#DependencyTrack
Damien Lucas nous parle sécurité avec #sbom, et notamment #DependencyTrack au #DevoxxFR
April 16, 2025 at 11:57 AM
On the #norsys blog, I've just posted an article which explains how building a local development environment for @dependencytrack.bsky.social with Docker Compose, code and examples included.

medium.com/norsys-octog...

#DependencyTrack #Trivy #Docker #DockerCompose #Security #DependencyManagement
A local environment for DependencyTrack with Docker Compose
A local DependencyTrack environment with Docker Compose for development and experimentation.
medium.com
January 29, 2026 at 3:26 PM
Join us next Monday at 9am EST for Quarkus Insights Ep. 188 as Alexey Loubyansky, Niklas Duester, & Steve Springett join us to discuss generating Quarkus application SBOMs for vulnerability management with OWASP DependencyTrack.

http://bit.ly/quarkusinsights

#java #quarkus #quarkusinsights
November 29, 2024 at 2:00 PM
dependency-track v4.14.4 — Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through... https://kitploit.com/tools/github/dependencytrack/dependency-track?utm_source=bluesky&utm_medium=social&utm_campaign=kitploit&utm_content=362112
September 18, 2026 at 8:47 PM
EMBA is now fully connected with the awesome #SBOM management environment @dependencytrack by #OWASP.
Check the great news around your next level #IoT security testing experience here github.com/e-m-b-a/emba...
November 21, 2025 at 2:17 PM
⏰ Starting soon! Join us for Quarkus Insights Ep. #188 as Alexey Loubyansky, Niklas Duester, & Steve Springett join us to discuss generating Quarkus application SBOMs for vulnerability management with OWASP DependencyTrack.

http://bit.ly/quarkusinsights

#java #quarkus @YouTube #quarkusinsights
December 2, 2024 at 1:45 PM
Running DependencyTrack requires a full-blown multi-container docker setup:
https://docs.dependencytrack.org/getting-started/deploy-docker/

Are they serious?

To run something that basically parses a well-defined JSON- or XML-File and then compares a list of strings with lists of strings from […]
Original post on rollenspiel.social
rollenspiel.social
March 1, 2025 at 1:37 PM
Not only jfrog though: Syft will put Go in the generated SBOM, and DependencyTrack will then attribute all Go vulns to the binary (saw it firsthand for Canonical's Pebble, now embedded in Ubuntu 26.04 Docker images).
I suppose Trivy will also flag it similarly.
July 24, 2026 at 8:48 PM
OWASP has released a new version of its dependency tracking tool, but the update is not the final word on managing software risk. #OWASP #DependencyTrack #ApplicationSecurity #SBOM
jpmellojr.blogspot.com/2024/10/owas...
OWASP's Dependency-Track tool update: Key changes — and limitations
OWASP has released a new version of its dependency-tracking tool, but the update is not the final word on managing software risk. more
jpmellojr.blogspot.com
October 23, 2024 at 8:27 PM
You can now share your thoughts on vulnerability CVE-2025-64758 in Vulnerability-Lookup:
https://vulnerability.circl.lu/vuln/CVE-2025-64758

DependencyTrack - frontend

#vulnerabilitylookup #vulnerability #cybersecurity #bot
cvelistv5 - CVE-2025-64758
Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.
vulnerability.circl.lu
November 17, 2025 at 5:41 PM
You can now share your thoughts on vulnerability CVE-2025-61776 in Vulnerability-Lookup:
https://vulnerability.circl.lu/vuln/CVE-2025-61776

DependencyTrack - dependency-track

#vulnerabilitylookup #vulnerability #cybersecurity #bot
cvelistv5 - CVE-2025-61776
Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.
vulnerability.circl.lu
October 7, 2025 at 7:24 PM
May 4, 2026 at 8:50 PM
Sur le blog de #norsys, je viens de publier un billet qui explique comment monter un environnement local pour @dependencytrack.bsky.social avec Docker Compose accompagné de code et d'exemples directement utilisables.

medium.com/norsys-octog...

#DependencyTrack #Trivy #Docker #Security
A local environment for DependencyTrack with Docker Compose
A local DependencyTrack environment with Docker Compose for development and experimentation.
medium.com
January 29, 2026 at 3:25 PM
@securestep9.bsky.social great catching up with you last night.
Remember my gripe about Dependency Track using flaky H2 db & if it's not for prod why force it out-of-box in first place?

Doh!
"Update quickstart Compose file to use Postgres instead of H2 - apiserver/#4576"
github.com/DependencyTr...
Update quickstart Compose file to use Postgres instead of H2 by nscuro · Pull Request #4576 · DependencyTrack/dependency-track
Description Updates quickstart Compose file to use Postgres instead of H2. Since we don't recommend using H2, and H2 keeps causing issues, we shouldn't have it as a default for new users. ...
github.com
April 30, 2025 at 1:39 PM
When a zero-day drops, you need to know your exposure in minutes, not days.

Our Managed #DependencyTrack gives you:
- Continuous SBOM monitoring across your fleet
- Multi-source intel that bypasses NVD delays
- Data sovereignty (your cloud and boundaries)
- Open source transparency
Managed Dependency-Track: Supply Chain Security in 2026
Learn how our Managed Dependency-Track delivers continuous software supply chain security, automated SBOM monitoring, and multi-source CVE intelligence.
buff.ly
May 21, 2026 at 11:14 PM
It’s almost go time!

Our #DependencyTrack webinar starts today at 3 PM CDT.

Stop guessing which vulnerabilities matter and start automating your SBOM security. Last chance to grab a seat and join the conversation!

🔗
Uncover Hidden Vulnerabilities with Dependency-Track
Stop chasing ghost vulnerabilities. Join us on April 8 to master Dependency-Track, automate SBOMs, and use EPSS to fix what actually matters. Register now!
buff.ly
April 8, 2026 at 6:19 PM
Static security scans are yesterday’s news.

On April 8th, at 3 PM CDT, learn how to use #DependencyTrack and #EPSS to find the 10% of website vulns that actually pose a threat to your production.

We’re down to the final few seats. Get yours now!
🔗 buff.ly/RNata9E
Uncover Hidden Vulnerabilities with Dependency-Track
Stop chasing ghost vulnerabilities. Join us on April 8 to master Dependency-Track, automate SBOMs, and use EPSS to fix what actually matters. Register now!
buff.ly
April 7, 2026 at 11:33 PM
Still relying on luck for your supply chain security? 🎲

We’re down to the final few seats for our #DependencyTrack webinar on April 8!

Learn how to kill the noise + fix what matters. Grab your seat before they're gone:

💺 buff.ly/XroQRSD

Can't make it? Register anyway & you'll get the recording!
Uncover Hidden Vulnerabilities with Dependency-Track
Stop chasing ghost vulnerabilities. Join us on April 8 to master Dependency-Track, automate SBOMs, and use EPSS to fix what actually matters. Register now!
buff.ly
April 1, 2026 at 11:24 PM
Static scans leave gaps that zero-days love to fill. 🕳️

Join our webinar on April 8 to see how #DependencyTrack uses real-time #SBOM analysis to find hidden risks.

buff.ly/XroQRSD

We’re also at #DrupalConChicago Booth 200 all week, come chat security with us!
Uncover Hidden Vulnerabilities with Dependency-Track
Stop chasing ghost vulnerabilities. Join us on April 8 to master Dependency-Track, automate SBOMs, and use EPSS to fix what actually matters. Register now!
www.amazee.io
March 25, 2026 at 11:36 PM
Have a lookbat CycloneDX for generating SBOMs and DependencyTrack for policy management.
February 7, 2025 at 6:36 PM
CycloneDX to generate SBoms and DependencyTrack for analyzing
November 28, 2024 at 10:02 AM
CVE-2025-64758 - @dependencytrack/frontend Vulnerable to Persistent Cross-Site-Scripting via Welcome Message
CVE ID : CVE-2025-64758

Published : Nov. 17, 2025, 6:15 p.m. | 2 hours, 48 minutes ago

Description : @dependencytrack/frontend is a Single Page Application (SPA) ...
CVE-2025-64758 - @dependencytrack/frontend Vulnerable to Persistent Cross-Site-Scripting via Welcome Message
@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Since version 4.12.0, Dependency-Track users with the SYSTEM_CONFIGURATION permission can configure a "welcome message", which is HTML that is to be …
cvefeed.io
November 17, 2025 at 9:36 PM

There are common formats like #OWASP CycloneDX and SPDX that allow defining SBOM. Tools like DependencyTrack from #OWASP may help you aggregating the information and defining policies.
October 22, 2024 at 7:42 AM
An example on how to use @pipedream to send custom messages to Google Chat from @DependencyTrack platform: https://sidoine.org/custom-message-dependency-track-google-chat-pipedream/
Custom message from Dependency Track to Google Chat with Pipedream!
How Pipedream can help to connect multiple application together to deliver value.
sidoine.org
November 28, 2024 at 9:35 PM