dependencytrack/dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 10 minutes ago
Type:Server / PlatformCategory(s):AppSec & Supply ChainSecurity & Privacy
Added to GitGenius on September 16th, 2026
Created on July 16th, 2013
Open Issues & Pull Requests: 1,077 (+0)
GitHub issues: Enabled
Number of forks: 817
Total Stargazers: 4,224 (+0)
Total Subscribers: 75 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 19.7 hours
Mean response time: 76.0 days
90th percentile: 195.1 days
Tracked items: 989

Most active contributors

Sign in to see contributor activity.

How this project is maintained

Roughly one issue in five opened in the past year never receives a reply. 92% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. Work labelled "pending more information" is answered fastest, typically in about an hour, while "p3" waits about 4 days. 58% of tracked open issues have had no activity in three months. Only 54% of issues opened in the past year have been closed.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 562
New in 7 days: 11
Closed in 7 days: 18
Avg open age: 630 days
Stale 30+ days: 490
Stale 90+ days: 410

Recent activity

Opened in 7 days: 11
Closed in 7 days: 18
Comments in 7 days: 6
Events in 7 days: 43

Top labels

  • defect (598)
  • enhancement (424)
  • p2 (325)
  • size/S (240)
  • in triage (230)
  • size/M (75)
  • p3 (65)
  • duplicate (56)

Detailed Description

Dependency-Track is a component analysis platform that identifies and reduces risk in the software supply chain by analyzing software bill of materials.

The tool addresses the challenge of understanding and managing vulnerabilities across software dependencies at scale. It takes a SBOM-centric approach, leveraging software bill of materials as the foundation for intelligent component analysis. This allows organizations to gain visibility into their supply chain risk by analyzing the components that make up their applications and detecting known vulnerabilities within those components.

Organizations building applications with complex dependency trees should consider Dependency-Track when they need centralized visibility into component vulnerabilities and supply chain risk. The platform suits teams practicing software composition analysis and those required to maintain detailed records of software components for compliance or security purposes. It integrates with standard formats like CycloneDX and supports package identification through Package URL, making it compatible with modern software supply chain tooling.

The project maintains an active community with regular monthly meetings and welcomes contributions through established guidelines. Development activity spans multiple repositories including dedicated projects for the frontend, documentation, and Kubernetes deployment via Helm charts, indicating sustained investment in the platform's ecosystem. The project explicitly supports a migration path from the previous major version, with the earlier release in maintenance mode through a defined end-of-life window.