What is OWASP Dependency-Check and where does it fit in a DevSecOps pipeline?
Quick Answer
OWASP Dependency-Check is used for SCA (software composition analysis), running at the build stage. Explain the class of problem it catches, why catching it there is cheaper than catching it in production, and how it reports findings back to developers.
Detailed Answer
Describe OWASP Dependency-Check by the failure it prevents, not by its feature list. It belongs to SCA (software composition analysis) and runs at the build stage of delivery, which matters because the cost of fixing a defect rises sharply the later it is found — the core argument behind shifting security left.
Strong answers cover CVE matching via the NVD feed, CPE identification and false positives, suppression files, the NVD API key and mirror for slow feed updates, CVSS-based failBuildOnCVSS thresholds, and generating SBOM-adjacent reports. Interviewers also listen for the operational side: who owns the rules, how findings reach the developer who introduced them, how false positives get suppressed without silently disabling coverage, and what the break-glass path is when a fix genuinely cannot ship in time.
Tie it to the wider toolchain. Security scanning is only useful when its output is actionable, deduplicated across tools, and attached to a specific commit, image digest or resource — otherwise teams learn to ignore it.
Code Example
# Where OWASP Dependency-Check sits in the pipeline # stage: build # 1. run the scan against the artifact produced by this stage # 2. compare findings against the agreed severity threshold # 3. failing the build when a dependency exceeds the configured CVSS threshold # 4. publish the report so developers see it on the commit or pull request
Interview Tip
Anchor OWASP Dependency-Check to a stage and a gate: what it scans, when it runs, and what makes the build stop.