Loading...
Software Supply Chain Security tools for Dependency Scanning: the Software Supply Chain Security options most relevant when Dependency Scanning is the priority, compared side by side so you can shortlist faster. Filter by pricing or specialization. Independent and vendor-neutral: our scores and rankings are earned, never bought — sponsored placement is always labeled.
We cover 19 cybersecurity tools
Cloud-native artifact mgmt & software supply chain security platform.
SBOM exchange platform for managing software supply chain compliance.
Client-side tool to check npm projects for Shai Hulud 2.0 supply chain compromise.
Detects foreign adversarial influence in open source software dependencies.
SCA & supply chain security platform for vuln detection, SBOM, and autofix.
Software supply chain security platform with SBOM, provenance, and vuln prioritization.
Supply chain firewall blocking malicious/vulnerable packages before installation.
Detects and blocks malicious/vulnerable open source packages in supply chains.
Automated CVE patching for open source software components
Binary code analysis platform for software supply chain security and SBOM gen.
Malware-resistant software libraries rebuilt from source for multiple languages
Software supply chain security platform detecting malware in dependencies
Software supply chain security platform with SCA, package firewall & threat intel
Software supply chain security platform with AI-powered scanning to detect malicious code
A dependency security scanner that identifies potential supply chain vulnerabilities by checking for available package namespace registrations across Python, JavaScript, PHP, and Maven repositories.
A Python script that scans Nexus Repository Manager for artifacts with identical names across repositories to identify dependency confusion attack vulnerabilities.
A security tool that detects potential Dependency Confusion attack vectors by identifying private package names that are not reserved on public registries.
An open-source framework that detects and prevents dependency confusion attacks across multiple package management systems and development environments.
GuardDog is a CLI tool that identifies malicious PyPI and npm packages using heuristics-based analysis of source code and metadata.