IT AI Index
Index Vendors › OWASP Dependency-Track · September 2026 Edition
1 category · Ranked

OWASP Dependency-Track

30Judge labels
9First choices
0Negative labels
12 of 12Models named it
1Category
September 2026 Edition. Every number here is derived from the raw labels under vendor table vv2026-09.2, every buyer segment counted.
Best standing
14% in SCA for enterprise buyers
Rank 6 of 49 in the mid-market standingaccepted challenger
0 of 12 models made it the first choice on the direct prompt; 0% of its 11 labels there were negative.
By buyer segmentStrongest at enterprise.
In sca · each standing computed within its segment · bars are 0 to 100 · the accent bar is the product's own best reading

Standing by category

Every category where a model named OWASP Dependency-Track for a mid-market B2B company. Share is first choices across the direct, paraphrase, budget and scale prompts; rank is within every product named in that category.
CategoryFunctionShareRankNegative rateLabelsQuadrant
Software composition analysisDeveloper platform2%6 of 490%11accepted challenger

Movement

This is the first edition on this tier, so no move can be computed for OWASP Dependency-Track yet. From the next edition this section shows, per buyer segment, whether its share moved by more than the measured noise floor.

By model

How each model treated OWASP Dependency-Track across every prompt where it was named for a mid-market B2B company. Twelve models, six prompts per category.
ModelFirst choiceAlternativeMentionNegativeLabels
Claude Haiku 4.501001
GPT-5.4 mini01001
Gemini 3.5 Flash00101
Perplexity Sonar00000
Grok 4.1 Fast01001
Mistral Small10001
DeepSeek V4 Flash02002
Llama 4 Maverick00101
Qwen 3.7 Flash00000
Kimi K200101
GLM 4.7 FlashX00101
MiniMax M2.501001

By framing

Which of the six questions produced the naming. By model says how often; this says asked what. The first-choice count on the right carries the marks of the models that produced it.
FramingLabels by classFirst choices
Direct3 labelsNone
Paraphrase14 labels7
Comparative4 labelsNone
Budget-constrained6 labels2
Scale-constrained2 labelsNone
Negative1 labelNone
First choiceAlternativeMentionNegative30 labels in all, every segment counted; 9 of the 9 first choices count toward share, since the comparative and negative framings do not. The bar is one segment per label class, to scale within the framing.

What the models said for it

Verbatim evidence the judge attached to positive labels.

“start with Trivy or OWASP Dependency-Track for full-featured, free SCA” Mistral Small · SCA · budget prompt · first choice
“optionally paired with OWASP Dependency-Track for centralized tracking” DeepSeek V4 Flash · SCA · paraphrase prompt · alternative
“better if you want a centralized vulnerability management platform” GPT-5.4 mini · SCA · paraphrase prompt · alternative
“For portfolio monitoring, pair with OWASP Dependency-Track (free OSS).” Grok 4.1 Fast · SCA · paraphrase prompt · alternative

And against it

Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.

No model argued against it.

Named alongside

The products named in the same answers as OWASP Dependency-Track, over the 30 answers that named it. Took the first choice instead counts the answers where the other product was the first choice and OWASP Dependency-Track was named but was not.
ProductSame answerTook the first choice insteadHead to head
OWASP Dependency-Check20 of 303Not in the top three
Trivy19 of 307Not in the top three
Snyk Open Source17 of 306Not in the top three
Black Duck12 of 300Not in the top three
Mend.io10 of 301Not in the top three
Grype9 of 300Not in the top three
Sonatype Lifecycle7 of 301Not in the top three
FOSSA7 of 300Not in the top three
JFrog Xray6 of 301Not in the top three
Checkmarx SCA6 of 300Not in the top three
A head-to-head page exists where both products are in a category's top three. The other rows are the same fact without a page behind them, so they link to the product instead.

What carried it into the answer

The sites and pages cited by the answers that named OWASP Dependency-Track. A fact about retrieval, not a lever on the model.

Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 25 of the 30 answers that named OWASP Dependency-Track and are not a share of its labels.

Domains cited

appsecsanta.com13
endorlabs.com12
aikido.dev10
guideflow.com10
ox.security9
safeguard.sh9
raven.io8
dupple.com7
github.com7
toolradar.com7

Ninety-two of the ninety-two domain citations in answers naming OWASP Dependency-Track came from somebody else's page.

Pages cited

Pages are listed as the models cited them.

Names read as OWASP Dependency-Track

What the judge wrote, as written, with how often. The vendor table decides that these count as OWASP Dependency-Track; a claim can dispute any of them.
Dependency-Track 3Dependency‑Track 1
Is this your product?

Claim this page

Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when OWASP Dependency-Track's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as OWASP Dependency-Track, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.

It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at owasp.org is approved on the spot, any other address is reviewed by hand.

Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.

Subscribe to the pack