Dependency-Track Working #1240
-
Hello Team, I am new to SBOM and Dependency Track. How different is this from Dependency Check? It also shows the vulnerabilities in the dependencies included in the project |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Correct. Generating build-time SBOMs is a good engineering practice, and requirements of NIST SSDF, OWASP SCVS, and BSIMM Dependency-Track is a Component Analysis platform. Dependency-Check is an SCA tool. |
Beta Was this translation helpful? Give feedback.
Correct. Generating build-time SBOMs is a good engineering practice, and requirements of NIST SSDF, OWASP SCVS, and BSIMM
Dependency-Track is a Component Analysis platform. Dependency-Check is an SCA tool.
See: https://docs.dependencytrack.org/odt-odc-comparison/