--- title: Dependency-Track Reviews meta_title: 'Dependency-Track Reviews 2026: Details, Pricing, & Features | G2' meta_description: Filter reviews by the users' company size, role or industry to find out how Dependency-Track works for a business like yours. aggregate_rating: rating_value: 4.3 review_count: 4 scale: '5' date_modified: '2026-09-22' parent_category: name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t" url: https://www.g2.com/categories/devsecops ---

Dependency-Track Reviews & Product Details

Profile Status

This profile is currently managed by Dependency-Track but has limited features.

Are you part of the Dependency-Track team? Upgrade your plan to enhance your branding and engage with visitors to your profile!

Pricing

Pricing provided by Dependency-Track.

Open Source

0
Atanu M.
AM
Atanu M.
Security Consultant
Enterprise (> 1000 emp.)
"An open source SCA with a Neat GUI but fails short of homerun"
3/5
What do you like best about Dependency-Track?

Its neat UI assisted by side nav bars and illustrative dashboards and tables as required is the best feature followed by ease of integration. Review collected by and hosted on G2.com.

What do you dislike about Dependency-Track?

The main shortcoming is that there is no way to export the data off of this tool. We end up resorting to the crude methods of copy pasting the data in excel for collaborating with development teams. Review collected by and hosted on G2.com.

Verified User in Medical Devices
UM
Verified User in Medical Devices
Enterprise (> 1000 emp.)
"Full focus on vulnerabilities"
5/5
What do you like best about Dependency-Track?

API-first design

Assessment database as part of data structure and process Review collected by and hosted on G2.com.

What do you dislike about Dependency-Track?

Project views are limited

No built-in export Review collected by and hosted on G2.com.

Suryansh G.
SG
Suryansh G.
Principal Engineer, Cloud HSM
Mid-Market (51-1000 emp.)
"Dependency track"
4/5
What do you like best about Dependency-Track?

No restriction on the number of repositories one can scan. Review collected by and hosted on G2.com.

What do you dislike about Dependency-Track?

Access to zero day vulnerabilities is not there and only works with an old DB leaving an attack surface open Review collected by and hosted on G2.com.

Vis C.
VC
Vis C.
Software Security Technical Director
Enterprise (> 1000 emp.)
"Best open-source SCA tool in the market"
5/5
What do you like best about Dependency-Track?

Has multiple vulnerability sources (NVD, OSS Index, etc.) and thus higher positive percentage. Review collected by and hosted on G2.com.

What do you dislike about Dependency-Track?

Slow in performance, especially the GUI operations Review collected by and hosted on G2.com.

There are not enough reviews of Dependency-Track for G2 to provide buying insight. Below are some alternatives with more reviews:

1
GitLab Logo
GitLab
4.5
(901)
An open source web interface and source control platform based on Git.
2
GitHub Logo
GitHub
4.7
(2,407)
GitHub is the best place to share code with friends, co-workers, classmates, and complete strangers. Over two million people use GitHub to build amazing things together.
3
Wiz Logo
Wiz
4.7
(845)
Wiz is a CNAPP that consolidates CSPM, KSPM, CWPP, vulnerability management, IaC scanning, CIEM, DSPM, and container and Kubernetes security into a single platform.
4
Microsoft Defender for Cloud Logo
Microsoft Defender for Cloud
4.4
(456)
Azure Security Center provides security management and threat protection across your hybrid cloud workloads. It allows you to prevent, detect, and respond to security threats with increased visibility.
5
Aikido Security Logo
Aikido Security
4.6
(266)
Aikido Security is a developer-first software security platform. We scan your source code & cloud to show you which vulnerabilities are actually important to solve. Triaging is sped up by massively reducing false-positives and making CVEs human-readable. Aikido makes it simple to keep your product secure and gives you back time to do what youdo best: writing code.
6
Mend.io Logo
Mend.io
4.3
(123)
Mend.io delivers the first AI native application security platform built for software created by both humans and machines. It empowers organizations to secure AI generated code and embedded AI components like models, agents, MCPs, and RAG pipelines. The unified platform brings together comprehensive capabilities including AI security, SAST, SCA, container scanning, and Mend Renovate providing development and security teams complete visibility into risks across their codebase. With AI powered remediation and prioritization workflows, teams are enabled to quickly resolve issues and reduce risk. With a simple, predictable price model, eliminating per-module costs and minimal reliance on expensive professional services Mend.io is a scalable, proactive, developer-friendly platform for modern AppSec—all in a single platform.
7
Snyk Logo
Snyk
4.5
(136)
Snyk is a security solution designed to find and fix vulnerabilities in Node.js and Ruby apps.
8
JFrog Logo
JFrog
4.3
(174)
The JFrog Platform is an end-to-end, hybrid, and universal binary-centric solution that continuously manages and secures your entire software supply chain from source to edge. We empower developers to be more efficient using JFrog’s services, Artifactory, Xray, Distribution, Pipelines, and Connect on a single unified platform. The JFrog Platform is an enterprise-grade solution that handles the scale of the largest development organizations in the world. The JFrog family of products includes: JFrog Artifactory: -Provides definitive artifact management for flexible development and trusted delivery at any scale. The industry leader. JFrog Xray: -The industry’s only DevOps-Centric Security solution offers protection across your supply chain and is integrated seamlessly with Artifactory and the other JFrog products for a single point of management and security. JFrog Pipelines: -Integrates with the leading CI/CD tools to manage all software pipelines in a single place with additional event triggers and easy-to-use templates. JFrog Distribution and JFrog PDN: -Creates trusted software releases and gets them where they need to be, fast. Handles the highest scale of throughput and consumption. JFrog Connect: -A comprehensive solution for updating, managing and monitoring software applications on Linux-based edge and IoT devices. JFrog Mission Control & Insights: -Enhances control over your JFrog Platform deployment with access to key metrics.
9
SonarQube Logo
SonarQube
4.4
(155)
SonarQube is a code quality and vulnerability solution for development teams that integrates with CI/CD pipelines to ensure the software you produce is secure, reliable, and maintainable.
10
Black Duck Polaris Platform Logo
Black Duck Polaris Platform
4.2
(104)
Black Duck by Synopsys provides a comprehensive software composition analysis (SCA) solution for managing security, quality, and license compliance risk that comes from the use of open source and third-party code in applications and containers. Black Duck gives you unmatched visibility into third-party code, enabling you to control it across your software supply chain and throughout the application life cycle.
Show More

Questions about Dependency-Track? Ask real users or explore answers from the community

Get practical answers, real workflows, and honest pros and cons from the G2 community or share your insights.

GU
Guest User
•
Last activity about 2 years ago

What is Dependency-Track used for?

0 Upvotes
1
Join the conversation

Pricing Options

Pricing provided by Dependency-Track.

Open Source

0