OWASP Dependency-Check is a tool that attempts to detect publicly disclosed vulnerabilities contained within a project’s dependencies. It can be run as a command line application, or using popular build systems such as Maven, Gradle or Brew.
Home page: https://owasp.org/www-project-dependency-check/
Documentation: https://jeremylong.github.io/DependencyCheck/