Dependency Firewall offer: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new

Comparison

SBOM Observer vs. Dependency-Track

Both check SBOMs for vulnerabilities and policy violations. Dependency-Track is open source and you run it yourself. SBOM Observer is a managed service in the EU. They also differ in formats, release history and how you write policies.

Bytesafe

SBOM Observer

Managed SBOM platform from Bitfront, hosted in the EU.

SBOM formats
CycloneDX and SPDX
Policies
Visual builder, Rego or JavaScript
Runs
Managed SaaS in the EU, or on-premises on Enterprise
License
Commercial
Cost
Subscription per user, hosting and upgrades included

OWASP

Dependency-Track

Open source SBOM platform from OWASP. You host it.

SBOM formats
CycloneDX
Policies
Visual conditions and CEL expressions
Runs
Self-hosted: container images and PostgreSQL 14+
License
Open source (Apache 2.0)
Cost
No license fee. You pay for the servers and the time to run, upgrade and back it up

Based on Dependency-Track's public documentation. Published by Bytesafe.

Which one fits

Most teams can tell from how they want to run it and which formats they receive.

SBOM Observer fits when

  • You want a managed service hosted in the EU, with support and an SLA.
  • You receive SPDX as well as CycloneDX, for example from suppliers.
  • You need to see every application and release a vulnerability reaches, and through which dependency.
  • You want policies in Rego or JavaScript that fail the build, including SBOM quality checks.
  • You keep SBOM and VEX evidence per release for CRA, NIS2 or DORA.

Dependency-Track fits when

  • You want open source, and have people to run it: upgrades, PostgreSQL, backups and the vulnerability data mirrors.
  • Your SBOMs are all CycloneDX.
  • You use its integrations: notifications to Slack, Teams or Jira, findings sent to DefectDojo.

Feature by feature

From public documentation and the product itself. If something is out of date, tell us.

SBOMs and documents

CycloneDX import
SBOM Observer
Yes. 1.3 and later, JSON and XML
Dependency-Track
Yes. All versions up to 1.7, JSON and XML
SPDX import
SBOM Observer
Yes. 2.2 and later: JSON, YAML, RDF/XML and tag-value
Dependency-Track
No. CycloneDX is the only upload format
SBOM export
SBOM Observer
Yes. CycloneDX and SPDX
Dependency-Track
Yes. CycloneDX: BOM, BOM with vulnerabilities, VDR
Uploaded documents kept per release
SBOM Observer
Yes. Every SBOM, VEX and SLSA document stays with the release it describes
Dependency-Track
Partly. One inventory per project version. A new upload to the same version replaces it
SLSA provenance
SBOM Observer
Yes. Imported and shown on the component page
Dependency-Track
No. No
OpenSSF Scorecard
SBOM Observer
Yes. For each component's source repository
Dependency-Track
No. No

Vulnerabilities

Vulnerability data
SBOM Observer
Yes. OSV, GitHub Advisories and NVD
Dependency-Track
Yes. NVD, GitHub Advisories and OSV, plus OSS Index, Snyk, Trivy and VulnDB analyzers
Continuous monitoring
SBOM Observer
Yes. New advisories matched against every stored release
Dependency-Track
Yes. Scheduled re-analysis of the portfolio
EPSS
SBOM Observer
Yes. Yes
Dependency-Track
Yes. Yes
Impact across applications
SBOM Observer
Yes. Graph from the vulnerable package to every application and release, with the dependency path
Dependency-Track
Partly. List of affected projects. Dependency graph per project
Container OS packages
SBOM Observer
Yes. Yes
Dependency-Track
Yes. Distribution-aware version matching
Container layers and base images
SBOM Observer
Yes. Components and findings per layer
Dependency-Track
No. No

VEX

VEX import
SBOM Observer
Yes. CycloneDX VEX and OpenVEX
Dependency-Track
Yes. CycloneDX VEX
VEX export
SBOM Observer
Yes. CycloneDX VEX
Dependency-Track
Yes. CycloneDX VEX and VDR
Triage in the UI
SBOM Observer
Yes. State, justification and response per finding
Dependency-Track
Yes. Analysis per finding, and vulnerability policies across projects

Policies

Visual policy builder
SBOM Observer
Yes. Can be converted to code later
Dependency-Track
Yes. Yes
Policies as code
SBOM Observer
Yes. Rego (Open Policy Agent) or JavaScript, with the full data model
Dependency-Track
Partly. CEL expression conditions. Vulnerability policies can sync from YAML bundles
License policies
SBOM Observer
Yes. Yes
Dependency-Track
Yes. License groups and SPDX expressions
SBOM quality policies
SBOM Observer
Yes. Template for NTIA minimum elements
Dependency-Track
No. No
Fail the CI/CD build
SBOM Observer
Yes. Observer CLI exits non-zero on a violation
Dependency-Track
Partly. Through the REST API or community plugins

Running it

Managed service
SBOM Observer
Yes. Hosted in the EU
Dependency-Track
No. The project ships self-hosted software only
Self-hosted
SBOM Observer
Yes. Enterprise plan, including air-gapped
Dependency-Track
Yes. Container images, PostgreSQL 14 or later, air-gapped guide
Single sign-on
SBOM Observer
Partly. SAML, on the Enterprise plan only
Dependency-Track
Yes. OIDC and LDAP, included
Open source
SBOM Observer
No. No
Dependency-Track
Yes. Apache 2.0, OWASP project
Commercial support and SLA
SBOM Observer
Yes. Yes
Dependency-Track
No. Community support

Every document stays with its release

SBOM Observer keeps every SBOM, VEX and SLSA document you upload, attached to the release it describes. Components are deduplicated across all of them: a library used by ten applications is one record with ten links.

Dependency-Track: Dependency-Track keeps one component inventory per project version. A new upload to the same version reconciles the list. To keep a release as a record, you clone the project to a new version.

One view of what a vulnerability reaches

Open a vulnerability and SBOM Observer draws a graph from the vulnerable package to every application and release that ships it, with the dependency path in between.

Dependency-Track: Dependency-Track lists the projects a vulnerability affects. The dependency graph is shown per project.

Impact graph for CVE-2023-4863 in libwebp, traced through the dependencies that pull it in

Policies you can write as code

Build a policy in the visual builder, or write it in Rego or JavaScript against the full data model. The Observer CLI evaluates it in CI/CD and exits non-zero on a violation. Templates cover NTIA minimum elements and copyleft licenses.

Dependency-Track: Dependency-Track policies combine conditions such as license, age, severity and EPSS. A CEL expression covers what the built-in conditions cannot. Pipelines read the result through the REST API.

build job in CI
# Generate an SBOM for this build
observer fs -o sbom.cdx.json .
 
# Evaluate your policies. Exits non-zero on a violation
observer analyze sbom.cdx.json
 
# Upload for monitoring when the build passes
observer upload sbom.cdx.json
Failed

Library Vulnerabilities EPSS/VEX

spring-beans 5.3.17: CVE-2022-22965 with CVSS 9.8 and EPSS 0.98 is not tolerated for a library

Dependency-Track 5 means a migration

Version 5 rebuilds the backend and changes how you deploy it. Teams on v4 migrate by hand before v4 reaches end of life in December 2026, which makes it a natural point to compare.

  • Version 5.0 shipped in June 2026 and 5.1 in August 2026.
  • PostgreSQL 14 or later is the only supported database. H2, MySQL and SQL Server support is gone.
  • It ships as container images only. The WAR file and the bundled image are discontinued.
  • Moving from v4 is a manual migration, from v4.14.2 or later.
  • Version 4 reaches end of life in December 2026.

Moving from Dependency-Track

Both speak CycloneDX, so your SBOMs and VEX decisions move over as files.

  1. 1

    Export from Dependency-Track

    Export each project as a CycloneDX SBOM, and its analysis decisions as CycloneDX VEX.

    GET /api/v1/bom/cyclonedx/project/{uuid}GET /api/v1/vex/cyclonedx/project/{uuid}
  2. 2

    Upload to SBOM Observer

    Upload both files. SBOM Observer reads the analysis states from the VEX, so your triage decisions come with the components. New releases then come in from CI/CD with the Observer CLI.

    observer upload sbom.cdx.json
  3. 3

    Rebuild your policies

    Recreate component policies in the visual builder or in Rego. Start from the templates for NTIA minimum elements and copyleft licenses.

Trust Repository may be all you need

If the job is to collect SBOMs and VEX from your suppliers, share your own with customers and run basic vulnerability and policy checks on them, Trust Repository covers it. It is a hosted service, so there is no server to run.

Add SBOM Observer when you need impact analysis across releases, your own policies in CI/CD and VEX review.

See Trust Repository

Frequently asked questions

Does Dependency-Track support SPDX?
No. As of version 5.1, CycloneDX is the only format Dependency-Track accepts for upload. SBOM Observer accepts CycloneDX and SPDX.
Can we move our data from Dependency-Track to SBOM Observer?
Yes. Export each project as a CycloneDX SBOM and its analysis decisions as CycloneDX VEX, then upload both to SBOM Observer. Policies are recreated in SBOM Observer.
Does SBOM Observer come with support?
Yes. Business includes support with an answer within 1 business day. Enterprise adds an SLA and a dedicated support channel.
Can SBOM Observer run on our own servers, like Dependency-Track?
Yes. The Enterprise plan includes on-premises deployment, including air-gapped environments.
What does SBOM Observer cost?
Business is for small teams. Enterprise is for 25 or more users, and adds SSO, audit logs, an SLA and on-premises deployment. See SBOM Observer pricing.

Bring a Dependency-Track export

Click through the live demo, or book a call with an engineer and bring an SBOM or a Dependency-Track export.

SBOM Observer attestations: imported CycloneDX SBOMs with their status, type and component count