
Deptools
Health scores for every dependency you ship.
Details
- Categories
- Developer ToolsDevOpsSecurity
- Use Cases
- Security ScanningCI/CDCompliance
- Target Audience
- DevOps EngineersDevelopersSecurity Teams
- Pricing
- Freemium from $39
- Featured in
- Best DevOpsBest SecurityBest Security Scanning ToolsBest CI/CD ToolsBest Tools for Security Teams
- Alternative To
RenovateDDependabot
Snyk
socket.dev
OWASP Dependency-Check
Discovery signals
How AI and people discover Deptools on PeerPush
About Deptools
Deptools is a software dependency health platform, also known as software composition analysis (SCA), for Java, Kotlin, Android, Scala, JavaScript/TypeScript, and PHP projects. It scans your project's build files (Maven, Gradle, npm/Yarn/pnpm, sbt, Composer) and resolves the complete dependency graph, direct and transitive, using a pre-built ecosystem knowledge graph. Each dependency is scored across six dimensions, rolled up into a single 0-10 Health Score: - Security: CVE detection, with severity levels and actionable patch paths - License: permissive vs. copyleft classification, including GPL-style compliance risks - Maintainability: outdated versions, version conflicts, duplicate versions, upgrade paths - Popularity: adoption trends across the ecosystem - Activity: release frequency, maintainer activity, abandonment risk - Community: contributor count, forks, open issues, bus factor Deptools generates SBOM exports (CycloneDX and SPDX formats) for software supply chain security and compliance requirements like the EU Cyber Resilience Act (CRA), plus CSV audit reports and embeddable health badges. Deptools offers a native GitHub integration, allowing teams to gate CI/CD pipelines based on dependency health directly through the GitHub Action. For any other CI system, the same gating capabilities are available via the public REST API. And if a project isn’t hosted on GitHub, its build files can be pushed directly from the pipeline instead. Free for open-source projects, with a Pro plan for private repositories and unlimited projects. Try the live demo at deptools.io/dashboard/demo
Product Video
Watch a video demo of Deptools.
Screenshots
Reviews (3)
Average 5.0 out of 5
Based on 3 reviews
The CRA exports will matter more than people expect. A lot of small EU teams have not looked at what that actually asks of them yet, and generating an SBOM by hand is nobody's idea of a good week.





Comments (1)
Hi, I'm Michaël, co-founder of Deptools. We help teams see the real health of every dependency they ship. Free for OSS projects, happy to answer any questions!