Skip to content

Dependency-Track Working #1240

Answered by stevespringett
bhuvi11 asked this question in Q&A
Discussion options

You must be logged in to vote

The only way i can see vulnerabilities is through importing SBOM?

Correct. Generating build-time SBOMs is a good engineering practice, and requirements of NIST SSDF, OWASP SCVS, and BSIMM

Dependency-Track is a Component Analysis platform. Dependency-Check is an SCA tool.

See: https://docs.dependencytrack.org/odt-odc-comparison/

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by bhuvi11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants