Loading...
Dependency Scanning groups the cybersecurity tools focused on dependency scanning, pulled from across every category so you can compare every option in one place. Filter by category or pricing to narrow the field. Independent and vendor-neutral: our scores and rankings are earned, never bought — sponsored placement is always labeled.
Browse 114 cybersecurity solutions, with 0 security professionals searching monthly
Cloud-native app security platform covering code to cloud with SAST, SCA, IaC
Runtime endpoint firewall that blocks malicious packages before they execute
AI-driven SCA tool with reachability analysis, SBOM gen & auto-fix PRs.
CI/CD pipeline firewall for build-time SBOM verification and policy enforcement.
Real-time firewall that monitors and enforces security policy in CI/CD pipelines.
SCA platform for scanning & remediating open-source dependency vulnerabilities.
Hardened, minimal container images with reduced CVE exposure and SBOM support.
Curated open-source package library with vuln tracking, SBOM, and license compliance.
Curated repo of pre-vetted, security-reviewed open-source language packages.
Scans AI models for malicious code, vulnerabilities, and unsafe artifacts pre-deployment.
CI/CD-integrated platform for EU Cyber Resilience Act compliance automation.
Cloud-native artifact mgmt & software supply chain security platform.
Security scanner and verifier for AI agent tools, MCP servers, and plugins.
SCA tool detecting OSS vulnerabilities & license risks in code, binaries, containers.
SBOM exchange platform for managing software supply chain compliance.
Centralized DevSecOps platform for orchestrating SAST, DAST & SCA scanners.
AI SDLC risk prevented or remediated. Automatically. At machine speed.
Runtime SCA tool prioritizing fixable & exploitable open-source vulnerabilities
OpenSCA Project is a dependency security scanner that runs in the browser.
Unified platform for SBOM, CBOM, and post-quantum cryptography readiness management
SCA platform for detecting and managing third-party component risks in the SDLC
Platform to identify, remediate, and prevent EOL open source software risk.
Client-side tool to check npm projects for Shai Hulud 2.0 supply chain compromise.
Detects foreign adversarial influence in open source software dependencies.