OSS Tanbou

match project dependencies to CPE and CVE data and detect known vulnerabilities from CLI, Maven, Gradle, and other build integrations

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
7,715
Primary language
Java
License
Apache-2.0
Repository last updated
Oct 2, 2026
On this page

Overview

OWASP Dependency-Check is a Software Composition Analysis tool that identifies likely CPEs for application dependencies and reports associated CVEs. It can run as a standalone CLI or through Maven, Gradle, Ant, Jenkins, and related build workflows.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Map dependencies to CPE identifiers and associated CVEs

Dependency-Check attempts to identify Common Platform Enumeration entries for dependencies and links matching CVE records into its vulnerability reports.

Sources: [1][2]

Choose between standalone CLI and build-tool integrations

The project supports the CLI as well as Maven, Gradle, Ant, Jenkins, and other integrations, so local investigations and CI gates can use the same vulnerability engine.

Sources: [1][2]

Keep generated reports as reviewable build artifacts

The CLI scans a target directory and generates reports that expose dependencies, identified CPEs, and associated CVEs for later review.

Sources: [2]

Best fit

Fits teams continuously checking application dependencies for known vulnerabilities

It is useful in verify stages and scheduled scans where dependency updates and vulnerability triage need to be part of the delivery workflow.

Sources: [1]

Before adoption

Design NVD API-key usage and CI caching before enforcing scans

The README strongly recommends an NVD API key and warns that updates are extremely slow without one. Reusing one key across many concurrent CI builds can hit rate limits, so cached or shared vulnerability data should be part of the design.

Sources: [1]

Treat external data sources and credentials as operational dependencies

Dependency-Check requires internet access to several external resources. The Sonatype OSS Index/Guide analyzer disables itself without credentials, and the project documents an ongoing migration from legacy OSS Index tokens to Sonatype Guide tokens during 2026.

Sources: [1]

Check Java requirements and database-schema changes during upgrades

Runtime versions 11.0.0 and later require Java 11 or newer. Version 12.2.2 also changed the external database schema, so external-DB users need the relevant update scripts before moving through the 13.0.0 upgrade.

Sources: [1][3][4]

Official sources

  1. [1]Dependency-Check 13.0.0 README(2026-10-04)
  2. [2]Dependency-Check 13.0.0 CLI guide(2026-10-04)
  3. [3]Dependency-Check changelog through 12.2.2(2026-10-04)
  4. [4]Dependency-Check 13.0.0 release(2026-10-04)
  5. [5]Dependency-Check Apache-2.0 license(2026-10-04)
Supplemental curator note

Treat vulnerability-data freshness as part of the CI result rather than only looking at findings. NVD updates are extremely slow without an API key, and sharing one key across many concurrent builds can hit rate limits, so design a cached or shared data strategy before making scans a release gate.

Try it in 3 steps

  1. 1

    Download the Dependency-Check 13.0.0 CLI release

    Pin the stable 13.0.0 CLI archive. For production use, also consider verifying the matching release signature.

    curl -L -o dependency-check-13.0.0-release.zip https://github.com/dependency-check/DependencyCheck/releases/download/v13.0.0/dependency-check-13.0.0-release.zip
  2. 2

    Extract the CLI into a dedicated directory

    The release archive expands the CLI scripts under dependency-check/bin.

    unzip -q dependency-check-13.0.0-release.zip -d dependency-check-13.0.0
  3. 3

    Inspect CLI options before the first scan

    A first real scan needs vulnerability-data updates. Prepare an NVD API key, internet access, and a CI caching strategy before using --scan.

    bash ./dependency-check-13.0.0/dependency-check/bin/dependency-check.sh --help
Check the official README

Growth

Growth trends · Last 30 days

7,715 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
39
Open PRs
4

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • security-audit
  • build-tool
  • maven-plugin
  • jenkins-plugin
  • gradle-plugin
  • vulnerability-detection
  • security
  • ant-task
  • software-composition-analysis
Stars
7,715
Forks
1,426
Watchers
175
Open issues
180
Contributors
324
Owner type
Organization
Primary language
Java
License
Apache-2.0
Repository last updated
Oct 2, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?