Software Alternatives, Accelerators & Startups

Black Duck Software Composition Analysis

Black Duck Software Composition Analysis (SCA) provides a solution for managing open source security, quality, and license compliance risks that comes from the use of open source and third-party code.

Top 12 Open-Source Alternatives to Black Duck Software Composition Analysis

Snyk SonarQube FOSSA OWASP Dependency-Track Cppcheck Sysdig Jenkins JaCoCo Closure Compiler

Summary

The top open-source alternatives to Black Duck Software Composition Analysis are Snyk, SonarQube, and FOSSA. One of the criteria for ordering this list is the number of mentions that products have on reliable external sources. You can suggest additional sources through the form here.
  1. 1
    Snyk helps you use open source and stay secure. Continuously find and fix vulnerabilities for npm, Maven, NuGet, RubyGems, PyPI and much more.
    Pricing:
    • Open Source

    #Security #Security Monitoring #Security CI 85 social mentions

  2. SonarQube, a core component of the Sonar solution, is an open source, self-managed tool that systematically helps developers and organizations deliver Clean Code.
    Pricing:
    • Open Source
    • Freemium
    • Free Trial
    • $150.0 / Annually

    #Code Analysis #Code Review #Code Coverage 1 social mentions

  3. 3
    Open source license compliance and dependency analysis
    Pricing:
    • Open Source

    #Security #Code Analysis #Web Application Security 7 social mentions

  4. OWASP Dependency-Track is an intelligent Software Composition Analysis (SCA) platform that allows...
    Pricing:
    • Open Source

    #Security #Code Analysis #Security & Privacy 19 social mentions

  5. Dependency-Check is a utility that identifies project dependencies and checks if there are any...
    Pricing:
    • Open Source

    #Security #Code Analysis #Web Application Security 16 social mentions

  6. Cppcheck is an analysis tool for C/C++ code. It detects the types of bugs that the compilers normally fail to detect. The goal is no false positives. CppCheckDownload cppcheck for free.
    Pricing:
    • Open Source

    #Code Analysis #Code Coverage #Development 10 social mentions

  7. 7
    Sysdig is an open source, system-level exploration that capture system state and activity from a running Linux instance, then save, filter and analyze.
    Pricing:
    • Open Source

    #Security #Monitoring Tools #Developer Tools 2 social mentions

  8. Jenkins is an open-source continuous integration server with 300+ plugins to support all kinds of software development
    Pricing:
    • Open Source

    #DevOps Tools #Continuous Integration #Continuous Deployment 6 social mentions

  9. 9
    JaCoCo is a free Java code coverage library.
    Pricing:
    • Open Source

    #Code Coverage #Code Analysis #Code Quality

  10. The Closure Compiler is a tool for making JavaScript download and run faster.
    Pricing:
    • Open Source

    #Web Application Bundler #Tool #Code Analysis 10 social mentions

  11. Analyzes C# source code to enforce a set of style and consistency rules. - StyleCop/StyleCop
    Pricing:
    • Open Source

    #Code Analysis #Code Coverage #Code Review

  12. Static Application Security Testing (SAST)
    Pricing:
    • Open Source

    #Code Analysis #Code Review #Web Application Security 4 social mentions

Suggest an alternative
If you think we've missed something, please suggest an alternative to Black Duck Software Composition Analysis.
Please use the Feedback button if you think any of the listed products shouldn't be regarded as open-source.

Black Duck Software Composition Analysis discussion

Log in or Post with