Comparison
SBOM Observer vs. Dependency-Track
Both check SBOMs for vulnerabilities and policy violations. Dependency-Track is open source and you run it yourself. SBOM Observer is a managed service in the EU. They also differ in formats, release history and how you write policies.
Bytesafe
SBOM Observer
Managed SBOM platform from Bitfront, hosted in the EU.
- SBOM formats
- CycloneDX and SPDX
- Policies
- Visual builder, Rego or JavaScript
- Runs
- Managed SaaS in the EU, or on-premises on Enterprise
- License
- Commercial
- Cost
- Subscription per user, hosting and upgrades included
OWASP
Dependency-Track
Open source SBOM platform from OWASP. You host it.
- SBOM formats
- CycloneDX
- Policies
- Visual conditions and CEL expressions
- Runs
- Self-hosted: container images and PostgreSQL 14+
- License
- Open source (Apache 2.0)
- Cost
- No license fee. You pay for the servers and the time to run, upgrade and back it up
Based on Dependency-Track's public documentation. Published by Bytesafe.
Which one fits
Most teams can tell from how they want to run it and which formats they receive.
SBOM Observer fits when
- You want a managed service hosted in the EU, with support and an SLA.
- You receive SPDX as well as CycloneDX, for example from suppliers.
- You need to see every application and release a vulnerability reaches, and through which dependency.
- You want policies in Rego or JavaScript that fail the build, including SBOM quality checks.
- You keep SBOM and VEX evidence per release for CRA, NIS2 or DORA.
Dependency-Track fits when
- You want open source, and have people to run it: upgrades, PostgreSQL, backups and the vulnerability data mirrors.
- Your SBOMs are all CycloneDX.
- You use its integrations: notifications to Slack, Teams or Jira, findings sent to DefectDojo.
Feature by feature
From public documentation and the product itself. If something is out of date, tell us.
SBOMs and documents
- CycloneDX import
- SBOM ObserverYes. 1.3 and later, JSON and XML
- Dependency-TrackYes. All versions up to 1.7, JSON and XML
- SPDX import
- SBOM ObserverYes. 2.2 and later: JSON, YAML, RDF/XML and tag-value
- Dependency-TrackNo. CycloneDX is the only upload format
- SBOM export
- SBOM ObserverYes. CycloneDX and SPDX
- Dependency-TrackYes. CycloneDX: BOM, BOM with vulnerabilities, VDR
- Uploaded documents kept per release
- SBOM ObserverYes. Every SBOM, VEX and SLSA document stays with the release it describes
- Dependency-TrackPartly. One inventory per project version. A new upload to the same version replaces it
- SLSA provenance
- SBOM ObserverYes. Imported and shown on the component page
- Dependency-TrackNo. No
- OpenSSF Scorecard
- SBOM ObserverYes. For each component's source repository
- Dependency-TrackNo. No
Vulnerabilities
- Vulnerability data
- SBOM ObserverYes. OSV, GitHub Advisories and NVD
- Dependency-TrackYes. NVD, GitHub Advisories and OSV, plus OSS Index, Snyk, Trivy and VulnDB analyzers
- Continuous monitoring
- SBOM ObserverYes. New advisories matched against every stored release
- Dependency-TrackYes. Scheduled re-analysis of the portfolio
- EPSS
- SBOM ObserverYes. Yes
- Dependency-TrackYes. Yes
- Impact across applications
- SBOM ObserverYes. Graph from the vulnerable package to every application and release, with the dependency path
- Dependency-TrackPartly. List of affected projects. Dependency graph per project
- Container OS packages
- SBOM ObserverYes. Yes
- Dependency-TrackYes. Distribution-aware version matching
- Container layers and base images
- SBOM ObserverYes. Components and findings per layer
- Dependency-TrackNo. No
VEX
- VEX import
- SBOM ObserverYes. CycloneDX VEX and OpenVEX
- Dependency-TrackYes. CycloneDX VEX
- VEX export
- SBOM ObserverYes. CycloneDX VEX
- Dependency-TrackYes. CycloneDX VEX and VDR
- Triage in the UI
- SBOM ObserverYes. State, justification and response per finding
- Dependency-TrackYes. Analysis per finding, and vulnerability policies across projects
Policies
- Visual policy builder
- SBOM ObserverYes. Can be converted to code later
- Dependency-TrackYes. Yes
- Policies as code
- SBOM ObserverYes. Rego (Open Policy Agent) or JavaScript, with the full data model
- Dependency-TrackPartly. CEL expression conditions. Vulnerability policies can sync from YAML bundles
- License policies
- SBOM ObserverYes. Yes
- Dependency-TrackYes. License groups and SPDX expressions
- SBOM quality policies
- SBOM ObserverYes. Template for NTIA minimum elements
- Dependency-TrackNo. No
- Fail the CI/CD build
- SBOM ObserverYes. Observer CLI exits non-zero on a violation
- Dependency-TrackPartly. Through the REST API or community plugins
Running it
- Managed service
- SBOM ObserverYes. Hosted in the EU
- Dependency-TrackNo. The project ships self-hosted software only
- Self-hosted
- SBOM ObserverYes. Enterprise plan, including air-gapped
- Dependency-TrackYes. Container images, PostgreSQL 14 or later, air-gapped guide
- Single sign-on
- SBOM ObserverPartly. SAML, on the Enterprise plan only
- Dependency-TrackYes. OIDC and LDAP, included
- Open source
- SBOM ObserverNo. No
- Dependency-TrackYes. Apache 2.0, OWASP project
- Commercial support and SLA
- SBOM ObserverYes. Yes
- Dependency-TrackNo. Community support
Every document stays with its release
SBOM Observer keeps every SBOM, VEX and SLSA document you upload, attached to the release it describes. Components are deduplicated across all of them: a library used by ten applications is one record with ten links.
Dependency-Track: Dependency-Track keeps one component inventory per project version. A new upload to the same version reconciles the list. To keep a release as a record, you clone the project to a new version.
Component
openssl 3.0.7
pkg:deb/debian/openssl@3.0.7
- Vulnerability
- CVE-2023-0286
- VEX
- Not affected
- License
- Apache-2.0
- Provenance
- SLSA fetched
Payments API
4.2.1
Checkout
2.8.0
Mobile API
1.14.3
Used by three releases. Stored, enriched and reviewed once.
One view of what a vulnerability reaches
Open a vulnerability and SBOM Observer draws a graph from the vulnerable package to every application and release that ships it, with the dependency path in between.
Dependency-Track: Dependency-Track lists the projects a vulnerability affects. The dependency graph is shown per project.
Policies you can write as code
Build a policy in the visual builder, or write it in Rego or JavaScript against the full data model. The Observer CLI evaluates it in CI/CD and exits non-zero on a violation. Templates cover NTIA minimum elements and copyleft licenses.
Dependency-Track: Dependency-Track policies combine conditions such as license, age, severity and EPSS. A CEL expression covers what the built-in conditions cannot. Pipelines read the result through the REST API.
# Generate an SBOM for this buildobserver fs -o sbom.cdx.json .# Evaluate your policies. Exits non-zero on a violationobserver analyze sbom.cdx.json# Upload for monitoring when the build passesobserver upload sbom.cdx.json
Library Vulnerabilities EPSS/VEX
spring-beans 5.3.17: CVE-2022-22965 with CVSS 9.8 and EPSS 0.98 is not tolerated for a library
Dependency-Track 5 means a migration
Version 5 rebuilds the backend and changes how you deploy it. Teams on v4 migrate by hand before v4 reaches end of life in December 2026, which makes it a natural point to compare.
- Version 5.0 shipped in June 2026 and 5.1 in August 2026.
- PostgreSQL 14 or later is the only supported database. H2, MySQL and SQL Server support is gone.
- It ships as container images only. The WAR file and the bundled image are discontinued.
- Moving from v4 is a manual migration, from v4.14.2 or later.
- Version 4 reaches end of life in December 2026.
Moving from Dependency-Track
Both speak CycloneDX, so your SBOMs and VEX decisions move over as files.
- 1
Export from Dependency-Track
Export each project as a CycloneDX SBOM, and its analysis decisions as CycloneDX VEX.
GET /api
/v1 /bom /cyclonedx /project /{uuid} GET /api /v1 /vex /cyclonedx /project /{uuid} - 2
Upload to SBOM Observer
Upload both files. SBOM Observer reads the analysis states from the VEX, so your triage decisions come with the components. New releases then come in from CI/CD with the Observer CLI.
observer upload sbom.cdx.json - 3
Rebuild your policies
Recreate component policies in the visual builder or in Rego. Start from the templates for NTIA minimum elements and copyleft licenses.
Trust Repository may be all you need
If the job is to collect SBOMs and VEX from your suppliers, share your own with customers and run basic vulnerability and policy checks on them, Trust Repository covers it. It is a hosted service, so there is no server to run.
Add SBOM Observer when you need impact analysis across releases, your own policies in CI/CD and VEX review.
See Trust RepositorySuppliers
SBOM and VEX
Trust Repository
Collect, check, share
Customers
Download
Frequently asked questions
Does Dependency-Track support SPDX?
Can we move our data from Dependency-Track to SBOM Observer?
Does SBOM Observer come with support?
Can SBOM Observer run on our own servers, like Dependency-Track?
What does SBOM Observer cost?
Bring a Dependency-Track export
Click through the live demo, or book a call with an engineer and bring an SBOM or a Dependency-Track export.
