# Top Free Software Bill of Materials (SBOM) Software

## How Many Software Bill of Materials (SBOM) Software Products Does G2 Track?

**Total Products under this Category:** 33

### Category Stats (Jul 2026)

- **Average Rating:** 4.49/5 (↑0.01 vs Jun 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Finite State (+1.29%) - Among all products in this category, Finite State recorded the largest rating increase compared to last month

_Last updated: July 28, 2026_

## How Does G2 Rank Software Bill of Materials (SBOM) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 900+ Authentic Reviews
- 33+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

**Sponsored**

### JFrog

JFrog Ltd. (Nasdaq: FROG), the creators of the unified DevOps, DevSecOps, DevGovOps and MLOps platform, is on a mission to create a world of software delivered without friction from development to production. Driven by a “Liquid Software” vision to keep software continuously flowing, secure, and always up to date, the JFrog Platform serves as the definitive software supply chain system of record. It is uniquely engineered to power organizations as they build, manage, and distribute trusted software with unprecedented speed, security, and scale across hybrid and multi-cloud environments. As software engineering evolves in the AI era, JFrog’s newest offerings address the industry's most pressing trend: the rise of agentic software development and the hidden security risks of "Shadow AI." In response to threat actors increasingly targeting developer workflows including a massive surge in malicious open-source AI models and infected packages; JFrog has expanded its platform capabilities to deliver absolute end-to-end visibility and automated compliance. Key new innovations include the JFrog AI Catalog, which enables organizations to centralize, govern, and control the lifecycle of AI models approved for enterprise use. To secure autonomous coding environments, JFrog introduced the Universal MCP Registry and the Agent Skills Registry (developed alongside NVIDIA). These new solutions establish the industry’s first enterprise-grade trust layer to safely manage and store AI agent skills, monitor connections, and instantly block unsafe developer tools or malicious coding extensions right where developers work. Furthermore, the integration of advanced DevGovOps and Runtime Security tools allows teams to replace slow, manual compliance audits with continuous, background policy enforcement. By shifting security left directly into the binary pipeline, JFrog ensures that the volume of AI-assisted code does not outpace an organization's ability to verify its safety. Today, millions of users and approximately 6,600 organizations worldwide, including a majority of the Fortune 100, depend on the universal JFrog Platform to eliminate point-solution fatigue, bridge the governance gap, and securely embrace digital transformation. Learn more at www.jfrog.com or follow us on X @JFrog.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list&secure%5Bcategory_id%5D=1008169&secure%5Bchosen_at%5D=2026-07-28T21%3A57%3A08Z&secure%5Bdisplayable_resource_id%5D=1008169&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=page_category&secure%5Bplacement_resource_ids%5D%5B%5D=1008169&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=143017&secure%5Bresource_id%5D=1008169&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsoftware-bill-of-materials-sbom%2Ffree&secure%5Btoken%5D=39c89ce93c6e98ecbff3d7d79d2163a6eeabe280f684e642bebbcfe29d03f4ee&secure%5Burl%5D=https%3A%2F%2Fjfrog.com%2Fartifactory%2F%3Futm_source%3Dg2%26utm_medium%3Dcpc_social%26utm_campaign%3Dbrand_awareness_banner_ad%26utm_content%3Du-bin&secure%5Burl_type%5D=custom_url)

[
OX Security
](https://www.g2.com/products/ox-security/reviews)

By [OX Security](https://www.g2.com/sellers/ox-security)

[

4.8/5(51)

](https://www.g2.com/products/ox-security/reviews)

What do users say?

Users consistently praise the intuitive interface and seamless integration with existing tools, which simplify security management and enhance productivity. The platform's ability to provide comprehen

Pros and Cons

[
Features (8)
](https://www.g2.com/products/ox-security/reviews?qs=pros-and-cons)[
Complexity (5)
](https://www.g2.com/products/ox-security/reviews?qs=pros-and-cons)

### [OX Security](https://www.g2.com/products/ox-security/reviews)

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track. OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime. OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform. The platform runs on four connected pillars: OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data. OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence. OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production. OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance. OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact. For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice. Visit https://ox.security for more information.

**Average Rating:** 4.8/5.0

**Total Reviews:** 51

#### Who Is the Company Behind OX Security?

- **Seller:** [OX Security](https://www.g2.com/sellers/ox-security)
- **Year Founded:** 2021
- **HQ Location:** New York, USA
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ee8e1fc166aedd5d2f8edd57605f86ae8eec3007f5eee8810871f0e4645b4f4d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fox-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
199 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Engineer
- **Top Industries:** Financial Services, Information Technology and Services
- **Company Size:** 63% Medium, 25% Large

#### What Do G2 Reviewers Say About OX Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **intuitive dashboard and seamless integration** of OX Security, enhancing their security management and workflow efficiency.
- Users value the **seamless collaboration** enabled by OX Security, enhancing their focus on critical development tasks.
- Users commend the **responsive customer support** of OX Security, enhancing their overall operational efficiency and satisfaction.
- Users value the **seamless integrations** with existing tools, enhancing workflows and boosting overall development efficiency.
- Users appreciate the **speed** of OX Security, enabling faster remediation of vulnerabilities and cloud misconfigurations.

##### Cons

- Users find the **complexity** of OX Security daunting, facing a steep learning curve and inadequate documentation.
- Users find the **interface overwhelming** , with a steep learning curve and insufficient documentation to guide new users.
- Users find the **complex setup** challenging, especially due to inadequate documentation and overwhelming UI for new users.
- Users find the **executive dashboard limiting** , impacting effective reporting on product security enhancements to management.
- Users find OX Security's **difficult learning curve** challenging, particularly due to its complex interface and lacking documentation.

#### What Are Recent G2 Reviews of OX Security?

**["A powerful and comprehensive tool that meets most best practices for web app security testing"](https://www.g2.com/survey_responses/ox-security-review-10961361)**

**Rating:** 4.5/5.0 stars

_— Verified User in Gambling & Casinos_

[Read full review](https://www.g2.com/survey_responses/ox-security-review-10961361)

**["Holistic Security Solution with Seamless Integration"](https://www.g2.com/survey_responses/ox-security-review-10487561)**

**Rating:** 4.5/5.0 stars

_— Sharon S._

[Read full review](https://www.g2.com/survey_responses/ox-security-review-10487561)

[
Cybeats
](https://www.g2.com/products/cybeats/reviews)

By [CYBEATS](https://www.g2.com/sellers/cybeats)

[

4.4/5(15)

](https://www.g2.com/products/cybeats/reviews)

What do users say?

Users consistently praise the product for its great protection against cyber threats and its intuitive interface, which simplifies management and troubleshooting. Many appreciate the real-time alerts

### [Cybeats](https://www.g2.com/products/cybeats/reviews)

Cybeats is at the forefront of cybersecurity innovation and is focused explicitly on automating Software Bill of Materials (SBOM) and Vulnerability Exploitability eXchange (VEX) management. Our platform has built-in support for HBOM and AIBOM. Our mission is to empower organizations to rapidly identify and address vulnerabilities, significantly reducing costs while enhancing the security posture of their products. With our focus on the vision of "Building trust in every layer of your technology," Cybeats provides a robust platform that ensures transparency and security throughout the technological stack. Core Offerings - SBOM Management & Continuous Monitoring Cybeats offers a scalable solution for managing and monitoring SBOMs. Our platform stores enriches and distributes SBOMs efficiently across the organization and the organization's customers. This continuous monitoring helps proactively identify and mitigate software component risks. - SBOM Inventory & Management We provide a centralized system for SBOM inventory management that ensures all software components are accounted for, up-to-date, and secure. This systematic approach helps maintain a clear overview of all software elements, facilitating easier management and compliance. - Vulnerability Lifecycle Management (VLM) Our VLM capabilities integrate Vulnerability Exploitability Exchange (VEX) and Vulnerability Disclosure Program (VDP) processes. This integration helps identify, assess, manage, and mitigate vulnerabilities throughout their lifecycle, ensuring continuous protection against potential software supply chain threats. - Regulatory Compliance Cybeats aligns with global regulatory requirements, assisting organizations in staying compliant with evolving cybersecurity standards. Our solution simplifies compliance management, reducing the complexity and resources required to meet legal and industry standards. With the introduction of regulatory requirements of the FDA pre-market and post-market, the EU CRA, PCI-SSF, and others, companies that develop software-based products must align with the SBOM and Vulnerability management requirements. - OSS and Comercial Licensing Risk Assessment Understanding and managing licensing risks associated with software components is crucial. Cybeats provides tools to assess these risks, helping organizations avoid legal and financial repercussions related to software licensing. - SBOM Sharing and Exchange We facilitate secure sharing and exchange of SBOMs within and across organizations. This capability ensures that all parties in the software supply chain have access to accurate and timely information, enhancing collaborative efforts toward secure software development.

**Average Rating:** 4.4/5.0

**Total Reviews:** 15

#### Who Is the Company Behind Cybeats?

- **Seller:** [CYBEATS](https://www.g2.com/sellers/cybeats)
- **Year Founded:** 2017
- **HQ Location:** Toronto, Ontario
- **Twitter:** @cybeatstech  
616 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=2663143089be0432d313d1e538a94c0aa900c3536fc6ddc68eb338c35cf31f18&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcybeats%2F&secure%5Burl_type%5D=linkedin_company_website)  
32 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 47% Small, 33% Medium

#### What Are Recent G2 Reviews of Cybeats?

**["Great Computer Security Service Solutin"](https://www.g2.com/survey_responses/cybeats-review-7160083)**

**Rating:** 4.5/5.0 stars

_— Patrícia P._

[Read full review](https://www.g2.com/survey_responses/cybeats-review-7160083)

**["A safe and secure enterprise supply chain management system is created and enabled by Cybeats"](https://www.g2.com/survey_responses/cybeats-review-7468992)**

**Rating:** 4.5/5.0 stars

_— Karan C._

[Read full review](https://www.g2.com/survey_responses/cybeats-review-7468992)

[
Mend.io
](https://www.g2.com/products/mend-io/reviews)

By [Mend](https://www.g2.com/sellers/mend-ab79a83a-6747-4682-8072-a3c176489d0b)

[

4.3/5(116)

](https://www.g2.com/products/mend-io/reviews)

What do users say?

Users consistently praise the product for its ease of use and effective integration with CI/CD pipelines, which simplifies vulnerability management and dependency tracking. Many appreciate the compreh

Pros and Cons

[
Scanning Efficiency (8)
](https://www.g2.com/products/mend-io/reviews?qs=pros-and-cons)[
Integration Issues (6)
](https://www.g2.com/products/mend-io/reviews?qs=pros-and-cons)

### [Mend.io](https://www.g2.com/products/mend-io/reviews)

Modern risk doesn't live in one layer, it lives between them. Mend.io is built for every risk, across AI and AppSec, securing the code layer, the AI layer, and the interactions between them. From discovery and red teaming to guardrails and runtime protection, Mend.io delivers continuous protection across the entire AI application lifecycle. Mend.io solutions include: 1. Mend AI secures the layer where modern risk actually lives—the interaction between code and AI. It continuously discovers AI components (agents, prompts, models), tests real behavioral risk through automated red teaming, and enforces in-app runtime guardrails for one continuous control system for the AI lifecycle. 2. Mend AppSec secures the modern code layer by continuously discovering and prioritizing risk across code, libraries, containers, and dependencies, giving teams the clarity they need to reduce exposure and ship secure software faster. 3. Mend Renovate secures the foundation of every codebase by automatically updating dependencies, rating the likelihood each update will succeed without breaking changes, and grouping them by confidence level so teams can resolve them faster.

**Average Rating:** 4.3/5.0

**Total Reviews:** 110

#### Who Is the Company Behind Mend.io?

- **Seller:** [Mend](https://www.g2.com/sellers/mend-ab79a83a-6747-4682-8072-a3c176489d0b)
- **Company Website:** mend.io
- **Year Founded:** 2011
- **HQ Location:** Boston, Massachusetts
- **Twitter:** @Mend\_io  
11,256 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=041c6c79eefb0ef528e05bab57503847c90096672ecceb998f987d3daebef99a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2440656%2F&secure%5Burl_type%5D=linkedin_company_website)  
257 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 36% Small, 34% Medium

#### What Do G2 Reviewers Say About Mend.io?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **scanning efficiency** of Mend.io, appreciating its quick and accurate results across multiple repositories.
- Users appreciate the **ease of use** of Mend.io, highlighting simple integration and efficient navigation to find vulnerabilities.
- Users appreciate the **easy integrations** of Mend.io, enabling efficient scanning and streamlined workflows across multiple repositories.
- Users appreciate the **quick and accurate scanning** capabilities of Mend.io, enhancing their development workflow and security.
- Users commend the **excellent automated vulnerability detection** in Mend.io, enhancing efficiency in their CI/CD processes.

##### Cons

- Users struggle with **integration issues** , finding the setup process for tools like Jira and on-premise systems challenging.
- Users find **limited features** in Mend.io, struggling with functionality and integration challenges for various tools and cases.
- Users note that Mend.io lacks **essential features** , requiring additional tools and workarounds for effective integration.
- Users experience **complex implementation** with Mend.io, citing difficulties in integration and frequent false positives.
- Users find the **confusing interface** of Mend.io awkward, especially when switching between different product portals.

#### What Are Recent G2 Reviews of Mend.io?

**["Great Tool for Managing 3rd party libraries"](https://www.g2.com/survey_responses/mend-io-review-6728890)**

**Rating:** 4.5/5.0 stars

_— Johannes B._

[Read full review](https://www.g2.com/survey_responses/mend-io-review-6728890)

**["Effortless Integration with Budget-Friendly Scanning"](https://www.g2.com/survey_responses/mend-io-review-4261734)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/mend-io-review-4261734)

#### What Are G2 Users Discussing About Mend.io?

- [What is your experience regarding pricing and costs for Mend.io, and how does it compare to other open-source security solutions?](https://www.g2.com/discussions/what-is-your-experience-regarding-pricing-and-costs-for-mend-io-and-how-does-it-compare-to-other-open-source-security-solutions)
- [What is Mend (formerly WhiteSource) used for?](https://www.g2.com/discussions/what-is-mend-formerly-whitesource-used-for)
- [What is white Source bolt?](https://www.g2.com/discussions/what-is-white-source-bolt)
- [What are SCA tools?](https://www.g2.com/discussions/what-are-sca-tools)
- [What is software composition analysis SCA?](https://www.g2.com/discussions/what-is-software-composition-analysis-sca)

[
Arnica
](https://www.g2.com/products/arnica/reviews)

By [Arnica](https://www.g2.com/sellers/arnica)

[

4.9/5(8)

](https://www.g2.com/products/arnica/reviews)

Product Description

Arnica is a comprehensive application security posture management (ASPM) platform that protects developers, source code, and products throughout the software development lifecycle. The platform provid

Pros and Cons

[
Accuracy of Findings (1)
](https://www.g2.com/products/arnica/reviews?qs=pros-and-cons)[
Paid Features (1)
](https://www.g2.com/products/arnica/reviews?qs=pros-and-cons)

### [Arnica](https://www.g2.com/products/arnica/reviews)

Arnica is a comprehensive application security posture management (ASPM) platform that protects developers, source code, and products throughout the software development lifecycle. The platform provides real-time application security scanning with 100% coverage across the software supply chain, addressing risks in Static Application Security Testing (SAST), Software Composition Analysis (SCA), Infrastructure as Code (IaC), hardcoded secrets detection, and more. At its core, Arnica offers AI-native security governance that takes control of AI-generated code through advanced AI SAST scanning and agentic rules enforcement. The platform automatically injects centrally-controlled security requirements into AI coding agents like Copilot, Cursor, and Claude at the point of code generation, ensuring every line of AI-written code is secure by default before vulnerabilities reach production. This approach addresses 92% of risks before they ever reach production environments. Arnica's pipelineless architecture provides automatic coverage for every repository without requiring CI/CD pipeline integrations or IDE deployments. The platform scans every code change at the feature branch level, delivering developer-native workflows that keep teams focused on building features rather than chasing security issues. Risk prioritization is enhanced through OWASP Top 10, CVSS, EPSS, and KEV scoring, combined with organizational context to surface the most critical vulnerabilities. The platform excels in developer experience by delivering security findings directly within existing workflows through Slack, Microsoft Teams, pull request comments, and automated ticket management in Jira and Azure DevOps Boards. AI-powered mitigation suggestions provide context-aware, automated fixes that align with organizational coding standards, significantly reducing mean-time-to-remediation. Key security capabilities include real-time secrets detection with automatic validation and mitigation, comprehensive container scanning that maps vulnerabilities directly to source code, and intelligent dependency management with automated SCA upgrades. The platform maintains SOC 2 Type 2 compliance and ISO 27001 certification, ensuring enterprise-grade security standards. Arnica's unique value proposition lies in its ability to scale security across entire organizations while maintaining development velocity, providing complete visibility into code risks, and enabling proactive security measures that prevent vulnerabilities from reaching production environments.

**Average Rating:** 4.9/5.0

**Total Reviews:** 8

#### Who Is the Company Behind Arnica?

- **Seller:** [Arnica](https://www.g2.com/sellers/arnica)
- **Company Website:** www.arnica.io
- **Year Founded:** 2021
- **HQ Location:** Alpharetta, Georgia
- **Twitter:** @arnicaio  
124 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=35b6c80888a16d99de6aed67226d5eee0835f227fc79936eb37367fea6278187&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Farnica-io%2Fabout&secure%5Burl_type%5D=linkedin_company_website)  
60 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 63% Large, 25% Small

#### What Do G2 Reviewers Say About Arnica?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **accuracy of findings** from Arnica, which helps identify and minimize unnecessary elevated privileges.
- Users value the **actionable recommendations** provided by Arnica, facilitating effective management of elevated privileges in code repositories.
- Users love the **easy setup and administration** of Arnica, saving time while meeting their needs effectively.
- Users love the **easy setup** of Arnica, finding it quick and efficient for their needs.
- Users value Arnica for its ability to **simplify remediation of overprovisioning** and enhance security through effective privilege management.

##### Cons

- Users note that **paid features** in Arnica restrict access for smaller teams, limiting comprehensive protections.

#### What Are Recent G2 Reviews of Arnica?

**["Intuitive Dashboards and AI That Finds Real Issues"](https://www.g2.com/survey_responses/arnica-review-12972680)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/arnica-review-12972680)

**["Developer-friendly AppSec with a flexible policy engine"](https://www.g2.com/survey_responses/arnica-review-12962349)**

**Rating:** 5.0/5.0 stars

_— Thomas G._

[Read full review](https://www.g2.com/survey_responses/arnica-review-12962349)

#### What Are G2 Users Discussing About Arnica?

- [What is Arnica used for?](https://www.g2.com/discussions/what-is-arnica-used-for)

[
Socket
](https://www.g2.com/products/socket-socket/reviews)

By [Socket](https://www.g2.com/sellers/socket)

[

4.7/5(10)

](https://www.g2.com/products/socket-socket/reviews)

What do users say?

Users consistently praise Socket for its strong supply chain monitoring and developer-friendly design, which seamlessly integrates into existing workflows. The product is noted for providing reliable

Pros and Cons

[
Security (3)
](https://www.g2.com/products/socket-socket/reviews?qs=pros-and-cons)[
Missing Features (1)
](https://www.g2.com/products/socket-socket/reviews?qs=pros-and-cons)

### [Socket](https://www.g2.com/products/socket-socket/reviews)

Socket is the leading developer-first security platform that protects modern applications from malicious and vulnerable open source dependencies. By combining real-time package monitoring with AI-powered code analysis, Socket detects and blocks supply chain attacks within minutes of publication. With advanced reachability analysis, automated remediation, and license compliance features, Socket enables teams to focus on building software, while we keep their open source code secure.

**Average Rating:** 4.7/5.0

**Total Reviews:** 10

#### Who Is the Company Behind Socket?

- **Seller:** [Socket](https://www.g2.com/sellers/socket)
- **Year Founded:** 2020
- **HQ Location:** San Francisco, US
- **Twitter:** @SocketSecurity  
21,558 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=333fcd28dd311ff160a9395ac69327d82d0f595897ba65d2388e7b628c0687bf&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsocketinc%2F&secure%5Burl_type%5D=linkedin_company_website)  
115 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 40% Medium, 30% Large

#### What Do G2 Reviewers Say About Socket?

_AI-generated summary from verified user reviews_

##### Pros

- Users value Socket's **exceptional security features** , particularly in monitoring and mitigating supply chain attacks effectively.
- Users praise Socket for its **effective open source security analysis** , streamlining package reviews and enhancing reliability.
- Users value the **accuracy of findings** from Socket, appreciating the thorough analysis it offers for open source security.
- Users value the **proactive alerts** from Socket, ensuring quick responses to potential supply chain threats.
- Users value the **comprehensive security** features of Socket, enhancing decision-making and risk management in software supply chains.

##### Cons

- Users find the **missing features** in Socket limit its ability to consolidate multiple use cases effectively.
- Users report experiencing **system slowness** , particularly noting the UI's slow loading times impacting their overall experience.

#### What Are Recent G2 Reviews of Socket?

**["Unique Approach to Supply Chain Security Problem and Does It Really Well"](https://www.g2.com/survey_responses/socket-review-12052484)**

**Rating:** 5.0/5.0 stars

_— Sindhoor H._

[Read full review](https://www.g2.com/survey_responses/socket-review-12052484)

**["Essential Tool for Application Security with Stellar MCP Feature"](https://www.g2.com/survey_responses/socket-review-12686360)**

**Rating:** 5.0/5.0 stars

_— Shreejal M._

[Read full review](https://www.g2.com/survey_responses/socket-review-12686360)

[
SOOS
](https://www.g2.com/products/soos/reviews)

By [SOOS](https://www.g2.com/sellers/soos)

[

4.6/5(42)

](https://www.g2.com/products/soos/reviews)

What do users say?

Users consistently praise the product for its ease of use and reliable integration with development workflows, making vulnerability management straightforward. The intuitive dashboard and responsive s

Pros and Cons

[
Ease of Use (9)
](https://www.g2.com/products/soos/reviews?qs=pros-and-cons)[
Lack of Guidance (3)
](https://www.g2.com/products/soos/reviews?qs=pros-and-cons)

### [SOOS](https://www.g2.com/products/soos/reviews)

SOOS is the complete application security posture management platform. Scan your software for vulnerabilities, control the introduction of new dependencies, exclude unwanted license types, generate and manage Software Bill of Materials (SBOM), and fill out your compliance worksheets across all your teams. SOOS’s ASPM is a dynamic, comprehensive approach to safeguarding your application infrastructure from vulnerabilities across the Software Development Life Cycle (SDLC) and live deployments. Easy to integrate, all in one dashboard. SCA - Deep tree vulnerability scanning, license compliance, governance DAST - Automated Web & API vulnerability scanning Containers - Scan contents for vulnerabilities SAST - Analyze code for security vulnerabilities IaC - Cloud security coverage SBOMs - Create – monitor – manage

**Average Rating:** 4.6/5.0

**Total Reviews:** 42

#### Who Is the Company Behind SOOS?

- **Seller:** [SOOS](https://www.g2.com/sellers/soos)
- **Year Founded:** 2019
- **HQ Location:** Winooski, US
- **Twitter:** @soostech  
44 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=61bd56b45756b75fc0339880cc3369c6d2af3971839c773abcfbf38d4d05a283&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F53122310&secure%5Burl_type%5D=linkedin_company_website)  
24 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 50% Medium, 43% Small

#### What Do G2 Reviewers Say About SOOS?

_AI-generated summary from verified user reviews_

##### Pros

- Users find SOOS to be **easy to use** , benefiting from user-friendly configurations and excellent support.
- Users praise the **awesome customer support** from SooS, ensuring a smooth onboarding and configuration process.
- Users commend SOOS for its **easy integrations** , enabling seamless workflows and efficient vulnerability management in development.
- Users value the **seamless integrations** of SOOS, enhancing workflow efficiency and simplifying vulnerability management.
- Users find the **easy setup** of SOOS to be intuitive and efficient, enhancing their overall experience.

##### Cons

- Users note a **lack of guidance** in documentation and processes, hindering onboarding and remediation efforts.
- Users find the **poor reporting** of SOOS limits their ability to analyze vulnerabilities effectively across projects.
- Users find the **dashboard issues** frustrating, particularly with limited reporting and filtering options that hinder analysis.
- Users find SOOS lacks **adequate reporting** , needing better customization and filtering options for effective analysis.
- Users find the **lack of features** in SOOS limits usability, especially with reporting and intuitive navigation.

#### What Are Recent G2 Reviews of SOOS?

**["Awesome tool for detecting vulnerabilities within project dependecies"](https://www.g2.com/survey_responses/soos-review-7753830)**

**Rating:** 4.5/5.0 stars

_— Nayan C._

[Read full review](https://www.g2.com/survey_responses/soos-review-7753830)

**["Reliable continuous security assessment for our pipelines"](https://www.g2.com/survey_responses/soos-review-7744758)**

**Rating:** 4.0/5.0 stars

_— Brallan G._

[Read full review](https://www.g2.com/survey_responses/soos-review-7744758)

[
CAST Highlight
](https://www.g2.com/products/cast-highlight/reviews)

By [CAST](https://www.g2.com/sellers/cast)

[

4.5/5(91)

](https://www.g2.com/products/cast-highlight/reviews)

What do users say?

Users consistently praise the ease of use and speed of analysis provided by CAST Highlight, which allows for quick assessments of application portfolios regarding cloud readiness and software health.

Pros and Cons

[
Ease of Use (8)
](https://www.g2.com/products/cast-highlight/reviews?qs=pros-and-cons)[
Complex Navigation (1)
](https://www.g2.com/products/cast-highlight/reviews?qs=pros-and-cons)

### [CAST Highlight](https://www.g2.com/products/cast-highlight/reviews)

Portfolio-level insights for app modernization, AI readiness, tech debt, OSS risks CAST Highlight is a SaaS software intelligence technology that delivers rapid, fact-based insights across your entire application portfolio. By automatically analyzing the source code of hundreds or thousands of applications, CAST Highlight helps organizations assess cloud maturity, AI & Agentic readiness, software health, open source risk, resiliency, technical debt, and sustainability from a single lightweight scan. CAST Highlight is designed for CIOs, CTOs, enterprise architects, cloud leaders, application owners, security teams, and modernization teams that need a fact-based way to prioritize modernization, cloud, and AI adoption decisions at scale. It helps teams identify which applications are ready to move quickly, which require remediation, and where hidden software risks may affect transformation cost, timelines, security, resilience, or business outcomes. Unlike traditional manual or survey-based assessments, CAST Highlight analyzes application source code directly to rapidly segment portfolios, prioritize modernization paths, and uncover risks before they impact transformation programs. Organizations use CAST Highlight to: - Accelerate cloud migration and modernization planning - Segment applications by cloud maturity and transformation path - Identify high-value AI adoption opportunities - Assess Agentic Readiness across application portfolios - Prioritize technical debt, resiliency, and maintainability improvements - Assess open source vulnerabilities and IP / license exposure - Evaluate software sustainability with Green Impact insights - Reduce complexity, cost, and risk across transformation programs Businesses move faster using CAST to understand, improve, and transform their software. Through semantic analysis of source code, CAST generates dashboards and 3D maps for executives, technologists, and AI to navigate inside individual applications and across entire portfolios. This intelligence enables companies to steer, speed, and report on initiatives such as technical debt, modernization, and cloud. As the pioneer of the software intelligence field, CAST is trusted by the world’s leading companies and governments, their consultancies and cloud providers. See it all at castsoftware.com.

**Average Rating:** 4.5/5.0

**Total Reviews:** 86

#### Who Is the Company Behind CAST Highlight?

- **Seller:** [CAST](https://www.g2.com/sellers/cast)
- **Company Website:** www.castsoftware.com
- **Year Founded:** 1990
- **HQ Location:** New York
- **Twitter:** @SW\_Intelligence  
1,887 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0ce2f19bfa683d9d06fc56898a1568de05de4c4332e22f1fb046292c65ff44c9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcast%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,264 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 57% Large, 24% Small

#### What Do G2 Reviewers Say About CAST Highlight?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of CAST Highlight, allowing for quick and efficient application analysis without complications.
- Users find the **easy setup** of CAST Highlight to be straightforward and efficient, enhancing their analysis experience.
- Users value CAST Highlight for its **comprehensive cloud assessment capabilities** , aiding in application migration and risk analysis.
- Users value the **efficiency** of CAST Highlight, enabling quick, objective analysis of application portfolios for better decision-making.
- Users appreciate the **real-time monitoring** of CAST Highlight, enabling quick, actionable insights for effective portfolio management.

##### Cons

- Users find the **complex navigation** in CAST Highlight challenging, affecting their overall user experience and efficiency.
- Users find the **dashboard issues** in CAST Highlight hinder effective insights and require customization for better alignment.
- Users find the **delayed detection** of issues in CAST Highlight hinders timely responses and detailed analysis.
- Users find the **difficulty in initial configuration** and metric interpretation challenging for new teams utilizing CAST Highlight.
- The **high price** of CAST Highlight restricts its usage in large companies, limiting its potential impact.

#### What Are Recent G2 Reviews of CAST Highlight?

**["Efficient Analysis & Confident Modernization"](https://www.g2.com/survey_responses/cast-highlight-review-12250186)**

**Rating:** 4.5/5.0 stars

_— Neha C._

[Read full review](https://www.g2.com/survey_responses/cast-highlight-review-12250186)

**["Portfolio Insights in One Place with CAST Highlight"](https://www.g2.com/survey_responses/cast-highlight-review-12977472)**

**Rating:** 4.5/5.0 stars

_— Verified User in Government Administration_

[Read full review](https://www.g2.com/survey_responses/cast-highlight-review-12977472)

#### What Are G2 Users Discussing About CAST Highlight?

- [What is cast imaging?](https://www.g2.com/discussions/what-is-cast-imaging) - 1 comment
- [How does a cast tool work?](https://www.g2.com/discussions/how-does-a-cast-tool-work)
- [What is CAST software tool?](https://www.g2.com/discussions/what-is-cast-software-tool) - 1 comment
- [What does cast highlight do?](https://www.g2.com/discussions/what-does-cast-highlight-do) - 1 comment

[
JFrog
](https://www.g2.com/products/jfrog-2024-03-28/reviews)

By [JFrog Ltd](https://www.g2.com/sellers/jfrog-ltd)

[

4.2/5(155)

](https://www.g2.com/products/jfrog-2024-03-28/reviews)

What do users say?

Users consistently praise JFrog for its centralized artifact management and seamless integration with CI/CD tools, which significantly enhances deployment efficiency and reliability. The platform's ab

Pros and Cons

[
Features (18)
](https://www.g2.com/products/jfrog-2024-03-28/reviews?qs=pros-and-cons)[
Complexity (9)
](https://www.g2.com/products/jfrog-2024-03-28/reviews?qs=pros-and-cons)

### [JFrog](https://www.g2.com/products/jfrog-2024-03-28/reviews)

JFrog Ltd. (Nasdaq: FROG), the creators of the unified DevOps, DevSecOps, DevGovOps and MLOps platform, is on a mission to create a world of software delivered without friction from development to production. Driven by a “Liquid Software” vision to keep software continuously flowing, secure, and always up to date, the JFrog Platform serves as the definitive software supply chain system of record. It is uniquely engineered to power organizations as they build, manage, and distribute trusted software with unprecedented speed, security, and scale across hybrid and multi-cloud environments. As software engineering evolves in the AI era, JFrog’s newest offerings address the industry's most pressing trend: the rise of agentic software development and the hidden security risks of "Shadow AI." In response to threat actors increasingly targeting developer workflows including a massive surge in malicious open-source AI models and infected packages; JFrog has expanded its platform capabilities to deliver absolute end-to-end visibility and automated compliance. Key new innovations include the JFrog AI Catalog, which enables organizations to centralize, govern, and control the lifecycle of AI models approved for enterprise use. To secure autonomous coding environments, JFrog introduced the Universal MCP Registry and the Agent Skills Registry (developed alongside NVIDIA). These new solutions establish the industry’s first enterprise-grade trust layer to safely manage and store AI agent skills, monitor connections, and instantly block unsafe developer tools or malicious coding extensions right where developers work. Furthermore, the integration of advanced DevGovOps and Runtime Security tools allows teams to replace slow, manual compliance audits with continuous, background policy enforcement. By shifting security left directly into the binary pipeline, JFrog ensures that the volume of AI-assisted code does not outpace an organization's ability to verify its safety. Today, millions of users and approximately 6,600 organizations worldwide, including a majority of the Fortune 100, depend on the universal JFrog Platform to eliminate point-solution fatigue, bridge the governance gap, and securely embrace digital transformation. Learn more at www.jfrog.com or follow us on X @JFrog.

**Average Rating:** 4.2/5.0

**Total Reviews:** 149

#### Who Is the Company Behind JFrog?

- **Seller:** [JFrog Ltd](https://www.g2.com/sellers/jfrog-ltd)
- **Company Website:** jfrog.com
- **Year Founded:** 2008
- **HQ Location:** Sunnyvale, CA
- **Twitter:** @jfrog  
23,186 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9e9f01c1efeb3f3e7b4535b3aefc16344bbb21773bc11bf4ad186f193dbcaabf&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fjfrog-ltd%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,364 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, DevOps Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 50% Large, 31% Medium

#### What Do G2 Reviewers Say About JFrog?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **comprehensive integration and multi-format support** of JFrog, streamlining their DevOps processes effectively.
- Users appreciate JFrog's **centralized artifact management** , enhancing efficiency in storing and tracking components across environments.
- Users value the **seamless deployment integration** of JFrog, enhancing CI/CD pipelines and security management effectively.
- Users value the **seamless integrations** of JFrog, enhancing their CI/CD processes across various package formats.
- Users value the **easy integrations** of JFrog with various tools, enhancing their CI/CD workflows seamlessly.

##### Cons

- Users find JFrog's platform to be **overly complex** , requiring significant training to navigate its extensive features effectively.
- Users find JFrog to be **expensive** , with costs posing challenges for smaller teams and individual developers.
- Users often face a **steep learning curve** with JFrog, requiring significant time to master its complexity.
- Users find the **difficult learning curve** of JFrog requires extensive training to navigate its complex features effectively.
- Users find JFrog to have a **steep learning curve** , requiring significant time and effort to reach proficiency.

#### What Are Recent G2 Reviews of JFrog?

**["JFrog Simplifies Artifact Management for Organized, Reliable Deployments"](https://www.g2.com/survey_responses/jfrog-review-12870354)**

**Rating:** 4.5/5.0 stars

_— Subhashree S._

[Read full review](https://www.g2.com/survey_responses/jfrog-review-12870354)

**["Efficient, Scalable Artifact Management That Streamlines the Software Delivery Lifecycle"](https://www.g2.com/survey_responses/jfrog-review-12788318)**

**Rating:** 4.0/5.0 stars

_— Arkajit D._

[Read full review](https://www.g2.com/survey_responses/jfrog-review-12788318)

#### What Are G2 Users Discussing About JFrog?

- [What are the benefits and challenges of using JFrog for managing your software supply chain?](https://www.g2.com/discussions/what-are-the-benefits-and-challenges-of-using-jfrog-for-managing-your-software-supply-chain)
- [What does Jfrog Platform do?](https://www.g2.com/discussions/what-does-jfrog-platform-do)
- [What is difference between JFrog and Nexus?](https://www.g2.com/discussions/what-is-difference-between-jfrog-and-nexus)
- [What is Artifactory software used for?](https://www.g2.com/discussions/what-is-artifactory-software-used-for)

[
SonarQube
](https://www.g2.com/products/sonarqube/reviews)

By [SonarSource Sàrl](https://www.g2.com/sellers/sonarsource-sarl)

[

4.4/5(155)

](https://www.g2.com/products/sonarqube/reviews)

What do users say?

Users consistently praise SonarQube for its automated code quality checks and seamless CI/CD integration, which significantly enhance development workflows and reduce reliance on manual reviews. The t

Pros and Cons

[
Code Quality (24)
](https://www.g2.com/products/sonarqube/reviews?qs=pros-and-cons)[
Software Bugs (12)
](https://www.g2.com/products/sonarqube/reviews?qs=pros-and-cons)

### [SonarQube](https://www.g2.com/products/sonarqube/reviews)

Sonar, the industry standard for code verification and automated code review, helps reduce outages, improve security, and lower risks associated with AI and agentic coding. As an independent verification platform, Sonar enables organizations to securely develop at the speed of AI. Sonar is the foundation for high-performance software engineering, analyzing over 750 billion lines of code daily to ensure applications are secure, reliable, and maintainable. Rooted in the open source community, Sonar is trusted by 7M+ developers globally, including teams at ServiceNow, Booking.com, Deutsche Bank, AstraZeneca, and Ford Motor Company.

**Average Rating:** 4.4/5.0

**Total Reviews:** 153

#### Who Is the Company Behind SonarQube?

- **Seller:** [SonarSource Sàrl](https://www.g2.com/sellers/sonarsource-sarl)
- **Company Website:** www.sonarsource.com
- **Year Founded:** 2008
- **HQ Location:** Geneva, Switzerland
- **Twitter:** @SonarSource  
10,913 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=db9923720e09f3dbdd68fea8c4ab0318017f4eb0cfd2d4fd98e083108e7e8641&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsonarsource%2F&secure%5Burl_type%5D=linkedin_company_website)  
973 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** DevOps Engineer, Software Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 42% Large, 40% Medium

#### What Do G2 Reviewers Say About SonarQube?

_AI-generated summary from verified user reviews_

##### Pros

- Users value how SonarQube **efficiently flags code quality and security issues** , ensuring a clean and maintainable codebase.
- Users value the **issue filtering and prioritization features** of SonarQube, enhancing focus on high-priority tasks.
- Users value the **issue identification and prioritization** features of SonarQube, improving focus on critical tasks.
- Users find SonarQube's **ease of use** invaluable for maintaining code quality and integrating seamlessly into development workflows.
- Users appreciate the **easy integrations** with existing CI/CD tools, enhancing their development workflow seamlessly.

##### Cons

- Users face challenges with **software bugs** as SonarQube can consume excessive RAM and occasionally reports false positives.
- Users find SonarQube's configuration **complex** , especially for beginners, leading to difficulties and overwhelming warnings to manage.
- Users encounter **false positives** that complicate evaluations, though mitigation options exist through detailed analysis and rule customization.
- Users find that SonarQube's **complexity in configuration** and excessive warnings can hinder effective usage and efficiency.
- Users find the **complex setup** of SonarQube challenging, especially for beginners unfamiliar with the configuration process.

#### What Are Recent G2 Reviews of SonarQube?

**["SonarQube Makes Code Quality Clear with Strong Quality Gates and CI/CD Integration"](https://www.g2.com/survey_responses/sonarqube-review-13142666)**

**Rating:** 4.5/5.0 stars

_— Kishor G._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-13142666)

**["SonarQube: Easy Integration, Simple UI, and Solid Free Code Quality Scanning"](https://www.g2.com/survey_responses/sonarqube-review-12975264)**

**Rating:** 4.5/5.0 stars

_— Divyarajsinh C._

[Read full review](https://www.g2.com/survey_responses/sonarqube-review-12975264)

#### What Are G2 Users Discussing About SonarQube?

- [What is SonarLint used for?](https://www.g2.com/discussions/what-is-sonarlint-used-for)
- [What is SonarQube and how does it work?](https://www.g2.com/discussions/what-is-sonarqube-and-how-does-it-work) - 1 upvote
- [What is the benefit of SonarQube?](https://www.g2.com/discussions/what-is-the-benefit-of-sonarqube)
- [What are the main components of SonarQube platform?](https://www.g2.com/discussions/what-are-the-main-components-of-sonarqube-platform)
- [What is SonarQube and its features?](https://www.g2.com/discussions/what-is-sonarqube-and-its-features)

[
Xygeni
](https://www.g2.com/products/xygeni/reviews)

By [Xygeni Security](https://www.g2.com/sellers/xygeni-security)

[

4.6/5(5)

](https://www.g2.com/products/xygeni/reviews)

Product Description

Secure your Software Development and Delivery! Xygeni Security specializes in Application Security Posture Management (ASPM), using deep contextual insights to effectively prioritize and manage secur

Pros and Cons

[
Comprehensive Security (2)
](https://www.g2.com/products/xygeni/reviews?qs=pros-and-cons)[
Difficult Setup (1)
](https://www.g2.com/products/xygeni/reviews?qs=pros-and-cons)

### [Xygeni](https://www.g2.com/products/xygeni/reviews)

Secure your Software Development and Delivery! Xygeni Security specializes in Application Security Posture Management (ASPM), using deep contextual insights to effectively prioritize and manage security risks while minimizing noise and overwhelming alerts. Our innovative technologies automatically detect malicious code in real-time upon new and updated components publication, immediately notifying customers and quarantining affected components to prevent potential breaches. With extensive coverage spanning the entire Software Supply Chain—including Open Source components, CI/CD processes and infrastructure, Anomaly detection, Secret leakage, Infrastructure as Code (IaC), and Container security—Xygeni ensures robust protection for your software applications. Trust Xygeni to protect your operations and empower your team to build and deliver with integrity and security.

**Average Rating:** 4.6/5.0

**Total Reviews:** 4

#### Who Is the Company Behind Xygeni?

- **Seller:** [Xygeni Security](https://www.g2.com/sellers/xygeni-security)
- **Year Founded:** 2021
- **HQ Location:** Madrid, ES
- **Twitter:** @xygeni  
178 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0302db05d62f71019af9c96a9c2a81cfa4c370ac1ddef2c863b931a5bb7be15a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fxygeni%2F&secure%5Burl_type%5D=linkedin_company_website)  
30 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 60% Small, 40% Medium

#### What Do G2 Reviewers Say About Xygeni?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend Xygeni for its **comprehensive security features** , enhancing protection while maintaining efficient software development processes.
- Users value the **contextual risk prioritization** of Xygeni, enabling focus on the most critical security issues efficiently.
- Users value the **effective risk management** of Xygeni, ensuring security without hindering development speed.
- Users praise the **robust security features** of Xygeni, ensuring efficient vulnerability management and compliance throughout development.
- Users value the **seamless CI/CD integration** of Xygeni, enhancing security without hindering development speed.

##### Cons

- Users experience **difficult setup** with Xygeni due to manual adjustments needed for specific CI/CD configurations.
- Users find the **learning curve for first-time users** challenging, needing familiarity with AppSec best practices for deeper insights.

#### What Are Recent G2 Reviews of Xygeni?

**["The essential tool for proactive security and confident development"](https://www.g2.com/survey_responses/xygeni-review-11393516)**

**Rating:** 4.5/5.0 stars

_— Marcos C._

[Read full review](https://www.g2.com/survey_responses/xygeni-review-11393516)

**["Revolutionized Our Security Workflow with Unified, AI-Driven Efficiency"](https://www.g2.com/survey_responses/xygeni-review-11998435)**

**Rating:** 5.0/5.0 stars

_— Yerassyl K._

[Read full review](https://www.g2.com/survey_responses/xygeni-review-11998435)

[
CAST SBOM Manager
](https://www.g2.com/products/cast-sbom-manager/reviews)

By [CAST](https://www.g2.com/sellers/cast)

[

0/5(0)

](https://www.g2.com/products/cast-sbom-manager/reviews)

Product Description

CAST SBOM Manager enables users to automatically create, customize, and maintain Software Bill of Materials (SBOMs) with the ultimate level of control and flexibility. It detects open source dependenc

### [CAST SBOM Manager](https://www.g2.com/products/cast-sbom-manager/reviews)

CAST SBOM Manager enables users to automatically create, customize, and maintain Software Bill of Materials (SBOMs) with the ultimate level of control and flexibility. It detects open source dependencies and related risks (vulnerabilities and security advisories, licenses, obsolescence) directly from scanning source code, and allows you to create and maintain SBOM metadata over time (proprietary components, custom licenses, vulnerabilities) and much more.

#### Who Is the Company Behind CAST SBOM Manager?

- **Seller:** [CAST](https://www.g2.com/sellers/cast)
- **Year Founded:** 1990
- **HQ Location:** New York
- **Twitter:** @SW\_Intelligence  
1,887 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0ce2f19bfa683d9d06fc56898a1568de05de4c4332e22f1fb046292c65ff44c9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcast%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,264 employees on LinkedIn®
- **Ownership:** Bridgepoint

[
Eracent SBOM-HQ
](https://www.g2.com/products/eracent-sbom-hq/reviews)

By [Eracent](https://www.g2.com/sellers/eracent)

[

0/5(0)

](https://www.g2.com/products/eracent-sbom-hq/reviews)

Product Description

SBOM-HQ™ - from Eracent SBOM-HQ™ provides a well-rounded set of data, reporting and analysis features that help organizations minimize risks and comply with cyber mandates and directives. While

### [Eracent SBOM-HQ](https://www.g2.com/products/eracent-sbom-hq/reviews)

SBOM-HQ™ - from Eracent SBOM-HQ™ provides a well-rounded set of data, reporting and analysis features that help organizations minimize risks and comply with cyber mandates and directives. While SBOM-HQ™ provides value to in-house and commercial application development teams, it is also unique in its approach to meeting the requirements of organizations that purchase or subscribe to software from numerous publishers. These “software consumers” will have to manage dozens, hundreds, or even thousands of SBOMs for products that they use, and this is impractical or impossible to do one SBOM at a time. SBOM-HQ™ is based around a centralized, single-source repository of libraries, components, and other related data from SBOMs. It dramatically reduces response time when a vulnerability is reported since it eliminates the need to review SBOMs individually. How does SBOM-HQ™ work? Customers upload their SBOM files via the user interface. During this straightforward process, users can assign related information that can be used to support reporting, filters, data access, and more. This information includes Publisher, Line of Business, Application Component, and more. SBOM-HQ™ “deconstructs” each uploaded SBOM and records the software product to which the SBOM belongs and all the SBOM’s content. This results in an index of components and libraries mapped to products. If a vulnerability is reported by NIST or another organization, customers get an immediate report of every product in use in their organization that includes the affected component or library. SBOM-HQ™ is continuously monitored and updated, and it leverages vulnerability data from NIST and other trusted global sources. It uses this data to display risk scores, levels of criticality, and more. SBOM-HQ™ also provides visibility into license types for each component and library, reducing the risk of unknowingly using a library that has excessive restrictions when less risky options are available. The system offers version tracking – the version in use, newer available versions, and version history – as well as lifecycle dates that support obsolescence management. The dedicated open source library within Eracent’s IT-Pedia® product data library provides a solid foundation for SBOM-HQ™’s analysis and reporting. Who can benefit from using SBOM-HQ? SBOM-HQ is designed to support all teams engaged in the use and operation of software. DevOps – SBOM-HQ integrates into CI/CD to generate and enrich SBOMs with real time risk data, ensuring secure and compliant releases. Procurement – SBOM-HQ equips procurement teams with SBOM-driven insights into software quality and licensing risks, enabling smarter vendor selection and safer software purchases. CyberSec teams – SBOM-HQ evaluates cyber security aspects of purchased software and monitors new vulnerabilities that appear. ITOps – SBOM-HQ exposes software weaknesses and helps mitigate the risks. Legal and Licensing teams – SBOM-HQ delivers clear visibility into open source licenses, flags conflicts early, and provides audit-ready compliance reports. Why SBOM-HQ? SBOM-HQ is designed to support software buyers and users, not just software publishers. While most SBOM solutions stop at the software development life cycle, SBOM-HQ goes further. It empowers software consumers to continuously monitor not only what they build, but also what they buy - from design and procurement, through integration, all the way to production in their own data centers. With SBOM-HQ, transparency extends beyond development, delivering visibility and control across the entire software supply chain. To learn more about SBOM-HQ™, register for a free trial at sbomhq.com or contact Eracent today!

#### Who Is the Company Behind Eracent SBOM-HQ?

- **Seller:** [Eracent](https://www.g2.com/sellers/eracent)
- **Year Founded:** 2000
- **HQ Location:** Riegelsville, Pennsylvania
- **Twitter:** @eracent  
141 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=061a86884957635bea8a86590cc6a3e69ada768cfe44044151ae7d03f750a122&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F15155&secure%5Burl_type%5D=linkedin_company_website)  
70 employees on LinkedIn®

[
FOSSA
](https://www.g2.com/products/fossa/reviews)

By [FOSSA](https://www.g2.com/sellers/fossa)

[

4.2/5(15)

](https://www.g2.com/products/fossa/reviews)

What do users say?

Users consistently praise FOSSA for its ease of use and comprehensive evaluations of open-source licensing and security issues. The product effectively integrates with various CI/CD platforms, allowin

Pros and Cons

[
Easy Integrations (1)
](https://www.g2.com/products/fossa/reviews?qs=pros-and-cons)

### [FOSSA](https://www.g2.com/products/fossa/reviews)

Open source is a critical part of your software. In the average modern software product, over 80% of the source code shipped is derived from open source. Each component can have cascading legal, security, and quality implications for your customers, making it one of the most important things to manage correctly. FOSSA helps you manage your open source components. We plug into your development workflow to help your team automatically track, manage, and remediate issues with the open source you use to: - Stay compliant with software licenses and generate required attribution documents - Enforce usage and licensing policies throughout your CI/CD workflow - Monitor and remediate security vulnerabilities - Flag code quality issues and outdated components proactively By enabling open source, we help development teams increase development velocity and decrease risk.

**Average Rating:** 4.2/5.0

**Total Reviews:** 15

#### Who Is the Company Behind FOSSA?

- **Seller:** [FOSSA](https://www.g2.com/sellers/fossa)
- **Year Founded:** 2015
- **HQ Location:** San Francisco, California
- **Twitter:** @getfossa  
774 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=00194647467978e04baaa89e8e6cbe7c0e0a4d673296571deb5ed1510ffbe675&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ffossa%2F&secure%5Burl_type%5D=linkedin_company_website)  
59 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 47% Small, 33% Medium

#### What Do G2 Reviewers Say About FOSSA?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **easy integrations** of FOSSA, seamlessly working with Maven and Gardle in their pipelines.
- Users benefit from Fossa's **effective issue resolution** , identifying vulnerabilities and recommending fixes for library dependencies.
- Users value the **effective remediation solutions** of FOSSA, which identify and suggest fixes for vulnerabilities in applications.
- Users value FOSSA for its **effective risk management** , identifying library issues and recommending fixes swiftly.
- Users value FOSSA's **security insights** that identify vulnerabilities and recommend fixes for their applications.

#### What Are Recent G2 Reviews of FOSSA?

**["Fossa for enterprise applications"](https://www.g2.com/survey_responses/fossa-review-10931000)**

**Rating:** 4.0/5.0 stars

_— Pavan Kumar G._

[Read full review](https://www.g2.com/survey_responses/fossa-review-10931000)

**[""The FOSSA Experience""](https://www.g2.com/survey_responses/fossa-review-8576931)**

**Rating:** 5.0/5.0 stars

_— Elvis M._

[Read full review](https://www.g2.com/survey_responses/fossa-review-8576931)

[
Heeler
](https://www.g2.com/products/heeler/reviews)

By [Heeler Security](https://www.g2.com/sellers/heeler-security)

[

0/5(0)

](https://www.g2.com/products/heeler/reviews)

Product Description

Heeler empowers application security teams to shift left with the context they need to reduce noise, accelerate remediation, and move beyond traditional vulnerability management. By combining ASPM, SC

### [Heeler](https://www.g2.com/products/heeler/reviews)

Heeler empowers application security teams to shift left with the context they need to reduce noise, accelerate remediation, and move beyond traditional vulnerability management. By combining ASPM, SCA with static and runtime context, and runtime threat modeling, Heeler transforms AppSec programs from reactive firefighting to proactive, scalable security. How Heeler Helps AppSec Teams • Reduce Noise: AppSec teams and developers are drowning in findings. Heeler delivers unified code, runtime, business and security context, reducing alert noise by up to 95%, so teams can focus on critical issues and fix what matters most. • Fix Remediation: Remediation is broken. Most effort is spent reaching a fix—not implementing it. Heeler automates the remediation lifecycle, cutting effort and time, enabling AppSec teams to scale alongside engineering. • Move Beyond Vulnerabilities: With Heeler, continuous runtime threat modeling becomes a reality. Decompose running applications, track changes, compare deployments, and stop risks in real time—all before they reach production. Why Heeler is Essential Modern applications are more complex and dynamic than ever, expanding attack surfaces and making end-to-end security modeling nearly impossible without the right tools. Heeler bridges this gap, addressing the root causes of unscalable AppSec programs: • Lack of Context: Disparate data silos make understanding application behavior and identifying risks challenging. • Labor-Intensive Processes: Without unified context, security efforts are manual, unscalable, and push risk identification too far right. • Firefighting Mode: Security and engineering teams are trapped addressing too many findings and often focus their time on the wrong threats, leaving no bandwidth for secure-by-design initiatives. Key Capabilities • ProductDNA (Unified Context): Automates a real-time service catalog, mapping changesets to deployments and modeling every service with integrated code, runtime, business, and security context. • Runtime Threat Modeling: Enables continuous threat modeling with tools to decompose applications, track changes, compare deployments, and uncover risks in real time. • ASPM: Heeler reduces alert noise by up to 95% and automates remediation workflows, scaling security seamlessly with engineering demands. • SCA with Static and Runtime Context: Combines static and runtime data with business and deployment context, delivering next-gen SCA that prioritizes what matters, strengthens security, and simplifies AppSec workflows. Heeler ensures AppSec teams and developers have the context they need to shift left and build secure-by-design applications—effortlessly.

#### Who Is the Company Behind Heeler?

- **Seller:** [Heeler Security](https://www.g2.com/sellers/heeler-security)
- **Year Founded:** 2023
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a1a68756cf4887b6fb99c645e3d205020401407b871bdb78a3753c9ca3752015&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fheeler-security&secure%5Burl_type%5D=linkedin_company_website)  
20 employees on LinkedIn®

[
MergeBase
](https://www.g2.com/products/mergebase/reviews)

By [MergeBase Software](https://www.g2.com/sellers/mergebase-software)

[

4.5/5(20)

](https://www.g2.com/products/mergebase/reviews)

What do users say?

Users consistently praise MergeBase for its ease of use and ability to provide real-time warnings about vulnerabilities, which enhances security during the development process. The platform is valued

### [MergeBase](https://www.g2.com/products/mergebase/reviews)

MergeBase is revolutionizing software supply chain protection with a full-featured, developer-oriented SCA solution that brings the lowest false positives in the industry and complete DevOps coverage from coding/building to deployment and run-time. MergeBase’s SCA tool analyzes the open-source/third-party libraries for vulnerabilities. Our mission is to protect the software supply chain. We provide a full-featured, developer-oriented solution that has the industry’s lowest false positive rates and complete coverage of the DevOps process.

**Average Rating:** 4.5/5.0

**Total Reviews:** 20

#### Who Is the Company Behind MergeBase?

- **Seller:** [MergeBase Software](https://www.g2.com/sellers/mergebase-software)
- **Year Founded:** 2018
- **HQ Location:** Coquitlam, British Columbia
- **Twitter:** @mergebasesecure  
86 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=69ee19fad389ad4f98212a51bf0a5efb0b41c459dc4f4e8ece60f23d0d5ab74b&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fmergebase%2F&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software
- **Company Size:** 40% Small, 35% Medium

#### What Are Recent G2 Reviews of MergeBase?

**["MergeBase Detector of risk and vulnerabilities"](https://www.g2.com/survey_responses/mergebase-review-7833957)**

**Rating:** 4.5/5.0 stars

_— Prashant S._

[Read full review](https://www.g2.com/survey_responses/mergebase-review-7833957)

**["Revolutionizing Software Supply Chain Protection with MergeBase's SCA Platform"](https://www.g2.com/survey_responses/mergebase-review-7670163)**

**Rating:** 5.0/5.0 stars

_— Disha K._

[Read full review](https://www.g2.com/survey_responses/mergebase-review-7670163)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/software-bill-of-materials-sbom/free?order=popular&page=2#product-list)
- [Next &rsaquo;Next ›](/categories/software-bill-of-materials-sbom/free?order=popular&page=2#product-list)

Spotlight Categories

[Customer Success Software](https://www.g2.com/categories/customer-success)

[Remote Monitoring & Management (RMM) Software](https://www.g2.com/categories/remote-monitoring-management-rmm)

[Lead Intelligence Software](https://www.g2.com/categories/lead-intelligence)

[Event Management Platforms](https://www.g2.com/categories/event-management-platforms)

[Robotic Process Automation (RPA) Software](https://www.g2.com/categories/robotic-process-automation-rpa)

Similar Categories

- [Static Code Analysis](/categories/static-code-analysis)
- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)

- [Log Analysis](/categories/log-analysis)
- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Software Bill of Materials (SBOM) Themes](/categories/software-bill-of-materials-sbom/themes)