AppSecNews

SCA

Software Composition Analysis

Identify open-source dependencies and match them against known vulnerability and license data.

28 tools profiled

How it differs Checks the open source packages you depend on for known vulnerabilities and license obligations. Flaws in code you wrote are SAST territory.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

6 tools match

  • Black Duck

    Black Duck Software

    SCA

    A software composition analysis platform that identifies open source components through manifest parsing, file signature matching and binary analysis, with deep license obligation data.

    Commercial
    Established
  • SCA

    A rapid portfolio scanner that analyzes source across hundreds of applications to report open source component risk, license exposure, cloud readiness and software health.

    Commercial
    Established
  • Finite State

    Finite State

    SCA

    A product security platform that unpacks firmware and binaries to generate SBOMs and identify component vulnerabilities in connected devices where no source code is available.

    Commercial
    Growing
  • Black Duck

    Black Duck Software

    A software composition analysis platform that identifies open source components through manifest parsing, file signature matching and binary analysis, with deep license obligation data.

    Commercial Established
    SCA
  • A rapid portfolio scanner that analyzes source across hundreds of applications to report open source component risk, license exposure, cloud readiness and software health.

    Commercial Established
    SCA
  • Finite State

    Finite State

    A product security platform that unpacks firmware and binaries to generate SBOMs and identify component vulnerabilities in connected devices where no source code is available.

    Commercial Growing
    SCA
  • FOSSA

    FOSSA

    SCA

    A composition analysis platform focused on license obligation management, resolving dependencies through native build tooling and generating attribution notices and SBOMs.

    Freemium
    Established
  • OSV-Scanner

    Google

    SCA

    Command line scanner that matches lockfiles, SBOMs and container contents against the OSV.dev advisory database using precise affected version ranges.

    Open source
    Growing
  • SCA

    Commercial software composition analysis that identifies components by binary fingerprint and enforces staged security and license policy across the build and release pipeline.

    Commercial
    Established
  • FOSSA

    FOSSA

    A composition analysis platform focused on license obligation management, resolving dependencies through native build tooling and generating attribution notices and SBOMs.

    Freemium Established
    SCA
  • OSV-Scanner

    Google

    Command line scanner that matches lockfiles, SBOMs and container contents against the OSV.dev advisory database using precise affected version ranges.

    Open source Growing
    SCA
  • Commercial software composition analysis that identifies components by binary fingerprint and enforces staged security and license policy across the build and release pipeline.

    Commercial Established
    SCA
Tick up to 4 tools above.