On this page
Overview
OWASP Dependency-Check is a Software Composition Analysis tool that identifies likely CPEs for application dependencies and reports associated CVEs. It can run as a standalone CLI or through Maven, Gradle, Ant, Jenkins, and related build workflows.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Map dependencies to CPE identifiers and associated CVEs
Dependency-Check attempts to identify Common Platform Enumeration entries for dependencies and links matching CVE records into its vulnerability reports.
Choose between standalone CLI and build-tool integrations
The project supports the CLI as well as Maven, Gradle, Ant, Jenkins, and other integrations, so local investigations and CI gates can use the same vulnerability engine.
Keep generated reports as reviewable build artifacts
The CLI scans a target directory and generates reports that expose dependencies, identified CPEs, and associated CVEs for later review.
Sources: [2]
Best fit
Fits teams continuously checking application dependencies for known vulnerabilities
It is useful in verify stages and scheduled scans where dependency updates and vulnerability triage need to be part of the delivery workflow.
Sources: [1]
Before adoption
Design NVD API-key usage and CI caching before enforcing scans
The README strongly recommends an NVD API key and warns that updates are extremely slow without one. Reusing one key across many concurrent CI builds can hit rate limits, so cached or shared vulnerability data should be part of the design.
Sources: [1]
Treat external data sources and credentials as operational dependencies
Dependency-Check requires internet access to several external resources. The Sonatype OSS Index/Guide analyzer disables itself without credentials, and the project documents an ongoing migration from legacy OSS Index tokens to Sonatype Guide tokens during 2026.
Sources: [1]
Official sources
- [1]Dependency-Check 13.0.0 README(2026-10-04)
- [2]Dependency-Check 13.0.0 CLI guide(2026-10-04)
- [3]Dependency-Check changelog through 12.2.2(2026-10-04)
- [4]Dependency-Check 13.0.0 release(2026-10-04)
- [5]Dependency-Check Apache-2.0 license(2026-10-04)
Supplemental curator note
Treat vulnerability-data freshness as part of the CI result rather than only looking at findings. NVD updates are extremely slow without an API key, and sharing one key across many concurrent builds can hit rate limits, so design a cached or shared data strategy before making scans a release gate.
Try it in 3 steps
- 1
Download the Dependency-Check 13.0.0 CLI release
Pin the stable 13.0.0 CLI archive. For production use, also consider verifying the matching release signature.
curl -L -o dependency-check-13.0.0-release.zip https://github.com/dependency-check/DependencyCheck/releases/download/v13.0.0/dependency-check-13.0.0-release.zip - 2
Extract the CLI into a dedicated directory
The release archive expands the CLI scripts under
dependency-check/bin.unzip -q dependency-check-13.0.0-release.zip -d dependency-check-13.0.0 - 3
Inspect CLI options before the first scan
A first real scan needs vulnerability-data updates. Prepare an NVD API key, internet access, and a CI caching strategy before using
--scan.bash ./dependency-check-13.0.0/dependency-check/bin/dependency-check.sh --help
Growth
Growth trends · Last 30 days
7,715 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 39
- Open PRs
- 4
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- security-audit
- build-tool
- maven-plugin
- jenkins-plugin
- gradle-plugin
- vulnerability-detection
- security
- ant-task
- software-composition-analysis
- Stars
- 7,715
- Forks
- 1,426
- Watchers
- 175
- Open issues
- 180
- Contributors
- 324
- Owner type
- Organization
- Primary language
- Java
- License
- Apache-2.0
- Repository last updated
- Oct 2, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Syft9,633 Stars
3 shared tag(s) · 3 shared category(s)
generate SBOMs from container images, filesystems, and archives in CycloneDX, SPDX, and other formats
Go - Opengrep3,136 Stars
3 shared tag(s) · 2 shared category(s)
scan 30+ languages for security issues with Semgrep-compatible rules
OCaml - Checkov9,054 Stars
2 shared tag(s) · 2 shared category(s)
statically analyze Terraform, Kubernetes, and other infrastructure as code to catch cloud misconfigurations, policy violations, and dependency risks before deployment
Python - kube-bench8,209 Stars
2 shared tag(s) · 2 shared category(s)
audit Kubernetes node and cluster configuration against CIS Benchmark checks
Go - Aegis Authenticator13,198 Stars
2 shared tag(s) · 1 shared category(s) · Same language
keep two-factor secrets in an encrypted local vault with user-controlled backups
Java - SonarQube Community Build11,044 Stars
2 shared tag(s) · 1 shared category(s) · Same language
Continuously verify bugs, vulnerabilities, maintainability, and coverage with static analysis and Quality Gates in an open-source code-verification server
Java
Report incorrect information
Tell us if any listing information is incorrect or outdated.