
Snyk
Software Composition Analysis
Snyk provides developer-first software composition analysis that finds and fixes vulnerabilities in open-source dependencies directly within developer workflows.
Price$25+ / seat / month
Code, dependency, and cloud scanning in the pipeline, with fixes proposed instead of PDFs delivered.

Software Composition Analysis
Snyk provides developer-first software composition analysis that finds and fixes vulnerabilities in open-source dependencies directly within developer workflows.
Price$25+ / seat / month

Software Composition Analysis
Socket detects malicious open-source dependencies and supply chain risks.
Price$25+ / seat / month

Software Composition Analysis
Mend.io is a software composition analysis and application security platform that helps development teams identify and remediate vulnerabilities in open-source dependencies.
Price$21+ / month
Software Composition Analysis
Sonatype provides software supply chain management and SCA tools including Nexus Repository and Sonatype Lifecycle for managing open-source security and compliance.
Price$15+ / month

Code Security Scanning
Aikido Security brings together code, cloud, dependency, and runtime security workflows in a more approachable platform for modern engineering teams.
Price$314+ / month

Code Security Scanning
Cloud-based code analysis service detecting bugs, vulnerabilities, and code smells in projects hosted on GitHub and other platforms.
Price$34+ / month

DevSecOps Platforms
Checkmarx provides a comprehensive application security platform including software composition analysis, SAST, DAST, and API security for enterprise DevSecOps programs.
Price$2,500+ / month

Quality Inspection Software
SonarQube is an open-source platform for continuous code quality inspection with static analysis for bugs, vulnerabilities, and code smells.
Price$150+ / month

Code Quality and Linting
DeepSource is an AI-powered static analysis platform that automatically detects and fixes code quality issues, security vulnerabilities, and anti-patterns across multiple languages.
Price$12+ / user / month

Supply Chain Security
Chainguard provides hardened container images and a software supply chain security platform for building and shipping safer modern applications.
Price$1,584+ / month
Software Composition Analysis
SOOS provides affordable software composition analysis and DAST solutions that help development teams identify vulnerabilities and license issues in open-source dependencies.
Price$42+ / month

Cybersecurity
Semgrep is a fast, open-source static analysis tool for finding bugs and security vulnerabilities in code, with support for 30+ languages and integration into CI/CD pipelines for automated s...

Cloud Security
Wiz provides agentless cloud security including container vulnerability scanning, runtime protection, and Kubernetes security as part of its comprehensive CNAPP platform.
PriceContact sales
CI/CD
GitLab is the DevSecOps platform that combines source control, CI/CD, security scanning, and project planning in a single application.
Code Security Scanning
Open source security scanner from Aqua for Terraform code finding potential misconfigurations before infrastructure is provisioned.

Vulnerability Scanning
Open-source vulnerability scanner from Aqua Security that finds CVEs in container images, IaC, and Git repositories.

Vulnerability Scanning
Open-source vulnerability scanner using YAML-based templates to find security issues across modern tech stacks.
Developer Tools
Synopsys' IDE plugin for developers delivering security and quality feedback during development.
PriceContact sales