Skip to content

A comprehensive list of software composition analysis tools.

License

Notifications You must be signed in to change notification settings

magnologan/awesome-sca

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

15 Commits
 
 
 
 

awesome-sca

A comprehensive list of Software Composition Analysis Tools.

Following repo contains a collection of SCA tools which can be used to analyze risks in third party components which were used as part of code. Feel free to add up any new tools.

**Note: ©️ stands for proprietary sofware, Rest belongs to Free and Open Source softwares. **

Table of Contents

Programming Languages

Javascript

Ruby

Multiple Languages

  • BlackDuck ©️ Open source software security audit
  • Bytesafe ©️ Discover and manage vulnerabilities in your dependencies
  • Contrast Security ©️
  • Debricked ©️
  • Dependancy-Check - OWASP Dependancy-check supports Java, .Net. Additional experimental support has been added for Ruby,Node.js,Python and Limited C/C++ build systems.(autoconf and cmake)
  • Flexera ©️
  • nexB ©️
  • OpenSCA - Apache License 2.0, OpenSCA is intended for scanning the third-party component dependencies and vulnerabilities.
  • RogueWave ©️
  • Snyk ©️ continuously find and fix vulnerabilities in your depandancies. it supports JS,Java,Python,Ruby,Go,PHP,.NET,Scala etc.
  • Sonatype ©️
  • Veracode ©️ (formerly SourceClear) - Thirdparty component analysis for Java, Ruby, Javascript, PHP, Python, Scala, Kotlin, C/C++, Objective C, Swift, Go, and .NET
  • WhiteSource ©️ - Secure your opensource components for C#,Java,C++,.NET,PHP,Python,Ruby,Docker,nodejs,Javascript etc.
  • Whitehat SCA ©️

Vulnerability Databases

SCA Platform

Books

Vulnerable Apps

Javascript

Java

References

Articles

About

A comprehensive list of software composition analysis tools.

Resources

License

Code of conduct

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published