DependencyTrack/dependency-track
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
Star History
Momentum
+106
STARS · LAST 30 DAYS
4
PER DAY
#83
MOST-STARRED Java
| Window | 7 days | 30 days | 90 days |
|---|---|---|---|
| Stars gained | +28 | +106 | +360 |
| Per day | 4 | 4 | 4 |
| Forks gained | +4 | +16 | +41 |
dependency-track gained 106 stars in the last 30 days, about 4 a day, and now has 4.2K. It is about 13 years old and has averaged roughly 326 stars a year. It ranks #83 among Java repositories and #1,199 across all languages on GitHubRepo.
Trending Record
5
DAYS ON TRENDING
#770
BEST RANK
Sep 24, 2026
FIRST APPEARANCE
Active
STATUS TODAY
dependency-track has maintained a continuous presence across global trending indexes, peaking at #770. Below is the 30-day activity profile:
💡 Overview
dependency-track is an open-source project written in Java: Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
Engineered for speed, consistency, and developer ease, it solves common hurdles in appsec, bill-of-materials, bom. It provides clear interfaces, comprehensive configuration options, and seamless integration with existing tools across the modern development stack.
⚡ Key Features
Optimized execution pipeline written in Java for predictable speed.
Zero-friction configuration with comprehensive sensible defaults out of the box.
Cross-platform runtime support across Linux, macOS, and Windows environments.
Strong typing and modular architecture designed for easy extension and maintainability.
Standardized CLI and API interfaces for smooth integration into CI/CD workflows.
Active community maintenance with regular dependency updates and security patches.
📥 Installation
$ git clone https://github.com/DependencyTrack/dependency-track.git
cd dependency-track
⚙ System Requirements
Platforms
- • macOS
- • Linux
- • Windows
Runtime & Dependencies
JDK 17 or higher (OpenJDK / GraalVM)
Architecture
x86_64, ARM64 (Apple Silicon & Graviton)
🧠 How It Works
dependency-track coordinates its core functionality through a modular Java pipeline. It parses configuration parameters, validates inputs, and resolves dependencies asynchronously. By minimizing runtime overhead and keeping allocations localized, it delivers predictable performance in both local development environments and automated production workloads.
🎯 Production Use Cases
Production System Integration
Embed dependency-track into Java backend services to handle core application logic.
CI/CD Automated Pipelines
Run automated validation, builds, and integration suites during deployments.
Developer Tooling & Workflows
Accelerate developer onboarding with pre-configured project utilities.
Open Source Extension
Fork and customize internal modules under the repository's open Apache-2.0 license.
🚀 Getting Started
Install dependency-track using your package manager: `git clone https://github.com/DependencyTrack/dependency-track.git`
Initialize your project workspace or configuration file for dependency-track.
Import dependency-track into your codebase or invoke it directly from your terminal.
Execute your test suite or run `dependency-track --help` to verify successful setup.
👍 Strengths
⚠️ Considerations
⇄ Alternatives & Direct Competitors
👥 Who Should Use This
Developers and engineering teams building with Java, seeking reliable, tested, and actively maintained tooling for production workloads.
🏆 Nearby in the Rankings
DependencyTrack/dependency-track is currently ranked #1,199 by stars across every repository tracked on GitHubRepo. These are adjacent projects:
| Rank | Repository | Language | Stars | Action |
|---|---|---|---|---|
| #1,194 | robinebers/openusage | Swift | ★ 4.3K | Compare ↗ |
| #1,195 | symfony/config | PHP | ★ 4.3K | Compare ↗ |
| #1,196 | clementine-player/Clementine | C++ | ★ 4.3K | Compare ↗ |
| #1,197 | codeceptjs/CodeceptJS | JavaScript | ★ 4.2K | Compare ↗ |
| #1,198 | GradleUp/shadow | Kotlin | ★ 4.2K | Compare ↗ |
| #1,199 | DependencyTrack/dependency-track This Project | Java | ★ 4.2K | |
| #1,199 | nolabs-ai/nono | Rust | ★ 4.2K | Compare ↗ |
| #1,201 | irbis-sh/zen-desktop | Go | ★ 4.2K | Compare ↗ |
| #1,202 | PurpleI2P/i2pd | C++ | ★ 4.2K | Compare ↗ |
| #1,203 | cake-build/cake | C# | ★ 4.2K | Compare ↗ |
| #1,204 | DioxusLabs/blitz | Rust | ★ 4.2K | Compare ↗ |
Frequently Asked Questions
What does dependency-track do? +
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
What language is dependency-track written in? +
The primary language is Java. Topics include: appsec, bill-of-materials, bom, component-analysis, cyclonedx.
Is dependency-track actively maintained? +
Yes, the last recorded push was on Sep 26, 2026 with 1,042 open issues being tracked.
How many stars does dependency-track have? +
dependency-track has 4,239 stars and 818 forks on GitHub.
How does dependency-track rank among GitHub repositories? +
With 4,239 stars, DependencyTrack/dependency-track is ranked #1,199 globally across all repositories tracked on GitHubRepo and #83 among Java projects.
What license is dependency-track distributed under? +
The repository reports a Apache-2.0 license. Always verify the repository LICENSE file for legal terms.