AppSecNews

SCA

Software Composition Analysis

Identify open-source dependencies and match them against known vulnerability and license data.

28 tools profiled

How it differs Checks the open source packages you depend on for known vulnerabilities and license obligations. Flaws in code you wrote are SAST territory.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

9 tools match

  • Anchore

    Anchore

    SCA

    An SBOM-first software composition platform that catalogs container and filesystem contents, matches them against vulnerability feeds, and enforces policy in the pipeline.

    Open source and commercial
    Established
  • Black Duck

    Black Duck Software

    SCA

    A software composition analysis platform that identifies open source components through manifest parsing, file signature matching and binary analysis, with deep license obligation data.

    Commercial
    Established
  • cdxgen

    CycloneDX

    SCA

    A command line SBOM generator that produces CycloneDX bills of materials from source projects, container images, binaries and operating system packages across many ecosystems.

    Open source
    Established
  • Endor Labs

    Endor Labs

    SCA

    A composition analysis platform that builds call graphs across application and dependency code to determine whether a vulnerable function is actually reachable before raising it.

    Commercial
    Growing
  • FOSSA

    FOSSA

    SCA

    A composition analysis platform focused on license obligation management, resolving dependencies through native build tooling and generating attribution notices and SBOMs.

    Freemium
    Established
  • Anchore

    Anchore

    An SBOM-first software composition platform that catalogs container and filesystem contents, matches them against vulnerability feeds, and enforces policy in the pipeline.

    Open source and commercial Established
    SCA
  • Black Duck

    Black Duck Software

    A software composition analysis platform that identifies open source components through manifest parsing, file signature matching and binary analysis, with deep license obligation data.

    Commercial Established
    SCA
  • cdxgen

    CycloneDX

    A command line SBOM generator that produces CycloneDX bills of materials from source projects, container images, binaries and operating system packages across many ecosystems.

    Open source Established
    SCA
  • Endor Labs

    Endor Labs

    A composition analysis platform that builds call graphs across application and dependency code to determine whether a vulnerable function is actually reachable before raising it.

    Commercial Growing
    SCA
  • FOSSA

    FOSSA

    A composition analysis platform focused on license obligation management, resolving dependencies through native build tooling and generating attribution notices and SBOMs.

    Freemium Established
    SCA
  • A composition analysis service that resolves dependency trees from source, matches known vulnerabilities, and scores the health and maintenance risk of the projects you depend on.

    Freemium
    Established
  • Compliance oriented composition analysis that combines dependency scanning with source snippet matching against a large open source knowledge base, wrapped in a legal review workflow.

    Commercial
    Established
  • SCANOSS

    SCANOSS

    SCA

    Open source composition analysis engine that fingerprints code at snippet level using winnowing hashes and matches it against a knowledge base you can query as a service or host yourself.

    Freemium
    Growing
  • Syft

    Anchore

    SCA

    Command line SBOM generator that catalogs packages in container images, filesystems and archives, emitting SPDX, CycloneDX or its own JSON format.

    Open source
    Established
  • A composition analysis service that resolves dependency trees from source, matches known vulnerabilities, and scores the health and maintenance risk of the projects you depend on.

    Freemium Established
    SCA
  • Compliance oriented composition analysis that combines dependency scanning with source snippet matching against a large open source knowledge base, wrapped in a legal review workflow.

    Commercial Established
    SCA
  • SCANOSS

    SCANOSS

    Open source composition analysis engine that fingerprints code at snippet level using winnowing hashes and matches it against a knowledge base you can query as a service or host yourself.

    Freemium Growing
    SCA
  • Syft

    Anchore

    Command line SBOM generator that catalogs packages in container images, filesystems and archives, emitting SPDX, CycloneDX or its own JSON format.

    Open source Established
    SCA
Tick up to 4 tools above.