Konvu is a RSAC Launch Pad finalist 🎉Meet the founders in SF →

    Back to integrations
    SCA

    OWASP Dependency-Track integration

    Prioritize Dependency-Track's SBOM risk findings based on exploitability.

    Integration details

    Primary category

    Software Composition Analysis

    Sync direction

    OWASP Dependency-Track ↔ Konvu

    Findings are ingested from OWASP Dependency-Track into Konvu. Based on your workflow, Konvu can then push context, status changes, and severity updates back to OWASP Dependency-Track.

    Status

    Available

    What is OWASP Dependency-Track?

    OWASP Dependency-Track is an open-source component analysis platform that continuously monitors SBOM files for vulnerable dependencies and licenses across portfolios.

    Why connect OWASP Dependency-Track to Konvu

    • Apply exploit context to Dependency-Track's portfolio-wide risk metrics for accurate exposure assessment.
    • Triage which components in your SBOM catalog pose actual risk versus inherited transitive dependencies.
    • Document remediation decisions in Konvu and sync status back to Dependency-Track projects.

    How it works

    1

    Scan

    OWASP Dependency-Track produces findings from scans or assessments.

    2

    Ingest & enrich

    Konvu ingests those findings and enriches them with code, configuration, and deployment context.

    3

    Assess exploitability

    Konvu determines exploitability and recommended action with evidence attached.

    4

    Sync decisions

    Based on your workflow, Konvu can push context, status updates, and severity adjustments back into OWASP Dependency-Track.

    Quick setup

    Configure OWASP Dependency-Track from the integrations list in Konvu.

    1. 1Go to /configuration/integrations in Konvu and choose OWASP Dependency-Track.
    2. 2Authorize access and confirm the data sources you want to sync.
    3. 3Save the configuration to start syncing.

    Sync direction

    OWASP Dependency-Track ↔ Konvu

    Findings are ingested from OWASP Dependency-Track into Konvu. Based on your workflow, Konvu can then push context, status changes, and severity updates back to OWASP Dependency-Track.