Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM).
Warning
Dependency-Track v5 is currently in release candidate stage and not yet generally available.
v5 release candidates are published for testing and feedback. They are not
recommended for production deployments. The release candidate images are
tagged 5.0.0-rc.<N> and are not pulled by :5-snapshot.
For production use, stay on the latest v4 release.
Important
Looking for Dependency-Track v4?
- v4 is in maintenance mode on the
4.14.xbranch. - v4 documentation: https://docs.dependencytrack.org/.
- Migrating from v4 to v5? See V5_MIGRATION.md.
- v4 will reach end-of-life ~6 months after v5 GA.
User-facing documentation is rendered at dependencytrack.github.io/docs/next and maintained in the docs repository.
- frontend: Frontend repository
- docs: Documentation repository
- helm-charts: Helm charts
- community: Community resources