Dependency-Check

OWASP scanner that finds known vulnerabilities in a project's dependencies.

These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.

About Dependency-Check

OWASP scanner that finds known vulnerabilities in a project's dependencies. It matches dependencies to CPE identifiers and reports the linked CVEs, and it plugs into Maven, Gradle, Jenkins and command-line builds.

CPE matching produces false positives and misses, and it needs an NVD API key and a long initial data download.

Strengths

  • It matches dependencies to CPE identifiers and reports the linked CVEs, and it plugs into Maven, Gradle, Jenkins and command-line builds.

Limitations

  • CPE matching produces false positives and misses, and it needs an NVD API key and a long initial data download.

Details

Pricing
Free · The software is free under its open-source licence. Hosting, hardware and external services are separate.
License
Apache-2.0
Developer
OWASP
Platforms
Windows, macOS, Linux, Command line
How it runs
Downloadable app
Best suited for
OWASP scanner that finds known vulnerabilities in a project's dependencies
Categories
Security tools
Last verified
Added
Provenance
Selected from the TechWalrus downloads catalog (Security); facts checked against the developer's own pages, 2 sources on file.

Report a wrong fact or a dead link on this listing