Dependency-Check
OWASP scanner that finds known vulnerabilities in a project's dependencies.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About Dependency-Check
OWASP scanner that finds known vulnerabilities in a project's dependencies. It matches dependencies to CPE identifiers and reports the linked CVEs, and it plugs into Maven, Gradle, Jenkins and command-line builds.
CPE matching produces false positives and misses, and it needs an NVD API key and a long initial data download.
Strengths
- It matches dependencies to CPE identifiers and reports the linked CVEs, and it plugs into Maven, Gradle, Jenkins and command-line builds.
Limitations
- CPE matching produces false positives and misses, and it needs an NVD API key and a long initial data download.
Details
- Pricing
- Free · The software is free under its open-source licence. Hosting, hardware and external services are separate.
- License
- Apache-2.0
- Developer
- OWASP
- Platforms
- Windows, macOS, Linux, Command line
- How it runs
- Downloadable app
- Best suited for
- OWASP scanner that finds known vulnerabilities in a project's dependencies
- Categories
- Security tools
- Last verified
- Added
- Provenance
- Selected from the TechWalrus downloads catalog (Security); facts checked against the developer's own pages, 2 sources on file.