Level: Beginner / Basic DevSecOps
Duration: 60 minutes
Format: Instructor-led hands-on demo
Focus: Install → scan a real project → read findings → understand CVE/CVSS → generate reports → demonstrate a simple security gate
Lab Version
Tutorial verified for: October 2026
OWASP Dependency-Check: 13.0.0
Recommended Java runtime: Java 17 LTS
Minimum Java runtime: Java 11
Sample project: OWASP NodeGoat
Pinned sample commit: 9336e34
Primary report format: HTML
Code language: CSS (css)
Important for a 1-hour class: Dependency-Check must download vulnerability data before it can perform useful analysis. The first update can take significant time. The instructor should pre-populate the Dependency-Check data directory before the session, or provide students with a prepared lab VM/environment.
1. Learning Objectives
By the end of this 60-minute lab, students should be able to:
- Explain what OWASP Dependency-Check does.
- Explain why Software Composition Analysis (SCA) matters.
- Verify a Dependency-Check installation.
- Scan a real GitHub project.
- Generate an HTML vulnerability report.
- Identify the affected dependency, CVE, severity, and CVSS score.
- Understand why a detected vulnerability still needs investigation.
- Generate a machine-readable report.
- Demonstrate a simple CVSS-based security gate.
- Explain where Dependency-Check fits into CI/CD.
2. 60-Minute Agenda
| Time | Activity |
|---|---|
| 0–5 min | SCA and Dependency-Check overview |
| 5–12 min | Environment and installation verification |
| 12–18 min | Clone the real sample application |
| 18–32 min | Run the first Dependency-Check scan |
| 32–43 min | Read the HTML report |
| 43–50 min | CVE, CVSS, severity, evidence, and false positives |
| 50–55 min | JSON report + simple security gate |
| 55–60 min | CI/CD placement, validation, recap |
3. What Is OWASP Dependency-Check?
OWASP Dependency-Check is a Software Composition Analysis tool that identifies publicly disclosed vulnerabilities in third-party software components used by an application.
A simplified workflow is:
Application source code
↓
Dependency manifests / packages
↓
OWASP Dependency-Check
↓
Component identification
↓
Known vulnerability matching
↓
CVE / CVSS information
↓
HTML / JSON / XML / SARIF reports
Code language: JavaScript (javascript)
Dependency-Check helps answer questions such as:
What third-party components are we using?
↓
Are known vulnerabilities associated with those components?
↓
How severe are the findings?
↓
Do the findings actually apply to our application?
↓
Should we upgrade, mitigate, suppress, or investigate further?
Code language: JavaScript (javascript)
Key lesson: A Dependency-Check finding is a security signal that requires analysis. It is not automatic proof that the application is exploitable.
4. Prerequisites
Student workstation
Recommended environment:
Ubuntu 22.04/24.04+ or current macOS
Java 17
Git
unzip
Internet access
OWASP Dependency-Check 13.0.0
Recommended resources:
CPU: 2+ cores
RAM: 4 GB minimum, 8 GB recommended
Disk: 3+ GB free for the lab and vulnerability data
Code language: HTTP (http)
Verify Java
java -version
Example:
openjdk version "17.x.x"
Code language: CSS (css)
Verify Git
git --version
Example:
git version 2.x.x
Code language: CSS (css)
5. Install Dependency-Check
If the instructor has already prepared Dependency-Check, students can skip directly to Installation Verification.
Linux/macOS — CLI distribution
Create a lab tools directory:
mkdir -p ~/odc-lab
cd ~/odc-lab
Download the 13.0.0 CLI distribution:
curl -LO https://github.com/dependency-check/DependencyCheck/releases/download/v13.0.0/dependency-check-13.0.0-release.zip
Code language: JavaScript (javascript)
Extract it:
unzip dependency-check-13.0.0-release.zip
Code language: CSS (css)
The executable is located under:
dependency-check/bin/
Installation Verification
Run:
./dependency-check/bin/dependency-check.sh --version
Expected result:
Dependency-Check Core version 13.0.0
Code language: CSS (css)
On Windows, use
dependency-check.batinstead ofdependency-check.sh.
6. Instructor Preparation — Do This Before Class
A first-time vulnerability database update can consume much of a 60-minute lab. Pre-populate the data directory.
Create a reusable data directory:
mkdir -p ~/odc-lab/odc-data
Code language: JavaScript (javascript)
If an NVD API key is available:
export NVD_API_KEY="YOUR_NVD_API_KEY"
Code language: JavaScript (javascript)
Populate/update Dependency-Check data:
~/odc-lab/dependency-check/bin/dependency-check.sh \
--updateonly \
--data ~/odc-lab/odc-data \
--nvdApiKey "$NVD_API_KEY"
Code language: JavaScript (javascript)
If no API key is available, the instructor can perform the update without --nvdApiKey, but updates can be considerably slower and are more likely to encounter rate limiting.
For the live class, reuse the same data directory:
~/odc-lab/odc-data
Code language: JavaScript (javascript)
7. Clone the Real Sample Application
For this quick demo we use OWASP NodeGoat, a deliberately vulnerable application maintained for security training.
Step 1 — Clone NodeGoat
cd ~/odc-lab
git clone https://github.com/OWASP/NodeGoat.git
cd NodeGoat
Code language: PHP (php)
Step 2 — Pin the lab revision
git checkout 9336e34
Expected output is similar to:
HEAD is now at 9336e34 ...
Step 3 — Confirm dependency files
ls package.json package-lock.json
Code language: CSS (css)
Expected:
package-lock.json
package.json
Code language: CSS (css)
Why pin the commit?
Using an immutable Git commit keeps the training project stable even if the NodeGoat default branch changes later.
8. Understand the Project Before Scanning
Inspect the beginning of the dependency manifest:
head -40 package.json
Code language: CSS (css)
Optional quick dependency search:
grep -n 'marked' package.json package-lock.json | head
Code language: JavaScript (javascript)
The pinned training revision contains intentionally old dependencies. This gives Dependency-Check useful material to analyze.
We are not trying to run NodeGoat in this lab. The goal is to analyze its third-party dependencies.
9. Run the First Dependency-Check Scan
Create a report directory:
mkdir -p ~/odc-lab/reports
Code language: JavaScript (javascript)
From the NodeGoat directory, run:
~/odc-lab/dependency-check/bin/dependency-check.sh \
--project "OWASP NodeGoat Quick Lab" \
--scan . \
--data ~/odc-lab/odc-data \
--format HTML \
--out ~/odc-lab/reports
Code language: JavaScript (javascript)
If the environment is not pre-populated and an NVD API key is available, add:
--nvdApiKey "$NVD_API_KEY"
Code language: JavaScript (javascript)
What Dependency-Check is doing
During the scan it broadly performs this sequence:
Read application files
↓
Identify dependencies
↓
Collect evidence about components
↓
Match components to vulnerability intelligence
↓
Associate possible CVEs
↓
Generate the report
Expected completion
The output should eventually indicate that analysis completed and that a report was written.
Do not expect an identical number of vulnerabilities every time. Vulnerability intelligence can change independently of the pinned application source code.
10. Locate the HTML Report
List the output directory:
ls -lh ~/odc-lab/reports
Code language: JavaScript (javascript)
You should see:
dependency-check-report.html
Code language: CSS (css)
Open the report
macOS
open ~/odc-lab/reports/dependency-check-report.html
Code language: JavaScript (javascript)
Linux desktop
xdg-open ~/odc-lab/reports/dependency-check-report.html
Code language: JavaScript (javascript)
If a graphical browser is not available, copy the report to a workstation with a browser.
11. Read the HTML Report
Spend several minutes examining one vulnerable dependency.
For one finding, identify these fields:
Dependency / component
↓
Detected version
↓
Evidence / identifiers
↓
CVE
↓
Severity
↓
CVSS score
↓
Vulnerability description
↓
References
↓
Affected-version information
What the fields mean
| Field | Meaning |
|---|---|
| Dependency | The library or component being analyzed |
| Version | Version Dependency-Check identified |
| CVE | Public vulnerability identifier |
| CVSS | Numerical severity score supplied by the vulnerability source |
| Severity | Human-readable severity classification |
| Evidence | Information used to identify the component |
| CPE / identifiers | Component identity information used during matching where applicable |
| Description | Summary of the vulnerability |
| References | Vendor, advisory, NVD, patch, or other supporting links |
12. CVE and CVSS — 5-Minute Explanation
CVE
CVE means Common Vulnerabilities and Exposures.
Example pattern:
CVE-YYYY-NNNNN
A CVE identifies a publicly disclosed vulnerability. It does not by itself tell you whether your application is exploitable.
CVSS
CVSS means Common Vulnerability Scoring System.
Typical interpretation:
| CVSS score | Common severity label |
|---|---|
| 0.0 | None |
| 0.1–3.9 | Low |
| 4.0–6.9 | Medium |
| 7.0–8.9 | High |
| 9.0–10.0 | Critical |
The score helps prioritize investigation, but it must be combined with application context.
13. Detection Is Not the Same as Confirmation
Teach students this workflow:
Dependency-Check finding
↓
Is the dependency really present?
↓
Is the detected version correct?
↓
Does the CVE apply to that version?
↓
Does our application use the vulnerable functionality?
↓
Is the component reachable/exploitable in our deployment?
↓
Upgrade / mitigate / investigate / suppress with justification
Code language: JavaScript (javascript)
Useful terms
Detected vulnerability
Dependency-Check found a relationship between a component and vulnerability intelligence.
Confirmed vulnerability
Engineering/security analysis confirms that the vulnerable component/version and relevant conditions apply.
False positive
The tool associated a vulnerability with the dependency incorrectly or the identification is not applicable.
Needs investigation
The tool has provided enough evidence to justify review, but the team has not yet confirmed applicability or exploitability.
Never teach teams to suppress a finding simply because they do not want the pipeline to fail.
14. Generate a JSON Report
Machine-readable output is useful for CI/CD and security tooling.
Run:
~/odc-lab/dependency-check/bin/dependency-check.sh \
--project "OWASP NodeGoat Quick Lab" \
--scan . \
--data ~/odc-lab/odc-data \
--format JSON \
--out ~/odc-lab/reports
Code language: JavaScript (javascript)
Check the directory:
ls -lh ~/odc-lab/reports
Code language: JavaScript (javascript)
You should now see a JSON report in addition to the HTML report.
Typical uses:
HTML → Human review
JSON → Automation / parsing / CI tools
XML → Integrations
SARIF → Security/code-scanning platforms that consume SARIF
Code language: JavaScript (javascript)
15. Quick Security-Gate Demo
Dependency-Check can return a failing exit status when findings meet or exceed a configured CVSS threshold.
For a demonstration threshold of 7.0:
~/odc-lab/dependency-check/bin/dependency-check.sh \
--project "OWASP NodeGoat Gate Demo" \
--scan . \
--data ~/odc-lab/odc-data \
--format HTML \
--out ~/odc-lab/reports \
--failOnCVSS 7
Code language: JavaScript (javascript)
Immediately inspect the shell exit code:
echo $?
Code language: PHP (php)
Conceptually:
Scan
↓
Find vulnerabilities
↓
Evaluate CVSS scores
↓
Compare with threshold
↓
Return pass/fail status
Code language: JavaScript (javascript)
Important distinction
Report generation ≠ vulnerability remediation
Security gate ≠ vulnerability proof
Build failure ≠ application compromise
A production threshold should be set by an organization’s risk policy, not copied blindly from this training example.
16. Where Dependency-Check Fits in CI/CD
A simple pipeline placement is:
Developer
↓
Git push / Pull request
↓
CI pipeline
↓
Restore/install dependencies
↓
OWASP Dependency-Check
↓
Publish security report
↓
Security gate
↓
Build / Test / Deploy
Typical automation pattern:
1. Cache or centrally maintain Dependency-Check vulnerability data.
2. Scan the application during CI.
3. Save HTML/JSON/SARIF as artifacts.
4. Apply an agreed policy threshold.
5. Investigate findings.
6. Upgrade or mitigate vulnerable components.
7. Use documented suppressions only for justified false positives/not-applicable findings.
Code language: JavaScript (javascript)
17. Essential CLI Options for This Lab
| Option | Purpose |
|---|---|
--project | Sets the project name shown in the report |
--scan | Specifies the file/directory to analyze |
--out | Specifies where reports are written |
--format | Selects report format |
--data | Specifies the Dependency-Check local data directory |
--nvdApiKey | Supplies an NVD API key for vulnerability-data updates |
--updateonly | Updates Dependency-Check data without running a project scan |
--failOnCVSS | Returns a failing status when the threshold is met/exceeded |
--version | Displays the installed Dependency-Check version |
For a quick lab, students do not need the full CLI option catalogue.
18. Three Student Tasks
Task 1 — Verify and Scan
Run:
~/odc-lab/dependency-check/bin/dependency-check.sh --version
Code language: JavaScript (javascript)
Then complete an HTML scan of NodeGoat.
Validation
Student can show:
Dependency-Check 13.0.0
and
dependency-check-report.html
Code language: CSS (css)
Task 2 — Investigate One Finding
Choose one dependency from the HTML report and record:
Dependency:
Version:
CVE:
CVSS:
Severity:
What evidence identified the component?
What should be investigated before calling it exploitable?
Validation
Student can explain why:
"CVE detected" does not automatically mean "application exploitable."
Code language: JavaScript (javascript)
Task 3 — Demonstrate a Gate
Run the scan with:
--failOnCVSS 7
Then inspect:
echo $?
Code language: PHP (php)
Validation
Student can explain that the exit status can be consumed by a CI system as a security gate.
19. Quick Troubleshooting
Problem — Java command not found
Cause: Java is not installed or is not on PATH.
Check:
java -version
Solution: Install a supported Java runtime. Java 17 is recommended for this lab.
Problem — dependency-check.sh permission denied
Check permissions:
ls -l ~/odc-lab/dependency-check/bin/dependency-check.sh
Code language: JavaScript (javascript)
If required:
chmod +x ~/odc-lab/dependency-check/bin/dependency-check.sh
Code language: JavaScript (javascript)
Verify:
~/odc-lab/dependency-check/bin/dependency-check.sh --version
Code language: JavaScript (javascript)
Problem — First scan is extremely slow
Likely cause: Vulnerability data is being downloaded for the first time.
Best lab solution: Pre-populate and reuse the --data directory before class.
Problem — NVD update errors or rate limiting
Likely causes:
- No NVD API key.
- API rate limiting.
- Proxy/firewall restrictions.
- Temporary network issues.
Lab solution: Use the instructor-prepared Dependency-Check data directory rather than spending class time rebuilding it.
Problem — No report appears
Confirm the requested output directory:
ls -lah ~/odc-lab/reports
Code language: JavaScript (javascript)
Then confirm the scan path exists:
pwd
ls package.json package-lock.json
Code language: CSS (css)
Problem — Many findings appear
That can be expected for a deliberately vulnerable training application.
Do not try to fix every finding during the 1-hour demo. Pick one finding and teach the investigation process.
20. Lab Validation Checklist
At the end of the session, students should be able to check:
[ ] Java works
[ ] Git works
[ ] Dependency-Check 13.0.0 is available
[ ] NodeGoat is cloned
[ ] Commit 9336e34 is checked out
[ ] Dependency-Check data is available
[ ] HTML scan completed
[ ] HTML report opened
[ ] One dependency was investigated
[ ] One CVE was identified
[ ] CVSS/severity were interpreted
[ ] JSON output was demonstrated
[ ] failOnCVSS security gate was demonstrated
[ ] CI/CD placement is understood
Code language: JavaScript (javascript)
21. Five-Minute Knowledge Check
1. What problem does Dependency-Check help solve?
Answer: It helps identify known vulnerabilities associated with third-party software components used by an application.
2. Does a reported CVE automatically prove the application is exploitable?
Answer: No. The finding must be validated in the context of the actual dependency, version, use, and deployment.
3. Why can the first Dependency-Check run take much longer?
Answer: Dependency-Check may need to download and build/update its local vulnerability data.
4. Which report is easiest for a person to review?
Answer: HTML.
5. Why generate JSON or SARIF?
Answer: They are machine-readable formats suitable for automation and security/tool integrations.
6. What does --failOnCVSS 7 demonstrate?
Answer: A CI/security gate that returns a failing status when a finding reaches the configured CVSS threshold.
7. Should suppression be used to make an uncomfortable finding disappear?
Answer: No. Suppression should be documented and justified for false positives or findings determined not to apply.
22. Key Takeaways
1. Dependency-Check is an SCA tool.
2. It analyzes application dependencies and matches them with known vulnerability intelligence.
3. A finding is the beginning of investigation—not the end.
4. CVE identifies the vulnerability; CVSS helps communicate severity.
5. HTML is useful for people; JSON/XML/SARIF are useful for automation and integrations.
6. Dependency-Check can participate in a CI/CD security gate using failOnCVSS.
7. Pre-populating the vulnerability database is essential for a smooth 1-hour classroom demo.
Code language: JavaScript (javascript)
23. Trainer Quick-Run Commands
Use these commands for the live demo after the Dependency-Check data directory has been prepared.
<em># 1. Verify Dependency-Check</em>
~/odc-lab/dependency-check/bin/dependency-check.sh --version
<em># 2. Clone and pin NodeGoat</em>
cd ~/odc-lab
git clone https://github.com/OWASP/NodeGoat.git
cd NodeGoat
git checkout 9336e34
<em># 3. HTML scan</em>
mkdir -p ~/odc-lab/reports
~/odc-lab/dependency-check/bin/dependency-check.sh \
--project "OWASP NodeGoat Quick Lab" \
--scan . \
--data ~/odc-lab/odc-data \
--format HTML \
--out ~/odc-lab/reports
<em># 4. Inspect output</em>
ls -lh ~/odc-lab/reports
<em># 5. JSON scan</em>
~/odc-lab/dependency-check/bin/dependency-check.sh \
--project "OWASP NodeGoat Quick Lab" \
--scan . \
--data ~/odc-lab/odc-data \
--format JSON \
--out ~/odc-lab/reports
<em># 6. Security-gate demo</em>
~/odc-lab/dependency-check/bin/dependency-check.sh \
--project "OWASP NodeGoat Gate Demo" \
--scan . \
--data ~/odc-lab/odc-data \
--format HTML \
--out ~/odc-lab/reports \
--failOnCVSS 7
echo $?
Code language: HTML, XML (xml)
24. Trainer Notes
For a successful one-hour delivery:
- Prepare the Dependency-Check vulnerability data before students arrive.
- Do not spend classroom time troubleshooting NVD downloads unless update troubleshooting is the lesson.
- Demonstrate only one or two findings in depth.
- Emphasize evidence and investigation rather than vulnerability counts.
- Avoid turning the session into a complete SCA governance course.
- Use the CVSS threshold only to explain how a gate works; do not present
7.0as a universal production policy. - End by showing where the scan would run in CI/CD rather than configuring a full pipeline during the hour.
25. Official References
Use these source categories when expanding the lab:
- OWASP Dependency-Check documentation
- Dependency-Check official GitHub repository and releases
- NVD API documentation
- OWASP NodeGoat repository
- Official CI platform documentation when implementing pipeline integration
For instructor-led delivery, verify the Dependency-Check release and upstream documentation again before reusing this lab in a future semester or training cycle.
I’m Rajesh Kumar, a DevOps, SRE, DevSecOps, Cloud, and Platform Engineering expert passionate about sharing practical knowledge, real-world experiences, and industry best practices. I have worked at Cotocus and regularly write about technology, travel, investing, health, product reviews, and digital marketing through my various platforms.
I publish technical articles at DevOps School, travel stories at Holiday Landmark, stock market insights at Stocks Mantra, health and fitness guidance at My Medic Plus, product reviews at TrueReviewNow, and SEO and digital marketing strategies at Wizbrand.
Find Trusted Cardiac Hospitals
Compare heart hospitals by city and services — all in one place.
Explore Hospitals