Software Alternatives & Reviews

OWASP Dependency-Check

OWASP dependency-check is open-source and can be used to scan Java and .NET applications via the CLI or using plugins.Read articles Continuous Security with OWASP Dependency Check and Integrating OWASP Dependency Check with Jenkins to CI/CD. subtitle

Top 11 Open-Source Alternatives to OWASP Dependency-Check

Snyk SonarQube OWASP Dependency-Track SonarCloud ESLint Semgrep SpotBugs FOSSA NewReleases

Summary

The top open-source alternatives to OWASP Dependency-Check are Snyk, SonarQube, and Dependency-Check. One of the criteria for ordering this list is the number of mentions that products have on reliable external sources. You can suggest additional sources through the form here.
  1. 1
    Snyk helps you use open source and stay secure. Continuously find and fix vulnerabilities for npm, Maven, NuGet, RubyGems, PyPI and much more.
    Pricing:
    • Open Source

    #Security #Security Monitoring #Security CI 85 social mentions

  2. SonarQube, a core component of the Sonar solution, is an open source, self-managed tool that systematically helps developers and organizations deliver Clean Code.
    Pricing:
    • Open Source
    • Freemium
    • Free Trial
    • $150.0 / Annually

    #Code Analysis #Code Review #Code Coverage 1 social mentions

  3. Dependency-Check is a utility that identifies project dependencies and checks if there are any...
    Pricing:
    • Open Source

    #Security #Software Development #Code Analysis 16 social mentions

  4. OWASP Dependency-Track is an intelligent Software Composition Analysis (SCA) platform that allows...
    Pricing:
    • Open Source

    #Security #Code Analysis #Security & Privacy 19 social mentions

  5. Enhance your workflow with continuous code quality, SonarCloud automatically analyzes and decorates pull requests on GitHub, Bitbucket, Azure DevOps and GitLab on major languages.
    Pricing:
    • Open Source
    • Freemium
    • Free Trial
    • €10.0 / Monthly (100,000 Lines of Code)

    #Developer Tools #DevOps Tools #SAST 12 social mentions

  6. 6
    The fully pluggable JavaScript code quality tool
    Pricing:
    • Open Source

    #Code Coverage #Developer Tools #Code Quality 229 social mentions

  7. Semgrep is a fast, open-source, static analysis tool for finding bugs and enforcing code standards at editor, commit, and CI time.
    Pricing:
    • Open Source

    #Code Analysis #Code Coverage #Code Quality 7 social mentions

  8. Static Application Security Testing (SAST)
    Pricing:
    • Open Source

    #Code Analysis #Code Review #Web Application Security 3 social mentions

  9. 9
    Open source license compliance and dependency analysis
    Pricing:
    • Open Source

    #Security #Code Analysis #Web Application Security 7 social mentions

  10. Stop wasting your time checking manually if some piece of software is updated. Get Email, Slack, Telegram, Discord, Hangouts Chat, Microsoft Teams, Mattermost, Rocket.Chat, or Webhooks notifications.
    Pricing:
    • Open Source
    • Free

    #Software Development #News #DevOps Services 18 social mentions

  11. 11
    One verification platform to secure the whole user journey
    Pricing:
    • Open Source
    • Paid
    • Free Trial

    #Identity Verification And Protection #Security #Identity Verification 8 social mentions

Suggest an alternative
If you think we've missed something, please suggest an alternative to OWASP Dependency-Check.
Please use the Feedback button if you think any of the listed products shouldn't be regarded as open-source.

Generic OWASP Dependency-Check discussion

Log in or Post with