Aqua Trivy vs Black Duck
Aqua TrivyVulnerability Scanning
Free open sourcePublished price
Black DuckSoftware Composition Analysis
CustomPublished price
Aqua Trivy Vulnerability Scanning The fastest way for DevOps and security teams to get started with vulnerability scanning and IaC scanning | Black Duck Software Composition Analysis Open source security and compliance. | |
|---|---|---|
| Overview | ||
| Category | Vulnerability Scanning | Software Composition Analysis |
| What it is | Open-source vulnerability scanner from Aqua Security that finds CVEs in container images, IaC, and Git repositories. | Black Duck provides software composition analysis that helps organizations manage security, quality, and license compliance risks from open-source and third-party code. |
| Pricing | ||
| Published price | Free open source Trivy is a free, open-source scanner (Apache 2.0) maintained by Aqua Security. There is no paid tier for Trivy itself; Aqua monetizes its separate commercial Aqua Platform (quote-… | Custom No public list price; quote-only, and AWS Marketplace listings are private-offer. Black Duck (formerly Synopsys' app-security business) SCA is sold by contract. Procurement benchm… |
| Pricing model | Free | Custom quote |
| Free options | Free plan · No free trial | No free plan · Free trial |
| Deal on Cubbie | None right now | None right now |
| Company | ||
| Founded | 2019 | 2002 |
| Team size | 501-1,000 employees | 1001-5000 employees |
| Headquarters | Burlington, MA | Burlington, Massachusetts |
| Featured clients | Not available | BMW, Siemens, Bosch |