OWASP Dependency-Track integration
Prioritize Dependency-Track's SBOM risk findings based on exploitability.
Integration details
Primary category
Software Composition Analysis
Sync direction
OWASP Dependency-Track ↔ Konvu
Findings are ingested from OWASP Dependency-Track into Konvu. Based on your workflow, Konvu can then push context, status changes, and severity updates back to OWASP Dependency-Track.
Status
Available
What is OWASP Dependency-Track?
OWASP Dependency-Track is an open-source component analysis platform that continuously monitors SBOM files for vulnerable dependencies and licenses across portfolios.
Why connect OWASP Dependency-Track to Konvu
- Apply exploit context to Dependency-Track's portfolio-wide risk metrics for accurate exposure assessment.
- Triage which components in your SBOM catalog pose actual risk versus inherited transitive dependencies.
- Document remediation decisions in Konvu and sync status back to Dependency-Track projects.
How it works
Scan
OWASP Dependency-Track produces findings from scans or assessments.
Ingest & enrich
Konvu ingests those findings and enriches them with code, configuration, and deployment context.
Assess exploitability
Konvu determines exploitability and recommended action with evidence attached.
Sync decisions
Based on your workflow, Konvu can push context, status updates, and severity adjustments back into OWASP Dependency-Track.
Quick setup
Configure OWASP Dependency-Track from the integrations list in Konvu.
- 1Go to /configuration/integrations in Konvu and choose OWASP Dependency-Track.
- 2Authorize access and confirm the data sources you want to sync.
- 3Save the configuration to start syncing.
Sync direction
OWASP Dependency-Track ↔ Konvu
Findings are ingested from OWASP Dependency-Track into Konvu. Based on your workflow, Konvu can then push context, status changes, and severity updates back to OWASP Dependency-Track.
More integrations
View all
Black Duck
Add exploit evidence to Black Duck's component risk and license compliance findings.
Checkmarx
Focus Checkmarx SAST and SCA alerts on code paths with demonstrated exploit potential.
Dependabot
Prioritize Dependabot PRs based on whether flagged vulnerabilities are exploitable.

Endor Labs
Focus Endor Labs dependency findings on vulnerabilities that are reachable and exploitable.
GitHub
Prioritize GitHub CodeQL and Dependabot alerts by adding exploit context to each finding.
GitLab
Add exploitability analysis to GitLab's built-in SAST and SCA pipeline findings.