OWASP dep-scan
B
B tier on Software Composition Analysis SoftwareScore 7.0 · #16 of 65
- Android app
- Not listed
- Free plan
- Yes
- Runs on
- api, Linux, Mac, self-hosted, Windows

Summary
OWASP dep-scan is ranked #16 of 65 in software composition analysis software on Everything Xiaomi. It runs on API, Linux, macOS, Self-hosted, Windows. There is a free plan.
OWASP dep-scan plans and pricing
All plansOWASP dep-scan Free Free, open-source tool Fully open source · server mode and some extensions require the all package owasp.org · 7 Oct 2026
Compared on software composition analysis software
- Free plan
- Yesowasp.github.io
- Supported ecosystems
- Node.js, Java/JVM, PHP, Python, Go, Ruby, Rust, .NET, Dart, Haskell, Elixir, C/C++, Clojure, Docker/OCI, GitHub Actions, Jenkins, YAML manifestsowasp.github.io
- SBOM generation
- Yesowasp.github.io
- Reachability analysis
- Yesowasp.github.io
- Deployment options
- self_hostedowasp.github.io
Facts
- Purpose
- Audits project dependencies, container images, and operating systems for known vulnerabilities, advisories, and license limitations.owasp.github.io · 7 Oct 2026
- Inputs
- Supports local repositories, Linux container images, Kubernetes manifests, and operating systems.owasp.github.io · 7 Oct 2026
- Prioritization
- Identifies known CVEs with prioritization to help users focus on findings that need attention.github.com · 7 Oct 2026
- Reachability
- Provides reachability analysis across Java, JavaScript/TypeScript, Python, PHP, Rust, Go, and .NET.github.com · 7 Oct 2026
- Reports
- Can generate SBOMs with Vulnerability Disclosure Report information and CSAF 2.0/2.1 VEX documents.github.com · 7 Oct 2026
- Vulnerability data
- Lists OSV, NVD, GitHub, NPM, and Linux vulnerability data among its sources.owasp.github.io · 7 Oct 2026
- Integrations
- Uses CycloneDX cdxgen to create SBOMs and documents integration with ORAS CLI and CI environments.owasp.org · 7 Oct 2026
- Local scanning
- Package vulnerability scanning runs locally, and the project says it does not require a server for that mode.owasp.github.io · 7 Oct 2026
- Server and API
- Can run as a self-hosted server with a /scan endpoint for scanning directories, SBOM files, and GitHub repositories.github.com · 7 Oct 2026
- Server security
- The server refuses non-local binding unless an API key is configured or unauthenticated binding is explicitly enabled.github.com · 7 Oct 2026
- Platforms
- The repository lists standalone binaries for Linux, macOS, and Windows, and also documents container use.github.com · 7 Oct 2026
- Notable limitation
- The standalone macOS binaries are unsigned, so Gatekeeper may block them on first run.github.com · 7 Oct 2026
- Support
- The project says developers can be reached through its Discord channel.owasp.org · 7 Oct 2026
- License and audience
- The repository identifies the project as MIT licensed and describes it for dependency and container-image security and license audits.github.com · 7 Oct 2026
Best OWASP dep-scan alternatives
See all 20Where it ranks on Everything Xiaomi
Is OWASP dep-scan yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- owasp.github.io/www-project-dep-scan/· checked 7 Oct 2026
- github.com/owasp-dep-scan/dep-scan· checked 7 Oct 2026
- owasp.org/projects/dep-scan· checked 7 Oct 2026
- owasp.org/blog/2023/10/05/appthreat-depscan-joins· checked 7 Oct 2026




