Built something? We create video reels & spotlights for GitHub projects.Promote your project →
DependencyTrack
Home / Java / dependency-track

DependencyTrack/dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Java ◇ appsec Apache-2.0
★4.2KSTARS
⑂818FORKS
!1,042ISSUES
🏆#1,199GLOBAL RANK
🔥5DAYS TRENDING
🚀
Maintainer Growth Kit for dependency-track

Claim this project, add your verified backlink badge to your README, and download milestone cards.

Claim Repo

Star History

Continuous Observations
Interactive star growth chart for DependencyTrack/dependency-track
CSV

Momentum

+106

STARS · LAST 30 DAYS

4

PER DAY

#83

MOST-STARRED Java

Window7 days30 days90 days
Stars gained+28+106+360
Per day444
Forks gained+4+16+41

dependency-track gained 106 stars in the last 30 days, about 4 a day, and now has 4.2K. It is about 13 years old and has averaged roughly 326 stars a year. It ranks #83 among Java repositories and #1,199 across all languages on GitHubRepo.

Trending Record

dependency-track has maintained a continuous presence across global trending indexes, peaking at #770. Below is the 30-day activity profile:

💡 Overview

dependency-track is an open-source project written in Java: Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Engineered for speed, consistency, and developer ease, it solves common hurdles in appsec, bill-of-materials, bom. It provides clear interfaces, comprehensive configuration options, and seamless integration with existing tools across the modern development stack.

⚡ Key Features

1

Optimized execution pipeline written in Java for predictable speed.

2

Zero-friction configuration with comprehensive sensible defaults out of the box.

3

Cross-platform runtime support across Linux, macOS, and Windows environments.

4

Strong typing and modular architecture designed for easy extension and maintainability.

5

Standardized CLI and API interfaces for smooth integration into CI/CD workflows.

6

Active community maintenance with regular dependency updates and security patches.

📥 Installation

terminal
$ git clone https://github.com/DependencyTrack/dependency-track.git
cd dependency-track

⚙ System Requirements

Platforms

  • • macOS
  • • Linux
  • • Windows

Runtime & Dependencies

JDK 17 or higher (OpenJDK / GraalVM)

Architecture

x86_64, ARM64 (Apple Silicon & Graviton)

🧠 How It Works

dependency-track coordinates its core functionality through a modular Java pipeline. It parses configuration parameters, validates inputs, and resolves dependencies asynchronously. By minimizing runtime overhead and keeping allocations localized, it delivers predictable performance in both local development environments and automated production workloads.

🎯 Production Use Cases

Production System Integration

Embed dependency-track into Java backend services to handle core application logic.

CI/CD Automated Pipelines

Run automated validation, builds, and integration suites during deployments.

Developer Tooling & Workflows

Accelerate developer onboarding with pre-configured project utilities.

Open Source Extension

Fork and customize internal modules under the repository's open Apache-2.0 license.

🚀 Getting Started

1

Install dependency-track using your package manager: `git clone https://github.com/DependencyTrack/dependency-track.git`

2

Initialize your project workspace or configuration file for dependency-track.

3

Import dependency-track into your codebase or invoke it directly from your terminal.

4

Execute your test suite or run `dependency-track --help` to verify successful setup.

👍 Strengths

Active community backing with 4,235 GitHub stars and verified adoption.
Permissive open-source distribution under the Apache-2.0 license.
Built in Java for high execution speed and developer familiarity.
Cross-platform compatibility across modern Linux, macOS, and Windows environments.
Clean modular design allowing flexible configuration and pipeline integration.

⚠️ Considerations

Requires familiarity with Java and modern CLI workflows.
Ecosystem extensions may require manual configuration depending on environment constraints.
Active development roadmap means breaking API changes may occur across major versions.

⇄ Alternatives & Direct Competitors

S

Spring Boot helps you to create Spring-powered, production-grade applications and services with absolute minimum fuss.

Compare ↗
G
google/guava ★ 51.9K Java

Google core libraries for Java

Compare ↗
D
apache/dubbo ★ 41.6K Java

The java implementation of Apache Dubbo. An RPC and microservice framework.

Compare ↗
T
eugenp/tutorials ★ 37.3K Java

Getting Started with Spring Boot 3:

Compare ↗

👥 Who Should Use This

Developers and engineering teams building with Java, seeking reliable, tested, and actively maintained tooling for production workloads.

🏆 Nearby in the Rankings

DependencyTrack/dependency-track is currently ranked #1,199 by stars across every repository tracked on GitHubRepo. These are adjacent projects:

RankRepositoryLanguageStarsAction
#1,194 robinebers/openusage Swift ★ 4.3K Compare ↗
#1,195 symfony/config PHP ★ 4.3K Compare ↗
#1,196 clementine-player/Clementine C++ ★ 4.3K Compare ↗
#1,197 codeceptjs/CodeceptJS JavaScript ★ 4.2K Compare ↗
#1,198 GradleUp/shadow Kotlin ★ 4.2K Compare ↗
#1,199 DependencyTrack/dependency-track This Project Java ★ 4.2K
#1,199 nolabs-ai/nono Rust ★ 4.2K Compare ↗
#1,201 irbis-sh/zen-desktop Go ★ 4.2K Compare ↗
#1,202 PurpleI2P/i2pd C++ ★ 4.2K Compare ↗
#1,203 cake-build/cake C# ★ 4.2K Compare ↗
#1,204 DioxusLabs/blitz Rust ★ 4.2K Compare ↗

Frequently Asked Questions

What does dependency-track do? +

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

What language is dependency-track written in? +

The primary language is Java. Topics include: appsec, bill-of-materials, bom, component-analysis, cyclonedx.

Is dependency-track actively maintained? +

Yes, the last recorded push was on Sep 26, 2026 with 1,042 open issues being tracked.

How many stars does dependency-track have? +

dependency-track has 4,239 stars and 818 forks on GitHub.

How does dependency-track rank among GitHub repositories? +

With 4,239 stars, DependencyTrack/dependency-track is ranked #1,199 globally across all repositories tracked on GitHubRepo and #83 among Java projects.

What license is dependency-track distributed under? +

The repository reports a Apache-2.0 license. Always verify the repository LICENSE file for legal terms.

From our network
FOR MAINTAINERS

Built something? Put it in front of millions of developers.

We make a short reel about your project and post it across YouTube, Instagram, Threads, and X. Send a link, we do the rest.