---
title: Using OWASP dependency check on MacOS
url: https://calvin.my/posts/using-owasp-dependency-check-on-macos
published: 2024-08-22
updated: 2026-09-17
category: Development
tags:
- owasp
- Security
- MacOS
summary: 'The post explains how to run OWASP Dependency-Check on macOS: install it through Homebrew, request an NVD API key, and scan a project directory. The tool produces an HTML report identifying dependency vulnerabilities. It supports analyzers for several ecosystem-specific package and artifact formats, including Java archives, Android packages, NuGet, Ruby Gemfiles, and lockfiles.'
---

# Using OWASP dependency check on MacOS

This article documents the steps to use OWASP [dependency check](https://github.com/jeremylong/DependencyCheck) tool.

1. Install the tool via homebrew

   ```bash
   brew update && brew install dependency-check
   ```

2. Obtain an NVD (National Vulnerability Database) API Key

   ```markup
   https://nvd.nist.gov/developers/request-an-api-key
   ```

3. Go to the directory you wish to scan (Usually the directory that contains your project files)

4. Run the tool

   ```markup
   dependency-check --out . --scan . --nvdApiKey XXXX
   ```

5. Once completed, the report will be available, in html format (dependency-check-report.html).

   ![](https://camy-pub.s3.ap-southeast-1.amazonaws.com/9977e9b4-3cee-4436-bdaa-c8f9af7d8b88.png)

6. The supported analyzers include jars, apks, nugets, Gemfile, package.lock, etc. View full list [here](https://jeremylong.github.io/DependencyCheck/analyzers/index.html).
