Dependency-Check is a Software Composition Analysis tool that identifies project dependencies and checks if there are any known, publicly disclosed, vulnerabilities. The tool can be part of a solution to the OWASP Top 10 2017 A9:2017-Using Components with Known Vulnerabilities.
https://github.com/jeremylong/DependencyCheck
https://jeremylong.github.io/DependencyCheck/