Hub Detect offers package management level analysis combined with signature scanning.
Detect Configuration
Hub Detect
Available from GitHub by running:
bash <(curl -s https://blackducksoftware.github.io/hub-detect/hub-detect.sh)
All documentation is located on our public Black Duck Confluence