Marketplace

By Use Case Marketplace

Compare By Use Case products across curated subcategories and trusted providers

Products
15,413
Subcategories
698

Selected subcategory

Software Composition Analysis (SCA)

Compare By Use Case products across curated subcategories and trusted providers

Explore By Use Case with structured category paths, practical filters, and independent product data

Showing 1–12 of 15

Active filtersOpen sourceClear all

Scans your project to determine what components you use

Software Composition Analysis (SCA)Open Source

Slsa

by SLSA Framework

Supply-chain Levels for Software Artifacts

Software Composition Analysis (SCA)Open Source

MurphySec

by murphysecurity

An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。

Software Composition Analysis (SCA)Open Source

Sbom Tool

by Microsoft

The SBOM tool is a highly scalable and enterprise ready tool to create SPDX 2.2 compatible SBOMs for any variety of artifacts.

Software Composition Analysis (SCA)Open Source

GUAC

by guacsec

GUAC aggregates software security metadata into a high fidelity graph database.

Software Composition Analysis (SCA)Open Source

OpenSCA-cli

by Xmirror Security

OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.

Software Composition Analysis (SCA)Open Source

Automatically migrate components to the Function API

Software Composition Analysis (SCA)Open Source

It Depends

by Trailofbits

A software dependency analyzer

Software Composition Analysis (SCA)Open Source

Harden Runner

by StepSecurity

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

Software Composition Analysis (SCA)Open Source

Deptective

by Trailofbits

Deptective automatically determines the native dependencies required to run any arbitrary program or command.

Software Composition Analysis (SCA)Open Source

Purl Spec

by Package-URL

A minimal specification for purl aka. a package "mostly universal" URL, join the discussion at https://gitter.im/package-url/Lobby

Software Composition Analysis (SCA)Open Source

Depx

by Projectdiscovery

Malicious package & supply-chain intelligence

Software Composition Analysis (SCA)Open Source

Frequently asked questions