OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
-
Updated
Sep 23, 2026 - Java
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
A simple Java command-line utility to mirror the CVE JSON data from NIST.
Maven plugin that integrates with a Dependency Track server to submit dependency manifests and optionally fail execution when vulnerable dependencies are found.
A simple Java command-line utility to mirror the entire contents of VulnDB.
Damn Vulnerable SCA Application
Lucy is a component analysis platform to minimize the risk of license infringements and to support and optimize the license compliance process.
SCANOSS Java package providing a simple, easy to consume library for interacting with SCANOSS APIs.
gradle pipeline
End-to-end DevSecOps CI/CD pipeline for a Java application using Jenkins, AWS, Docker, SonarCloud, Snyk, Trivy, and OWASP ZAP Baseline Scan.
Open-source Software Watchlist — self-hosted SCA platform for CVE & license risk tracking
To associate your repository with the software-composition-analysis topic, visit your repo's landing page and select "manage topics."