Dependency Scanning

Browse 71 dependency scanning tools

Contrast Software Composition Analysis (SCA) Logo

SCA tool detecting vulnerabilities in third-party libraries at runtime & build

0
CloudDefense.AI QINA (App Security) Logo

DevSecOps platform for app security with SAST, DAST, SCA, and API testing

0
FossID Software Composition Analysis Logo

SCA tool for code scanning, license identification, and SBOM generation

0
MergeBase Software Composition Analysis Logo

SCA platform for managing open source vulnerabilities across SDLC

0
Datadog Software Composition Analysis Logo

SCA tool for identifying vulnerabilities in open-source dependencies

0
Sonatype Lifecycle Logo

Automated SCA tool for open source dependency management and vulnerability remediation

0
SCANOSS Security Dataset Logo

Vulnerability detection dataset for declared & undeclared dependencies in code

0
Cycode Enterprise Software Composition Analysis Logo

Enterprise SCA tool for scanning & remediating vulnerable open source dependencies

0
OpenSCA Project Logo

OpenSCA Project is a dependency security scanner that runs in the browser.

0
Xygeni SCA Logo

SCA tool for vulnerability detection, malicious code identification & remediation

0
Ossprey Logo

Ossprey is a software supply chain security platform that uses AI-powered scanning to detect malicious open source code and prevent supply chain attacks through automated policy enforcement and dependency analysis.

-1
Mend Mend AI Native AppSec Platform Logo

AI-native AppSec platform with SAST, SCA, container & dependency mgmt.

0
SonarSource SonarQube Logo

Code quality and security platform with SAST, SCA, and AI-powered remediation

0
Codacy Security and Code Quality Logo

Code security and quality platform with SAST, SCA, DAST, and AI code protection

0
AuditJS Logo

AuditJS is a command-line tool that scans JavaScript projects for known vulnerabilities and outdated packages in npm dependencies using the OSS Index API or Nexus IQ Server.

0
Betterscan Logo

Betterscan is an orchestration toolchain that coordinates multiple security tools to scan source code and infrastructure as code for security vulnerabilities, compliance risks, secrets, and misconfigurations.

0
snync Logo

A security tool that detects potential Dependency Confusion attack vectors by identifying private package names that are not reserved on public registries.

0
Dependency Combobulator Logo

An open-source framework that detects and prevents dependency confusion attacks across multiple package management systems and development environments.

0
sdc-check Logo

A dependency security analysis tool that identifies potential risks in project dependencies including unsafe lock files, installation scripts, obfuscated code, and dangerous shell commands.

0
Nexus Repository Manager Dependency/Namespace Confusion Checker Logo

A Python script that scans Nexus Repository Manager for artifacts with identical names across repositories to identify dependency confusion attack vulnerabilities.

0
GuardDog Logo

GuardDog is a CLI tool that identifies malicious PyPI and npm packages using heuristics-based analysis of source code and metadata.

0
Hakiri Toolbelt Logo

A command line tool that automates vulnerability scanning of Ruby gems and Rails stack components by identifying CVE vulnerabilities in detected technology versions.

0
LunaTrace Logo

LunaTrace is an open source supply chain security tool that monitors software dependencies for vulnerabilities and integrates with GitHub to notify developers of security issues before deployment.

0