OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container images are supported as the input, and the tool is ideal for integration.
☆1,296Sep 21, 2026Updated 2 weeks ago
Alternatives and similar repositories for dep-scan
Users that are interested in dep-scan are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package manager…☆1,085Updated this week
- Vulnerability database and package search for sources such as Linux, OSV, NVD, GitHub and npm. Powered by sqlite, CVE 5.2, purl, and vers…☆153Updated this week
- blint is a Binary Linter that checks the security properties and capabilities of your executables. It can also generate a Software Bill-o…☆457Oct 4, 2026Updated last week
- Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependenci…☆882Sep 1, 2023Updated 3 years ago
- Scans Software Bill of Materials (SBOMs) for security vulnerabilities☆625Feb 10, 2026Updated 8 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- atom is a novel intermediate representation for applications and a standalone tool that is powered by chen.☆98Updated this week
- Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supp…☆4,269Updated this week
- Binary builds for dep-scan - The Dependency Scanner☆10Apr 1, 2024Updated 2 years ago
- A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sp…☆711Updated this week
- A vulnerability scanner for container images and filesystems☆12,995Updated this week
- Open-Source Unified Vulnerability Management, DevSecOps & ASPM☆4,989Updated this week
- Utility that provides an API platform for validating, querying and managing BOM data☆166Sep 24, 2026Updated 2 weeks ago
- CLI tool and library for generating a Software Bill of Materials from container images and filesystems☆9,658Updated this week
- Vulnerability scanner written in Go which uses the data provided by https://osv.dev☆11,155Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more☆38,312Updated this week
- Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.☆2,758Updated this week
- GitHub app for SBOM creation using cdxgen and upload to Dependency-Track☆26Oct 3, 2026Updated last week
- Open source vulnerability DB and triage service.☆2,966Updated this week
- A curated list of SBOM (Software Bill Of Materials) related tools, frameworks, blogs, podcasts, and articles☆600May 27, 2026Updated 4 months ago
- 🔎 Static code analysis engine to find security issues in code.☆3,160Updated this week
- reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via E…☆8,873Updated this week
- SBOM Search - Context aware search in SBOM repositories☆32Updated this week
- Fully open-source SAST scanner supporting a range of languages and frameworks. Integrates with major CI pipelines and IDE such as Azure D…☆149Sep 4, 2020Updated 6 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Mantis is a security framework that automates the workflow of discovery, reconnaissance, and vulnerability scanning.☆1,037Jul 7, 2026Updated 3 months ago
- OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependen…☆7,721Updated this week
- Streamline vulnerability patching with CVSS, EPSS, and CISA's Known Exploited Vulnerabilities. Prioritize actions based on real-time thre…☆710Aug 23, 2026Updated last month
- Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.☆16,943Updated this week
- OXO is a security scanning orchestrator for the modern age.☆583Oct 2, 2026Updated last week
- Open-source and AI-powered cybersecurity tools for offensive security, vulnerability management, and autonomous pentesting. Built by hack…☆6,772Updated this week
- Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.☆1,451Updated this week
- GUAC aggregates software security metadata into a high fidelity graph database.☆1,553Updated this week
- ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.☆2,478Jun 11, 2025Updated last year
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- CIS Benchmark testing of Windows SIEM configuration☆44May 25, 2023Updated 3 years ago
- The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.☆2,078Sep 21, 2026Updated 2 weeks ago
- A standard API specification for exchanging supply chain artifacts and intelligence☆117Updated this week
- A suite of tools to automate software compliance checks.☆2,099Updated this week
- Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.☆2,454Updated this week
- OpenSSF Scorecard - Security health metrics for Open Source☆5,745Updated this week
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆31,854Updated this week