Dependency-Track MCP Server
Provides tools for managing OWASP Dependency-Track projects, vulnerabilities, findings, and CycloneDX BOM uploads through the Dependency-Track REST API.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Dependency-Track MCP Serverlist all projects with their latest findings"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Dependency-Track MCP Server
A small Model Context Protocol (MCP) server for OWASP Dependency-Track. It exposes a practical subset of the official Dependency-Track REST API over stdio so tools like Codex can query projects, fetch findings, trigger analysis, upload CycloneDX BOMs, and check async token status.
The implementation is based on the official Dependency-Track API surface:
GET /api/v1/projectGET /api/v1/project/{uuid}GET /api/v1/project/lookupGET /api/v1/project/latest/{name}GET /api/v1/finding/project/{uuid}POST /api/v1/finding/project/{uuid}/analyzePUT /api/v1/bomGET /api/v1/event/token/{uuid}
Official references:
Features
list_projectssearch_projects_by_nameget_projectlookup_projectget_latest_projectget_project_findingstrigger_project_analysisupload_bomget_event_token_status
Related MCP server: nowsecure-mcp-server
Requirements
Node.js 18+ (tested with Node 25)
A reachable Dependency-Track instance
Either an API key or bearer token with the necessary Dependency-Track permissions
Configuration
Set these environment variables before starting the server:
$env:DEPENDENCY_TRACK_BASE_URL="https://dependency-track.example.com"
$env:DEPENDENCY_TRACK_API_KEY="your-api-key"Or use a bearer token instead:
$env:DEPENDENCY_TRACK_BASE_URL="https://dependency-track.example.com"
$env:DEPENDENCY_TRACK_BEARER_TOKEN="your-bearer-token"Run
node src/index.jsCodex MCP configuration
Example stdio entry:
{
"mcpServers": {
"dependency-track": {
"command": "node",
"args": [
"C:/absolute/path/to/dependency-track-mcp-server/src/index.js"
],
"env": {
"DEPENDENCY_TRACK_BASE_URL": "https://dependency-track.example.com",
"DEPENDENCY_TRACK_API_KEY": "your-api-key"
}
}
}
}Notes on permissions
The server only wraps official Dependency-Track endpoints. Actual access still depends on the permissions of the API key or bearer token:
project listing and lookup:
VIEW_PORTFOLIOfindings and analysis:
VIEW_VULNERABILITYBOM upload:
BOM_UPLOADauto-create during BOM upload:
PORTFOLIO_MANAGEMENTorPROJECT_CREATION_UPLOAD
Query behavior
list_projectsnow supports optional client-sideoffsetandlimitparameters.search_projects_by_nameis intended for normal interactive use and defaults to returning up to 25 matches.Both tools still use the official
GET /api/v1/projectendpoint underneath.
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Generate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
Programmatic control of the Hiro security platform: scans, tasks, plans, and approvals.
Submit files and URLs to a malware sandbox, poll scans, fetch reports, hashes and IOCs.
Vulnerability management: scan projects, search sealed packages, manage sealing rules and reports.
Related MCP Servers
- AlicenseAqualityDmaintenanceEnables interaction with Xray Cloud and Data Center for test management, including authentication, GraphQL queries, test execution/plan management, and result import via MCP.96 npmMIT
- AlicenseAqualityCmaintenanceEnables interaction with NowSecure Platform for listing applications, retrieving remediation findings, and generating remediation PDFs via REST and GraphQL APIs.59 npm3MIT

deeptempo-mcp-serversofficial
FlicenseNot gradedqualityDmaintenanceProvides tools for DeepTempo AI SOC including findings and case management, investigation workflow orchestration, action approval workflows, and MITRE ATT&CK layer generation.2-- FlicenseNot gradedqualityAmaintenanceEnables to interact with Drone CI/CD for managing repositories, builds, cron jobs, secrets, and users.1-