|---|---|---|
| OWASP Dependency-Track | Open Source | — |
| WhiteSource Bolt | Open Source | — |
| WhiteSource | Open Source | — |
| Mend Renovate | N/A | — |
| FOSSA | Open Source | — |
| git.legal | N/A | — |
| Black Duck Software | Open Source | — |
Read full OWASP Dependency-Track review → | Browse Security-Privacy software