
Top picks: Aikido Software Supply Chain Security, Chainguard Libraries, Socket — plus 45 more compared.
Application Securitypkgsign is a free Software Composition Analysis tool. Security professionals most commonly compare it with . All 48 alternatives are matched by shared capabilities, tags, and NIST CSF 2.0 coverage.
A closer look at the 8 most relevant alternatives and competitors to pkgsign, including their key features and shared capabilities.
Software supply chain security platform detecting malware in dependencies
Shares 3 capabilities with pkgsign: NPM, Supply Chain Security, Package Security
Malware-resistant software libraries rebuilt from source for multiple languages
Shares 3 capabilities with pkgsign: NPM, Supply Chain Security, Package Security
Detects and blocks malicious/vulnerable open source packages in supply chains.
Shares 3 capabilities with pkgsign: NPM, Supply Chain Security, Package Security
npm-zoo is a curated database of known malicious NPM packages that helps developers and security researchers identify and avoid potentially harmful dependencies in their projects.
Shares 3 capabilities with pkgsign: NPM, Supply Chain Security, Package Security
Software supply chain security platform with SCA, package firewall & threat intel
Detects malicious open-source packages across SDLC using 410K+ package database
AI-driven platform that patches OSS CVEs in-place without version upgrades.
Detects foreign adversarial influence in open source software dependencies.
Software supply chain security platform detecting malware in dependencies
Malware-resistant software libraries rebuilt from source for multiple languages
Detects and blocks malicious/vulnerable open source packages in supply chains.
npm-zoo is a curated database of known malicious NPM packages that helps developers and security researchers identify and avoid potentially harmful dependencies in their projects.
Software supply chain security platform with SCA, package firewall & threat intel
Detects malicious open-source packages across SDLC using 410K+ package database
AI-driven platform that patches OSS CVEs in-place without version upgrades.
Detects foreign adversarial influence in open source software dependencies.
Cloud-native artifact mgmt & software supply chain security platform.
Tool for searching, comparing, and evaluating open source dependencies.
Identifies and helps remediate end-of-life open source dependencies.
GuardDog is a CLI tool that identifies malicious PyPI and npm packages using heuristics-based analysis of source code and metadata.
Lint lockfiles for improved security and trust policies.
A tool that safely installs packages with npm/yarn by auditing them as part of your install process.
A tool to run YARA rules against node_module folders to identify suspicious scripts
A security tool that detects potential Dependency Confusion attack vectors by identifying private package names that are not reserved on public registries.
A Python script that scans Nexus Repository Manager for artifacts with identical names across repositories to identify dependency confusion attack vulnerabilities.
A dependency security scanner that identifies potential supply chain vulnerabilities by checking for available package namespace registrations across Python, JavaScript, PHP, and Maven repositories.
SCA tool that finds, prioritizes, and fixes open source vulnerabilities
CI/CD security platform for GitHub Actions with runtime threat detection
Platform for vulnerability detection in firmware, binaries, and SBOMs
AI-native AppSec platform with SAST, SCA, container & dependency mgmt.
Automated SCA tool for open source dependency management and vulnerability remediation
SCA platform for managing open source vulnerabilities across SDLC
SCA tool for code scanning, license identification, and SBOM generation
Universal artifact repository & software supply chain security platform
JavaScript security scanner for detecting vulnerabilities in third-party scripts
SCA tool for vulnerability detection, malicious code identification & remediation
Malware detection across SDLC, DevOps pipelines, and open-source components
SCA tool for detecting vulnerabilities & license risks in open-source deps
Cloud-native SCA and SBOM platform for supply chain security across code to runtime
SCA tool that scans open-source dependencies for vulnerabilities and malware
Full lifecycle software supply chain security platform for code integrity
SCA platform with reachability analysis, AI-powered fixes, and license compliance
Runtime protection preventing supply-chain attacks & exploits via library-level policies
SBOM management platform for tracking dependencies and vulnerabilities
AI-native AppSec platform with SCA, SAST, container & dependency mgmt.
End-to-end software supply chain platform for secure artifact management
SCA tool for SBOM generation, dependency analysis, and open-source risk mgmt.
SBOM generation tool for software supply chain visibility and risk management
SCA tool for identifying vulnerable third-party libraries and dependencies
Software supply chain security platform for SDLC infrastructure protection
Vulnerability detection dataset for declared & undeclared dependencies in code
Automates SBOM ingestion, monitoring, and compliance management for software
SCA tool for managing security, quality, and license risks in open source code
Software supply chain security platform using binary analysis for threat detection
Tracks, governs, and secures software installs across endpoints and marketplaces.
SCA tool with reachability analysis for dependency vulnerabilities
Common questions security professionals ask when evaluating alternatives and competitors to pkgsign.
The most popular alternatives to pkgsign include Aikido Software Supply Chain Security, Chainguard Libraries, Socket, npm-zoo, and Veracode Secure Your Software Supply Chain. These Software Composition Analysis tools offer similar capabilities and are frequently compared by security professionals evaluating their options.