Skip to main content
Glama
pluries

Dependency-Track MCP Server

by pluries

Dependency-Track MCP Server

A small Model Context Protocol (MCP) server for OWASP Dependency-Track. It exposes a practical subset of the official Dependency-Track REST API over stdio so tools like Codex can query projects, fetch findings, trigger analysis, upload CycloneDX BOMs, and check async token status.

The implementation is based on the official Dependency-Track API surface:

  • GET /api/v1/project

  • GET /api/v1/project/{uuid}

  • GET /api/v1/project/lookup

  • GET /api/v1/project/latest/{name}

  • GET /api/v1/finding/project/{uuid}

  • POST /api/v1/finding/project/{uuid}/analyze

  • PUT /api/v1/bom

  • GET /api/v1/event/token/{uuid}

Official references:

Features

  • list_projects

  • search_projects_by_name

  • get_project

  • lookup_project

  • get_latest_project

  • get_project_findings

  • trigger_project_analysis

  • upload_bom

  • get_event_token_status

Related MCP server: papertrail-mcp

Requirements

  • Node.js 18+ (tested with Node 25)

  • A reachable Dependency-Track instance

  • Either an API key or bearer token with the necessary Dependency-Track permissions

Configuration

Set these environment variables before starting the server:

$env:DEPENDENCY_TRACK_BASE_URL="https://dependency-track.example.com"
$env:DEPENDENCY_TRACK_API_KEY="your-api-key"

Or use a bearer token instead:

$env:DEPENDENCY_TRACK_BASE_URL="https://dependency-track.example.com"
$env:DEPENDENCY_TRACK_BEARER_TOKEN="your-bearer-token"

Run

node src/index.js

Codex MCP configuration

Example stdio entry:

{
  "mcpServers": {
    "dependency-track": {
      "command": "node",
      "args": [
        "C:/absolute/path/to/dependency-track-mcp-server/src/index.js"
      ],
      "env": {
        "DEPENDENCY_TRACK_BASE_URL": "https://dependency-track.example.com",
        "DEPENDENCY_TRACK_API_KEY": "your-api-key"
      }
    }
  }
}

Notes on permissions

The server only wraps official Dependency-Track endpoints. Actual access still depends on the permissions of the API key or bearer token:

  • project listing and lookup: VIEW_PORTFOLIO

  • findings and analysis: VIEW_VULNERABILITY

  • BOM upload: BOM_UPLOAD

  • auto-create during BOM upload: PORTFOLIO_MANAGEMENT or PROJECT_CREATION_UPLOAD

Query behavior

  • list_projects now supports optional client-side offset and limit parameters.

  • search_projects_by_name is intended for normal interactive use and defaults to returning up to 25 matches.

  • Both tools still use the official GET /api/v1/project endpoint underneath.

License

MIT

Related MCP Connectors

Related MCP Servers

  • F
    license
    A
    quality
    C
    maintenance
    Read-only MCP server for searching migrated Papertrail logs via SolarWinds Observability API. Provides tools to list environments and perform bearer-authenticated log queries through stdio.
    2
    67 npm
    -
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables MCP clients to access a CRM over stdio, with Microsoft Entra device-code sign-in so queries run as the signed-in user, and tools to start/check login and search CRM accounts.
    2 npm
    ISC
  • A
    license
    B
    quality
    F
    maintenance
    Enables local MCP clients to manage messaging workflows via stdio: list and read chats/messages, send messages, react to messages, manage typing/read state, and handle contact cards and requests.
    16
    1,100 npm
    MIT