# Best Software Composition Analysis Tools

## How Many Software Composition Analysis Tools Products Does G2 Track?

**Total Products under this Category:** 75

### Category Stats (Aug 2026)

- **Average Rating:** 4.49/5 (↑0.01 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Finite State (+3.17%) - Among all products in this category, Finite State recorded the largest rating increase compared to last month

_Last updated: August 06, 2026_

## How Does G2 Rank Software Composition Analysis Tools Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 6,500+ Authentic Reviews
- 75+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Software Composition Analysis Tools
 ![G2 Grid® for Software Composition Analysis Tools plotting products by satisfaction and market presence](https://www.g2.com/categories/software-composition-analysis/grids.png?focus%5B%5D=146504&focus%5B%5D=1392&focus%5B%5D=1259627&focus%5B%5D=14032&focus%5B%5D=56950&focus%5B%5D=36094&focus%5B%5D=19003&focus%5B%5D=1225549)

Highlighted products: Wiz, GitHub, Aikido Security, Mend.io, DigiCert ONE, Snyk, GitLab, and Semgrep.

Underlying data: [Grid® JSON](https://www.g2.com/categories/software-composition-analysis/grids.json?focus%5B%5D=wiz-wiz&focus%5B%5D=github&focus%5B%5D=aikido-security&focus%5B%5D=mend-io&focus%5B%5D=digicert-one&focus%5B%5D=snyk&focus%5B%5D=gitlab&focus%5B%5D=semgrep)

**Sponsored**

### IPinfo

IPinfo is a comprehensive IP data provider for high-confidence, accurate, low down-time, low-latency, easy-to-use, and highly-contextual data about IP addresses backed by a proprietary ground-truth measurement infrastructure. IPinfo specializes in delivering detailed IP Data, including IP to geolocation, IP to mobile carrier information, IP to privacy detection, IP to proxy identification, and more. By leveraging this data, businesses and developers can enrich their data, improve their product, enhance their decision-making processes, improve security measures, and ensure compliance with regulatory standards. The target audience for IPinfo spans a wide range of users, from individual developers to large enterprises, including Fortune 500 companies. These users rely on IP data for various applications, such as fraud prevention, targeted marketing, and customer experience optimization. With the increasing importance of data-driven insights in today’s digital landscape, IPinfo serves as a vital resource for organizations looking to harness the power of IP intelligence. One of the standout features of IPinfo is its robust API, which processes over 1 billion requests daily. This high volume of data requests demonstrates the platform's reliability and scalability, making it suitable for businesses of all sizes. Additionally, users can access data through direct downloads and leading cloud platforms, ensuring flexibility in how they integrate IP information into their systems. The platform is backed by a dedicated team of data experts who prioritize accuracy and precision, further enhancing the value of the service. IPinfo’s key features include real-time IP geolocation, which allows users to pinpoint the physical location of an IP address, and mobile carrier identification, which helps businesses understand the network providers their users are utilizing. Our data also offers privacy detection capabilities, enabling organizations to identify potential risks associated with anonymous browsing or proxy usage. These features collectively empower users to make informed decisions, mitigate security threats, and tailor their services to meet the needs of their customers effectively. By providing highly contextual and accurate IP data, IPinfo stands out in its category as a trusted partner for organizations seeking to leverage internet intelligence. Our data not only enhances operational efficiency but also plays a crucial role in shaping better customer interactions and experiences.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=2041&secure%5Bchosen_at%5D=2026-08-07T01%3A49%3A01Z&secure%5Bdisplayable_resource_id%5D=494&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=retargeted_product&secure%5Bplacement_resource_ids%5D%5B%5D=100459&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=100459&secure%5Bresource_id%5D=2041&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsoftware-composition-analysis&secure%5Btoken%5D=740437e8f6e2c6c12605be5e4f7786ecf8c9b6db8a5d57a3871dcf3669ead6bd&secure%5Burl%5D=https%3A%2F%2Fipinfo.io%2Fproducts%3Futm_source%3Dg2%26utm_medium%3Dpaidreview%26utm_campaign%3Dg2_clicks&secure%5Burl_type%5D=custom_url)

### [Wiz](https://www.g2.com/products/wiz-wiz/reviews)

Wiz transforms cloud security for customers – including more than 50% of the Fortune 100 – by enabling a new operating model. With Wiz, organizations can democratize security across the development lifecycle, empowering them to build fast and securely. Its Cloud Native Application Protection Platform (CNAPP) consolidates CSPM, KSPM, CWPP, Vulnerability management, IaC scanning, CIEM, DSPM into a single platform. Wiz drives visibility, risk prioritization, and business agility. Protecting Your Cloud Environments Requires a Unified, Cloud Native Platform. Wiz connects to every cloud environment, scans every layer, and covers every aspect of your cloud security - including elements that normally require installing agents. Its comprehensive approach has all of these cloud security solutions built in. Hundreds of organizations worldwide, including 50 percent of the Fortune 100, to rapidly identify and remove critical risks in cloud environments. Its customers include Salesforce, Slack, Mars, BMW, Avery Dennison, Priceline, Cushman & Wakefield, DocuSign, Plaid, and Agoda, among others. Wiz is backed by Sequoia, Index Ventures, Insight Partners, Salesforce, Blackstone, Advent, Greenoaks, Lightspeed and Aglaé. Visit https://www.wiz.io for more information.

**Average Rating:** 4.7/5.0

**Total Reviews:** 836

#### How Do G2 Users Rate Wiz?

- **Quality of Support:** 9.2/10 (Category avg: 9.0/10)
- **Language Support:** 8.8/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 9.2/10 (Category avg: 8.7/10)
- **Integration:** 9.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Wiz?

- **Seller:** [Wiz](https://www.g2.com/sellers/wiz-76a0133b-42e5-454e-b5da-860e503471db)
- **Company Website:** www.wiz.io
- **Year Founded:** 2020
- **HQ Location:** New York, US
- **Twitter:** @wiz\_io  
24,733 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fc8f5e9bf3787dc70dd506314d2a37e0cc0ea32fb3ecf53e678c506b7e53eff0&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fwizsecurity%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,383 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** CISO, Security Engineer
- **Top Industries:** Financial Services, Computer Software
- **Company Size:** 53% Large, 39% Medium

#### What Do G2 Reviewers Say About Wiz?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend the **capable APIs and user-friendly UI** , providing valuable insights and continuous improvements in security features.
- Users value the **unmatched security features** of Wiz, providing comprehensive visibility and proactive threat management capabilities.
- Users find Wiz's product suite **extremely easy to use** , benefiting from seamless integration and a user-friendly interface.
- Users appreciate the **visibility** Wiz offers, enhancing security posture and prioritizing critical vulnerabilities effectively.
- Users praise the **easy setup** of Wiz, enabling quick deployment and seamless integration across modules for enhanced security.

##### Cons

- Users experience a **steep learning curve** with Wiz, making it challenging for newcomers to fully utilize the platform.
- Users find the **feature limitations** of Wiz, such as complex reporting and management, hinder user-friendliness and efficiency.
- Users highlight the need for **improvement in performance and reporting capabilities** to enhance overall usability of Wiz.
- Users note several **improvements needed** , particularly in dashboard reporting and the complexity of the pricing model.
- Users find the **complexity of the interface** overwhelming initially, requiring time to adapt and learn effectively.

#### What Are Recent G2 Reviews of Wiz?

**["Unmatched Security Insights, Excellent Reporting, and Strong Post-Sales Support"](https://www.g2.com/survey_responses/wiz-review-13153618)**

**Rating:** 5.0/5.0 stars

_— Alastair J._

[Read full review](https://www.g2.com/survey_responses/wiz-review-13153618)

**["Excellent Cloud Risk Visibility and Fast Insights with Wiz"](https://www.g2.com/survey_responses/wiz-review-12964571)**

**Rating:** 4.5/5.0 stars

_— Ruben F._

[Read full review](https://www.g2.com/survey_responses/wiz-review-12964571)

### [GitHub](https://www.g2.com/products/github/reviews)

GitHub is where the world builds software. Millions of individuals, organizations and businesses around the world use GitHub to discover, share, and contribute software. Developers at startups to Fortune 50 companies use GitHub, every step of the way.

**Average Rating:** 4.7/5.0

**Total Reviews:** 2,332

#### How Do G2 Users Rate GitHub?

- **Quality of Support:** 8.7/10 (Category avg: 9.0/10)
- **Language Support:** 8.8/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 9.0/10 (Category avg: 8.7/10)
- **Integration:** 9.0/10 (Category avg: 8.8/10)

#### Who Is the Company Behind GitHub?

- **Seller:** [GitHub](https://www.g2.com/sellers/github)
- **Year Founded:** 2008
- **HQ Location:** San Francisco, CA
- **Twitter:** @github  
2,673,925 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=c06a67fd698737e0e0058dd8a6726d5e9af42b7ce88417153ae8028eed3914af&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1418841%2F&secure%5Burl_type%5D=linkedin_company_website)  
6,653 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 47% Small, 31% Medium

#### What Do G2 Reviewers Say About GitHub?

_AI-generated summary from verified user reviews_

##### Pros

- Users value **exceptional collaboration and version control** features, making GitHub essential for code tracking and development.
- Users value the **ease of use** that GitHub offers, enhancing collaboration and version control effortlessly.
- Users value the **seamless team collaboration** on GitHub, enhancing project transparency and workflow automation effectively.
- Users value the **seamless collaboration** GitHub offers, enabling efficient teamwork and project transparency for developers.
- Users value the **seamless version control** in GitHub, enhancing collaboration and simplifying code management throughout projects.

##### Cons

- Users find the **learning curve and complexity** of advanced features like GitHub Actions challenging for newcomers.
- Users find the **learning curve steep** , facing challenges with complexity and configuration in GitHub Actions.
- Users find the **learning difficulty** of GitHub challenging, especially for beginners unfamiliar with Git workflows.
- Users find the **complexity for beginners** challenging, especially with CI/CD workflows and permission management in GitHub.
- Users find the **steep learning curve** of GitHub challenging, especially when configuring workflows and managing permissions.

#### What Are Recent G2 Reviews of GitHub?

**["GitHub Makes Code Management and Collaboration Effortless"](https://www.g2.com/survey_responses/github-review-13209123)**

**Rating:** 5.0/5.0 stars

_— NEET ._

[Read full review](https://www.g2.com/survey_responses/github-review-13209123)

**["Essential Version Control and Collaboration for Building CanniComply"](https://www.g2.com/survey_responses/github-review-13193636)**

**Rating:** 5.0/5.0 stars

_— Wayne D._

[Read full review](https://www.g2.com/survey_responses/github-review-13193636)

#### What Are G2 Users Discussing About GitHub?

- [How is GitHub shaping the landscape of collaborative software development and version control?](https://www.g2.com/discussions/how-is-github-shaping-the-landscape-of-collaborative-software-development-and-version-control) - 4 comments
- [What is GitHub used for?](https://www.g2.com/discussions/what-is-github-used-for) - 9 comments, 5 upvotes
- [What does GitHub mean?](https://www.g2.com/discussions/what-does-github-mean) - 2 comments
- [Is GitHub a CASE tool?](https://www.g2.com/discussions/is-github-a-case-tool)
- [What can GitHub be used for?](https://www.g2.com/discussions/what-can-github-be-used-for) - 5 comments

### [Aikido Security](https://www.g2.com/products/aikido-security/reviews)

Aikido Security is the developer-first security platform that unifies code, cloud, protection, and attack testing in one suite of best-in-class products. Built by developers for developers, Aikido helps teams of any size ship secure software faster, automate protection, and simulate real-world attacks with AI-driven precision. The platform’s proprietary AI cuts noise by 95%, delivers one-click fixes, and saves developers 10+ hours per week. Aikido Intel proactively uncovers vulnerabilities in open source packages before disclosure, helping secure more than 50,000 organizations worldwide, including Revolut, Niantic, Visma, Montblanc, and GoCardless.

**Average Rating:** 4.6/5.0

**Total Reviews:** 255

#### How Do G2 Users Rate Aikido Security?

- **Quality of Support:** 9.2/10 (Category avg: 9.0/10)
- **Language Support:** 9.0/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 9.0/10 (Category avg: 8.7/10)
- **Integration:** 9.1/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Aikido Security?

- **Seller:** [Aikido Security](https://www.g2.com/sellers/aikido-security)
- **Company Website:** aikido.dev
- **Year Founded:** 2022
- **HQ Location:** Ghent, Belgium
- **Twitter:** @AikidoSecurity  
11,770 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=79406802efc597500b142b19f023ee80eb82879906d7e1e458900293346529a9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Faikido-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
241 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Founder, CTO
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 80% Small, 13% Medium

#### What Do G2 Reviewers Say About Aikido Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Aikido Security, benefiting from its clear, actionable insights and seamless integration.
- Users praise Aikido Security for its **fast and user-friendly identification of security issues** in codebases, enhancing development practices.
- Users appreciate the **robust features of Aikido Security** , valuing its usability and effectiveness in enhancing security workflows.
- Users value the **easy integrations** with GitLab, allowing for quick start and effective tracking of security issues.
- Users commend the **easy setup** of Aikido Security, simplifying integration and enhancing their security workflow significantly.

##### Cons

- Users note the **missing features** in Aikido Security, wishing for more integration and advanced configuration options.
- Users find the **pricing excessive** , particularly for startups, despite acknowledging the product's value.
- Users find Aikido Security has **limited features** , particularly in advanced customization and reporting for complex environments.
- Users find the **entry-level pricing** of Aikido Security too high for startups, limiting adoption and experimentation.
- Users are frustrated by the **lack of features** , especially with local scanning and branch handling limitations.

#### What Are Recent G2 Reviews of Aikido Security?

**["Seamless GitHub Integration with Solid Security Findings and Smart False-Positive Analysis"](https://www.g2.com/survey_responses/aikido-security-review-13109689)**

**Rating:** 4.5/5.0 stars

_— Jordan B._

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13109689)

**["Enterprise Security Without an Enterprise Security Team"](https://www.g2.com/survey_responses/aikido-security-review-13108704)**

**Rating:** 4.0/5.0 stars

_— Ian M._

[Read full review](https://www.g2.com/survey_responses/aikido-security-review-13108704)

### [Mend.io](https://www.g2.com/products/mend-io/reviews)

Modern risk doesn't live in one layer, it lives between them. Mend.io is built for every risk, across AI and AppSec, securing the code layer, the AI layer, and the interactions between them. From discovery and red teaming to guardrails and runtime protection, Mend.io delivers continuous protection across the entire AI application lifecycle. Mend.io solutions include: 1. Mend AI secures the layer where modern risk actually lives—the interaction between code and AI. It continuously discovers AI components (agents, prompts, models), tests real behavioral risk through automated red teaming, and enforces in-app runtime guardrails for one continuous control system for the AI lifecycle. 2. Mend AppSec secures the modern code layer by continuously discovering and prioritizing risk across code, libraries, containers, and dependencies, giving teams the clarity they need to reduce exposure and ship secure software faster. 3. Mend Renovate secures the foundation of every codebase by automatically updating dependencies, rating the likelihood each update will succeed without breaking changes, and grouping them by confidence level so teams can resolve them faster.

**Average Rating:** 4.3/5.0

**Total Reviews:** 116

#### How Do G2 Users Rate Mend.io?

- **Quality of Support:** 8.7/10 (Category avg: 9.0/10)
- **Language Support:** 8.5/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 8.8/10 (Category avg: 8.7/10)
- **Integration:** 8.7/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Mend.io?

- **Seller:** [Mend](https://www.g2.com/sellers/mend-ab79a83a-6747-4682-8072-a3c176489d0b)
- **Company Website:** mend.io
- **Year Founded:** 2011
- **HQ Location:** Boston, Massachusetts
- **Twitter:** @Mend\_io  
11,256 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=041c6c79eefb0ef528e05bab57503847c90096672ecceb998f987d3daebef99a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2440656%2F&secure%5Burl_type%5D=linkedin_company_website)  
259 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 35% Small, 33% Large

#### What Do G2 Reviewers Say About Mend.io?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **scanning efficiency** of Mend.io, appreciating its quick and accurate results across multiple repositories.
- Users appreciate the **ease of use** of Mend.io, highlighting simple integration and efficient navigation to find vulnerabilities.
- Users appreciate the **easy integrations** of Mend.io, enabling efficient scanning and streamlined workflows across multiple repositories.
- Users appreciate the **quick and accurate scanning** capabilities of Mend.io, enhancing their development workflow and security.
- Users commend the **excellent automated vulnerability detection** in Mend.io, enhancing efficiency in their CI/CD processes.

##### Cons

- Users struggle with **integration issues** , finding the setup process for tools like Jira and on-premise systems challenging.
- Users find **limited features** in Mend.io, struggling with functionality and integration challenges for various tools and cases.
- Users note that Mend.io lacks **essential features** , requiring additional tools and workarounds for effective integration.
- Users experience **complex implementation** with Mend.io, citing difficulties in integration and frequent false positives.
- Users find the **confusing interface** of Mend.io awkward, especially when switching between different product portals.

#### What Are Recent G2 Reviews of Mend.io?

**["Mend.io Makes Vulnerability Scanning and Prioritization Easy"](https://www.g2.com/survey_responses/mend-io-review-13187391)**

**Rating:** 4.5/5.0 stars

_— Ratna P._

[Read full review](https://www.g2.com/survey_responses/mend-io-review-13187391)

**["Comprehensive AppSec Platform with Fast Scans and Clear Remediation Guidance"](https://www.g2.com/survey_responses/mend-io-review-13209300)**

**Rating:** 4.5/5.0 stars

_— Atharva S._

[Read full review](https://www.g2.com/survey_responses/mend-io-review-13209300)

#### What Are G2 Users Discussing About Mend.io?

- [What is your experience regarding pricing and costs for Mend.io, and how does it compare to other open-source security solutions?](https://www.g2.com/discussions/what-is-your-experience-regarding-pricing-and-costs-for-mend-io-and-how-does-it-compare-to-other-open-source-security-solutions)
- [What is Mend (formerly WhiteSource) used for?](https://www.g2.com/discussions/what-is-mend-formerly-whitesource-used-for)
- [What is white Source bolt?](https://www.g2.com/discussions/what-is-white-source-bolt)
- [What are SCA tools?](https://www.g2.com/discussions/what-are-sca-tools)
- [What is software composition analysis SCA?](https://www.g2.com/discussions/what-is-software-composition-analysis-sca)

### [DigiCert ONE](https://www.g2.com/products/digicert-one/reviews)

DigiCert ONE is a cloud-native digital trust platform that helps organizations automate, manage, and secure certificates, identities, software, devices, DNS infrastructure, documents, and email communications from a single platform. Designed to simplify complex trust environments, DigiCert ONE provides centralized visibility, policy-based governance, and automation to reduce operational risk, improve compliance, and accelerate digital transformation initiatives. The platform includes: - Trust Lifecycle Manager for CA-agnostic certificate lifecycle management, certificate discovery, automation, and public and private PKI. - Software Trust Manager for secure code signing, software supply chain protection, and automated signing workflows. - Device Trust Manager for establishing and managing trusted device identities throughout the IoT and device lifecycle. - Content Trust Manager for digital signatures, electronic seals, timestamping, and document trust services. - UltraDNS for highly available, secure DNS infrastructure, intelligent traffic management, and application resiliency. - Messaging Trust for email authentication, domain protection, phishing prevention, and improved email deliverability. DigiCert ONE also integrates with CertCentral®, enabling organizations to streamline the issuance, management, and automation of publicly trusted TLS/SSL certificates alongside their broader digital trust operations. Built on a scalable, container-based architecture, DigiCert ONE supports cloud, on-premises, hybrid, and air-gapped deployments, enabling organizations to meet security, operational, and regulatory requirements while maintaining agility. Organizations use DigiCert ONE to eliminate manual trust management processes, prevent certificate-related outages, secure software and connected devices, protect critical infrastructure, and build trusted digital experiences at scale.

**Average Rating:** 4.3/5.0

**Total Reviews:** 71

#### How Do G2 Users Rate DigiCert ONE?

- **Quality of Support:** 8.7/10 (Category avg: 9.0/10)

#### Who Is the Company Behind DigiCert ONE?

- **Seller:** [digicert](https://www.g2.com/sellers/digicert)
- **Company Website:** www.digicert.com
- **Year Founded:** 2003
- **HQ Location:** Lehi, UT
- **Twitter:** @digicert  
6,675 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=5fe45d5f7f2edf0d7733dbb4b395d486660bd817f0f62c0d8755e403b32def6f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F357882%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,901 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 40% Small, 37% Medium

#### What Are Recent G2 Reviews of DigiCert ONE?

**["Intuitive UI, But Manual DNS Validation for SANs Slows Renewals"](https://www.g2.com/survey_responses/digicert-one-review-12475495)**

**Rating:** 4.5/5.0 stars

_— Saurabh J._

[Read full review](https://www.g2.com/survey_responses/digicert-one-review-12475495)

**["Centralized Certificate Lifecycle Management in One Intuitive Dashboard"](https://www.g2.com/survey_responses/digicert-one-review-12464328)**

**Rating:** 4.5/5.0 stars

_— Saurabh J._

[Read full review](https://www.g2.com/survey_responses/digicert-one-review-12464328)

#### What Are G2 Users Discussing About DigiCert ONE?

- [What is GeoTrust SSL used for?](https://www.g2.com/discussions/what-is-geotrust-ssl-used-for)
- [What is DigiCert Acme?](https://www.g2.com/discussions/what-is-digicert-acme)
- [How do DigiCert certificates work?](https://www.g2.com/discussions/how-do-digicert-certificates-work)
- [Is DigiCert a software?](https://www.g2.com/discussions/is-digicert-a-software) - 1 comment
- [Is RapidSSL a DigiCert?](https://www.g2.com/discussions/is-rapidssl-a-digicert) - 1 comment

### [Snyk](https://www.g2.com/products/snyk/reviews)

Snyk (pronounced sneak) is a developer security platform for securing custom code, open source dependencies, containers, and cloud infrastructure all from a single platform. Snyk’s developer security solutions enable modern applications to be built securely, empowering developers to own and build security for the whole application, from code & open source to containers & cloud infrastructure. Secure while you code in your IDE: find issues quickly using the scanner, fix issues easily with remediation advice, verify the updated code. Integrate your source code repositories to secure applications: integrate a repository to find issues, prioritize with context, fix & merge. Secure your containers as you build, throughout the SDLC: start fixing containers as soon as your write a Dockerfile, continuously monitor container images throughout their lifecycle, and prioritize with context. Secure build and deployment pipelines: Integrate natively with your CI/CD tool, configure your rules, find & fix issues in your application, and monitor your applications. Secure your apps quickly with Snyk’s vulnerability scanning and automated fixes - Try for Free!

**Average Rating:** 4.5/5.0

**Total Reviews:** 135

#### How Do G2 Users Rate Snyk?

- **Quality of Support:** 8.6/10 (Category avg: 9.0/10)
- **Language Support:** 8.1/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 8.7/10 (Category avg: 8.7/10)
- **Integration:** 8.8/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Snyk?

- **Seller:** [Snyk](https://www.g2.com/sellers/snyk)
- **HQ Location:** Boston, Massachusetts
- **Twitter:** @snyksec  
21,057 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=53ae05ab7bc9d48691ba96e338012b66175e75679973854c2a6c213b21fab33f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F10043614%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,370 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 44% Medium, 35% Small

#### What Do G2 Reviewers Say About Snyk?

_AI-generated summary from verified user reviews_

##### Pros

- Users value Snyk's **rapid vulnerability detection** , enabling efficient identification and remediation in development environments.
- Users appreciate Snyk's **rapid vulnerability identification** , enhancing security through quick updates and effective integration.
- Users value the **easy integrations** of Snyk, enhancing workflow efficiency in CI/CD pipelines and GitHub.
- Users appreciate the **easy setup** of Snyk, enabling seamless integration with GitHub and efficient codebase scanning.
- Users commend Snyk for its **intuitive GUI and customizable organization structure** , enhancing vulnerability management and reporting efficiency.

##### Cons

- Users experience **false positives** from Snyk, leading to confusion and slowing down the scanning process.
- Users feel the **poor interface design** of Snyk hinders usability, especially with the separate DAST interface.
- Users face **pricing issues** with Snyk, as the cost can be high for accessing all features.
- Users often face **scanning issues** such as false positives and slow scans, affecting overall efficiency and workflow.
- Users report **false positives** and slow scans in Snyk, affecting efficiency and integration with other tools.

#### What Are Recent G2 Reviews of Snyk?

**["Seamless Dev-First Security with Fast Scans and Actionable Fixes"](https://www.g2.com/survey_responses/snyk-review-12676270)**

**Rating:** 4.5/5.0 stars

_— Prateek J._

[Read full review](https://www.g2.com/survey_responses/snyk-review-12676270)

**["Developer-Friendly Security with Clear, Automated Fixes"](https://www.g2.com/survey_responses/snyk-review-12974957)**

**Rating:** 4.5/5.0 stars

_— Hemanth K._

[Read full review](https://www.g2.com/survey_responses/snyk-review-12974957)

#### What Are G2 Users Discussing About Snyk?

- [What is Snyk scanning?](https://www.g2.com/discussions/what-is-snyk-scanning) - 2 comments, 2 upvotes
- [Is Snyk a SaaS?](https://www.g2.com/discussions/is-snyk-a-saas) - 2 comments
- [How good is Snyk?](https://www.g2.com/discussions/how-good-is-snyk) - 2 comments
- [What is Snyk used for?](https://www.g2.com/discussions/what-is-snyk-used-for)

### [GitLab](https://www.g2.com/products/gitlab/reviews)

GitLab is the most comprehensive AI-Powered DevSecOps platform that enables software innovation by empowering development, security, and operations teams to build better software, faster. With GitLab, teams can create, deliver, and manage code quickly and continuously instead of managing disparate tools and scripts. GitLab helps your teams across the complete DevSecOps lifecycle, from developing, securing, and deploying software. What makes us truly different? - Flexibility: Consume as a service or manage your own deployment - Cloud-Agnostic: Deploy anywhere with no vendor lock-in - No rip and replace: Scale to a platform approach at your own pace

**Average Rating:** 4.5/5.0

**Total Reviews:** 884

#### How Do G2 Users Rate GitLab?

- **Quality of Support:** 8.5/10 (Category avg: 9.0/10)
- **Language Support:** 8.7/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 9.0/10 (Category avg: 8.7/10)
- **Integration:** 8.8/10 (Category avg: 8.8/10)

#### Who Is the Company Behind GitLab?

- **Seller:** [GitLab Inc.](https://www.g2.com/sellers/gitlab-inc)
- **Company Website:** about.gitlab.com
- **Year Founded:** 2014
- **HQ Location:** San Francisco, California
- **Twitter:** @gitlab  
171,534 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a712a3bc9d0c8f9d0d986490c4b4786dfb8085e13a770fa4c99cd9d01137c372&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F5101804%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,473 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, Senior Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 37% Medium, 37% Small

#### What Do G2 Reviewers Say About GitLab?

_AI-generated summary from verified user reviews_

##### Pros

- Users enjoy the **ease of use** of GitLab, thanks to its unified interface and streamlined CI/CD integrations.
- Users value the **all-in-one platform** of GitLab, which streamlines development processes and enhances team collaboration.
- Users praise GitLab for its **powerful CI/CD integration** , which simplifies automation and enhances pipeline efficiency.
- Users value GitLab's **s seamless integrations** allowing streamlined workflows without the need for multiple tools.
- Users value GitLab's **seamless CI/CD integration** , which simplifies automation and enhances overall development efficiency.

##### Cons

- Users find the **complexity** of GitLab's group structure and management challenging, particularly for newcomers and infrastructure.
- Users face a **difficult learning curve** with GitLab, especially for those unfamiliar with its unique structure and features.
- Users find the **confusing interface** of GitLab overwhelming, especially new users navigating its complex functionalities and settings.
- Users find the **complex user interface** of GitLab requires significant effort to master and is not always intuitive.
- Users find the **steep learning curve** of GitLab challenging, especially when adapting to its comprehensive features and UI.

#### What Are Recent G2 Reviews of GitLab?

**["GitLab’s All-in-One DevOps Platform with CI/CD and Security Scanning"](https://www.g2.com/survey_responses/gitlab-review-12864830)**

**Rating:** 5.0/5.0 stars

_— mani s._

[Read full review](https://www.g2.com/survey_responses/gitlab-review-12864830)

**["All-in-One DevOps Platform That Streamlines CI/CD and Collaboration"](https://www.g2.com/survey_responses/gitlab-review-12894467)**

**Rating:** 4.5/5.0 stars

_— Kishor G._

[Read full review](https://www.g2.com/survey_responses/gitlab-review-12894467)

#### What Are G2 Users Discussing About GitLab?

- [What is GitLab used for?](https://www.g2.com/discussions/what-is-gitlab-used-for) - 2 comments
- [Why GitLab is better than Jenkins?](https://www.g2.com/discussions/why-gitlab-is-better-than-jenkins) - 1 comment
- [Is GitLab paid?](https://www.g2.com/discussions/is-gitlab-paid) - 5 comments, 2 upvotes
- [Is GitLab free software?](https://www.g2.com/discussions/is-gitlab-free-software) - 4 comments, 1 upvote
- [What can GitLab do?](https://www.g2.com/discussions/what-can-gitlab-do) - 2 comments

### [JFrog](https://www.g2.com/products/jfrog-2024-03-28/reviews)

JFrog Ltd. (Nasdaq: FROG), the creators of the unified DevOps, DevSecOps, DevGovOps and MLOps platform, is on a mission to create a world of software delivered without friction from development to production. Driven by a “Liquid Software” vision to keep software continuously flowing, secure, and always up to date, the JFrog Platform serves as the definitive software supply chain system of record. It is uniquely engineered to power organizations as they build, manage, and distribute trusted software with unprecedented speed, security, and scale across hybrid and multi-cloud environments. As software engineering evolves in the AI era, JFrog’s newest offerings address the industry's most pressing trend: the rise of agentic software development and the hidden security risks of "Shadow AI." In response to threat actors increasingly targeting developer workflows including a massive surge in malicious open-source AI models and infected packages; JFrog has expanded its platform capabilities to deliver absolute end-to-end visibility and automated compliance. Key new innovations include the JFrog AI Catalog, which enables organizations to centralize, govern, and control the lifecycle of AI models approved for enterprise use. To secure autonomous coding environments, JFrog introduced the Universal MCP Registry and the Agent Skills Registry (developed alongside NVIDIA). These new solutions establish the industry’s first enterprise-grade trust layer to safely manage and store AI agent skills, monitor connections, and instantly block unsafe developer tools or malicious coding extensions right where developers work. Furthermore, the integration of advanced DevGovOps and Runtime Security tools allows teams to replace slow, manual compliance audits with continuous, background policy enforcement. By shifting security left directly into the binary pipeline, JFrog ensures that the volume of AI-assisted code does not outpace an organization's ability to verify its safety. Today, millions of users and approximately 6,600 organizations worldwide, including a majority of the Fortune 100, depend on the universal JFrog Platform to eliminate point-solution fatigue, bridge the governance gap, and securely embrace digital transformation. Learn more at www.jfrog.com or follow us on X @JFrog.

**Average Rating:** 4.2/5.0

**Total Reviews:** 150

#### How Do G2 Users Rate JFrog?

- **Quality of Support:** 8.4/10 (Category avg: 9.0/10)
- **Language Support:** 8.7/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 9.4/10 (Category avg: 8.7/10)
- **Integration:** 8.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind JFrog?

- **Seller:** [JFrog Ltd](https://www.g2.com/sellers/jfrog-ltd)
- **Company Website:** jfrog.com
- **Year Founded:** 2008
- **HQ Location:** Sunnyvale, CA
- **Twitter:** @jfrog  
23,186 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9e9f01c1efeb3f3e7b4535b3aefc16344bbb21773bc11bf4ad186f193dbcaabf&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fjfrog-ltd%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,364 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, DevOps Engineer
- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 50% Large, 31% Medium

#### What Do G2 Reviewers Say About JFrog?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **comprehensive integration and multi-format support** of JFrog, streamlining their DevOps processes effectively.
- Users appreciate JFrog's **centralized artifact management** , enhancing efficiency in storing and tracking components across environments.
- Users value the **seamless deployment integration** of JFrog, enhancing CI/CD pipelines and security management effectively.
- Users value the **seamless integrations** of JFrog, enhancing their CI/CD processes across various package formats.
- Users value the **easy integrations** of JFrog with various tools, enhancing their CI/CD workflows seamlessly.

##### Cons

- Users find JFrog's platform to be **overly complex** , requiring significant training to navigate its extensive features effectively.
- Users find JFrog to be **expensive** , with costs posing challenges for smaller teams and individual developers.
- Users often face a **steep learning curve** with JFrog, requiring significant time to master its complexity.
- Users find the **difficult learning curve** of JFrog requires extensive training to navigate its complex features effectively.
- Users find JFrog to have a **steep learning curve** , requiring significant time and effort to reach proficiency.

#### What Are Recent G2 Reviews of JFrog?

**["JFrog Simplifies Artifact Management for Organized, Reliable Deployments"](https://www.g2.com/survey_responses/jfrog-review-12870354)**

**Rating:** 4.5/5.0 stars

_— Subhashree S._

[Read full review](https://www.g2.com/survey_responses/jfrog-review-12870354)

**["Efficient, Scalable Artifact Management That Streamlines the Software Delivery Lifecycle"](https://www.g2.com/survey_responses/jfrog-review-12788318)**

**Rating:** 4.0/5.0 stars

_— Arkajit D._

[Read full review](https://www.g2.com/survey_responses/jfrog-review-12788318)

#### What Are G2 Users Discussing About JFrog?

- [What are the benefits and challenges of using JFrog for managing your software supply chain?](https://www.g2.com/discussions/what-are-the-benefits-and-challenges-of-using-jfrog-for-managing-your-software-supply-chain)
- [What does Jfrog Platform do?](https://www.g2.com/discussions/what-does-jfrog-platform-do)
- [What is difference between JFrog and Nexus?](https://www.g2.com/discussions/what-is-difference-between-jfrog-and-nexus)
- [What is Artifactory software used for?](https://www.g2.com/discussions/what-is-artifactory-software-used-for)

### [Semgrep](https://www.g2.com/products/semgrep/reviews)

Semgrep is a modern static analysis (SAST), software composition analysis (SCA), and secrets detection platform designed for both developers and security teams. It combines fast, deterministic analysis with context-aware AI that triages findings like a senior security engineer. The AI Assistant helps reduce false positives, prioritize meaningful results, and offers clear remediation guidance. Its “Memories” feature learns from past decisions to further reduce triage noise over time. Semgrep also supports deep analysis of transitive dependencies, not just direct ones, helping teams surface and address hidden risks in their supply chain. It integrates well into modern development workflows and is easy to customize across environments.

**Average Rating:** 4.6/5.0

**Total Reviews:** 56

#### How Do G2 Users Rate Semgrep?

- **Quality of Support:** 8.8/10 (Category avg: 9.0/10)
- **Language Support:** 8.4/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 8.3/10 (Category avg: 8.7/10)
- **Integration:** 8.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Semgrep?

- **Seller:** [Semgrep](https://www.g2.com/sellers/semgrep)
- **Company Website:** semgrep.dev
- **Year Founded:** 2017
- **HQ Location:** San Francisco, US
- **Twitter:** @semgrep  
4,433 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=968a71f2060531e986a3873882c34b492bee4d8d264ff88e0089e53b8f7771f4&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Freturntocorp&secure%5Burl_type%5D=linkedin_company_website)  
262 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 45% Large, 43% Medium

#### What Do G2 Reviewers Say About Semgrep?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **ease of use** of Semgrep, praising its intuitive syntax and smooth CI/CD integration.
- Users appreciate the **intuitive pattern-matching syntax** of Semgrep, enabling effective custom rules for various programming languages.
- Users appreciate Semgrep's **effective vulnerability detection** , enabling quick identification of security issues with low false positives.
- Users value the **scanning efficiency** of Semgrep, benefiting from rapid scans and seamless CI/CD integration.
- Users appreciate the **robust security features** of Semgrep, enabling effective identification and remediation of vulnerabilities effortlessly.

##### Cons

- Users find Semgrep **not user-friendly** , citing a steep learning curve and challenges in initial setup and customization.
- Users note the **limited features** of Semgrep, making categorization and comprehensive analysis more challenging.
- Users find the **difficult learning** curve for custom rules in Semgrep challenging, impacting new user experiences and efficiency.
- Users face a **lack of guidance** in mastering rule creation and initial setup, impacting effective tool utilization.
- Users find the **learning curve steep** for rule writing, especially for those new to static analysis tools.

#### What Are Recent G2 Reviews of Semgrep?

**["Streamlined Code Security with Semgrep"](https://www.g2.com/survey_responses/semgrep-review-11971635)**

**Rating:** 5.0/5.0 stars

_— Shreekanth k._

[Read full review](https://www.g2.com/survey_responses/semgrep-review-11971635)

**["Fast, Easy-to-Customize Rules That Catch Security and Code-Quality Issues Early"](https://www.g2.com/survey_responses/semgrep-review-13079252)**

**Rating:** 4.5/5.0 stars

_— Milan K._

[Read full review](https://www.g2.com/survey_responses/semgrep-review-13079252)

### [Cortex Cloud](https://www.g2.com/products/cortex-cloud/reviews)

Cortex Cloud by Palo Alto Networks, the next version of Prisma Cloud, understands a unified security approach is essential for effectively addressing AppSec, CloudSec, and SecOps. Connecting cloud security and SOC workflows enables teams to achieve holistic visibility, trace risk across the lifecycle, and correlate real-time threat activity with development and runtime contexts. Cortex Cloud is a unified platform built on three core pillars: data integration, AI-driven intelligence, and automation. Now you can safeguard applications, data, and infrastructure across multicloud and hybrid environments with a unified data model that consolidates telemetry from code, runtime, identity, and endpoints, all into a single data source. Empower teams with precise, AI-powered insights and 2200+ machine learning models to identify and stop zero-day threats with real-time advanced threat detection and response. And automate with 1000+ prebuilt playbooks across your cloud stack to reduce manual workloads, accelerate remediations, and cut response times tenfold. Cortex Cloud delivers more than tools—it transforms how organizations secure their cloud environments.

**Average Rating:** 4.1/5.0

**Total Reviews:** 124

#### How Do G2 Users Rate Cortex Cloud?

- **Quality of Support:** 8.0/10 (Category avg: 9.0/10)
- **Language Support:** 6.7/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 7.9/10 (Category avg: 8.7/10)
- **Integration:** 9.2/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Cortex Cloud?

- **Seller:** [Palo Alto Networks](https://www.g2.com/sellers/palo-alto-networks)
- **Company Website:** www.paloaltonetworks.com
- **Year Founded:** 2005
- **HQ Location:** Santa Clara, CA
- **Twitter:** @PaloAltoNtwks  
128,951 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=283fa006a7b7db5565e608e4d1bc1dafae45bdf4b312f2cd5bb208ac9271f81d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F30086%2F&secure%5Burl_type%5D=linkedin_company_website)  
22,313 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 38% Large, 31% Medium

#### What Do G2 Reviewers Say About Cortex Cloud?

_AI-generated summary from verified user reviews_

##### Pros

- Users find Cortex Cloud to be **extremely easy to use** , appreciating its intuitive interface and seamless integration.
- Users value **strong cloud security** and appreciate the intuitive interface and effective compliance support of Cortex Cloud.
- Users value the **ease of managing cloud security** with Cortex Cloud, enhancing focus on critical threats efficiently.
- Users value the **clear visibility** provided by Cortex Cloud, enhancing their management of cloud security and team coordination.
- Users value the **ease of integration** with operations, enhancing the management of cloud security efficiently.

##### Cons

- Users find the **high cost** of Cortex Cloud to be a significant drawback, impacting budget for mid-sized organizations.
- Users find the **difficult learning** curve challenging, especially with complex features and insufficient documentation for beginners.
- Users find the **learning curve steep** due to time-intensive onboarding and a cluttered user interface.
- Users express concerns about **pricing issues** with Cortex Cloud, as costs can rise significantly in larger setups.
- Users find the **complex setup** of Cortex Cloud to be time-consuming and challenging to navigate effectively.

#### What Are Recent G2 Reviews of Cortex Cloud?

**["Cortex Cloud earned it's place before every release."](https://www.g2.com/survey_responses/cortex-cloud-review-13089470)**

**Rating:** 5.0/5.0 stars

_— Johanna K._

[Read full review](https://www.g2.com/survey_responses/cortex-cloud-review-13089470)

**["Cortex Cloud Unifies Cloud Security with Real-Time Protection and Smart Prioritization"](https://www.g2.com/survey_responses/cortex-cloud-review-12997786)**

**Rating:** 4.0/5.0 stars

_— Galateya M._

[Read full review](https://www.g2.com/survey_responses/cortex-cloud-review-12997786)

### [OX Security](https://www.g2.com/products/ox-security/reviews)

OX rewires your security program for the Mythos Age: the era where AI writes the code, chains the exploits, and moves faster than human-built defenses can track. OX is an AI Native Application Protection Platform (AINAPP) unifying security from Prompt to Runtime. It moves your control surface upstream to the prompt, preventing and governing risk at the source instead of chasing it downstream in runtime. OX Mind and OX AI Context Lake connect AI-user governance, code security, cloud and runtime enforcement, and agentic pentesting into one system that shares context across the entire Agentic Development Lifecycle (ADLC), replacing fragmented point tools with a single platform. The platform runs on four connected pillars: OX VibeSec: Prevents unsafe AI decisions at the point of creation and governs every AI user in the organization, not just developers using coding assistants. Full visibility into which agents, MCPs, skills, and packages run, with what permissions, against what data. OX Code: Separates exploitable risk from theoretical noise using evidence from your actual deployment, threat model, and threat intelligence. OX Cloud: Prevents misconfigurations and enforces runtime boundaries that code and agents cannot cross, watching what actually runs in production. OX Agentic Pentester: Continuously simulates adversarial agent behavior to prove exploit paths back to their exact source, feeding what it finds back into OX VibeSec to sharpen governance. OX connects to your existing stack and traces every finding back to its origin (the prompt, the AI user, or the endpoint that created it), then fixes issues at the source rather than flagging them after the fact. For new deployments, OX consolidates governance, code security, cloud enforcement, and pentesting into one platform. For existing stacks, OX layers governance on top and makes current tools smarter through continuous learning, so the same issue never gets created twice. Visit https://ox.security for more information.

**Average Rating:** 4.8/5.0

**Total Reviews:** 51

#### How Do G2 Users Rate OX Security?

- **Quality of Support:** 9.6/10 (Category avg: 9.0/10)
- **Language Support:** 8.7/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 8.8/10 (Category avg: 8.7/10)
- **Integration:** 9.4/10 (Category avg: 8.8/10)

#### Who Is the Company Behind OX Security?

- **Seller:** [OX Security](https://www.g2.com/sellers/ox-security)
- **Year Founded:** 2021
- **HQ Location:** New York, USA
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ee8e1fc166aedd5d2f8edd57605f86ae8eec3007f5eee8810871f0e4645b4f4d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fox-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
199 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Security Engineer
- **Top Industries:** Financial Services, Information Technology and Services
- **Company Size:** 63% Medium, 25% Large

#### What Do G2 Reviewers Say About OX Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **intuitive dashboard and seamless integration** of OX Security, enhancing their security management and workflow efficiency.
- Users value the **seamless collaboration** enabled by OX Security, enhancing their focus on critical development tasks.
- Users commend the **responsive customer support** of OX Security, enhancing their overall operational efficiency and satisfaction.
- Users value the **seamless integrations** with existing tools, enhancing workflows and boosting overall development efficiency.
- Users appreciate the **speed** of OX Security, enabling faster remediation of vulnerabilities and cloud misconfigurations.

##### Cons

- Users find the **complexity** of OX Security daunting, facing a steep learning curve and inadequate documentation.
- Users find the **interface overwhelming** , with a steep learning curve and insufficient documentation to guide new users.
- Users find the **complex setup** challenging, especially due to inadequate documentation and overwhelming UI for new users.
- Users find the **executive dashboard limiting** , impacting effective reporting on product security enhancements to management.
- Users find OX Security's **difficult learning curve** challenging, particularly due to its complex interface and lacking documentation.

#### What Are Recent G2 Reviews of OX Security?

**["A powerful and comprehensive tool that meets most best practices for web app security testing"](https://www.g2.com/survey_responses/ox-security-review-10961361)**

**Rating:** 4.5/5.0 stars

_— Verified User in Gambling & Casinos_

[Read full review](https://www.g2.com/survey_responses/ox-security-review-10961361)

**["Holistic Security Solution with Seamless Integration"](https://www.g2.com/survey_responses/ox-security-review-10487561)**

**Rating:** 4.5/5.0 stars

_— Sharon S._

[Read full review](https://www.g2.com/survey_responses/ox-security-review-10487561)

### [CAST Highlight](https://www.g2.com/products/cast-highlight/reviews)

Portfolio-level insights for app modernization, AI readiness, tech debt, OSS risks CAST Highlight is a SaaS software intelligence technology that delivers rapid, fact-based insights across your entire application portfolio. By automatically analyzing the source code of hundreds or thousands of applications, CAST Highlight helps organizations assess cloud maturity, AI & Agentic readiness, software health, open source risk, resiliency, technical debt, and sustainability from a single lightweight scan. CAST Highlight is designed for CIOs, CTOs, enterprise architects, cloud leaders, application owners, security teams, and modernization teams that need a fact-based way to prioritize modernization, cloud, and AI adoption decisions at scale. It helps teams identify which applications are ready to move quickly, which require remediation, and where hidden software risks may affect transformation cost, timelines, security, resilience, or business outcomes. Unlike traditional manual or survey-based assessments, CAST Highlight analyzes application source code directly to rapidly segment portfolios, prioritize modernization paths, and uncover risks before they impact transformation programs. Organizations use CAST Highlight to: - Accelerate cloud migration and modernization planning - Segment applications by cloud maturity and transformation path - Identify high-value AI adoption opportunities - Assess Agentic Readiness across application portfolios - Prioritize technical debt, resiliency, and maintainability improvements - Assess open source vulnerabilities and IP / license exposure - Evaluate software sustainability with Green Impact insights - Reduce complexity, cost, and risk across transformation programs Businesses move faster using CAST to understand, improve, and transform their software. Through semantic analysis of source code, CAST generates dashboards and 3D maps for executives, technologists, and AI to navigate inside individual applications and across entire portfolios. This intelligence enables companies to steer, speed, and report on initiatives such as technical debt, modernization, and cloud. As the pioneer of the software intelligence field, CAST is trusted by the world’s leading companies and governments, their consultancies and cloud providers. See it all at castsoftware.com.

**Average Rating:** 4.5/5.0

**Total Reviews:** 86

#### How Do G2 Users Rate CAST Highlight?

- **Quality of Support:** 9.1/10 (Category avg: 9.0/10)
- **Language Support:** 8.5/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 8.5/10 (Category avg: 8.7/10)
- **Integration:** 8.5/10 (Category avg: 8.8/10)

#### Who Is the Company Behind CAST Highlight?

- **Seller:** [CAST](https://www.g2.com/sellers/cast)
- **Company Website:** www.castsoftware.com
- **Year Founded:** 1990
- **HQ Location:** New York
- **Twitter:** @SW\_Intelligence  
1,887 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0ce2f19bfa683d9d06fc56898a1568de05de4c4332e22f1fb046292c65ff44c9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcast%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,264 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 57% Large, 24% Small

#### What Do G2 Reviewers Say About CAST Highlight?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of CAST Highlight, allowing for quick and efficient application analysis without complications.
- Users find the **easy setup** of CAST Highlight to be straightforward and efficient, enhancing their analysis experience.
- Users value CAST Highlight for its **comprehensive cloud assessment capabilities** , aiding in application migration and risk analysis.
- Users value the **efficiency** of CAST Highlight, enabling quick, objective analysis of application portfolios for better decision-making.
- Users appreciate the **real-time monitoring** of CAST Highlight, enabling quick, actionable insights for effective portfolio management.

##### Cons

- Users find the **complex navigation** in CAST Highlight challenging, affecting their overall user experience and efficiency.
- Users find the **dashboard issues** in CAST Highlight hinder effective insights and require customization for better alignment.
- Users find the **delayed detection** of issues in CAST Highlight hinders timely responses and detailed analysis.
- Users find the **difficulty in initial configuration** and metric interpretation challenging for new teams utilizing CAST Highlight.
- The **high price** of CAST Highlight restricts its usage in large companies, limiting its potential impact.

#### What Are Recent G2 Reviews of CAST Highlight?

**["Efficient Analysis & Confident Modernization"](https://www.g2.com/survey_responses/cast-highlight-review-12250186)**

**Rating:** 4.5/5.0 stars

_— Neha C._

[Read full review](https://www.g2.com/survey_responses/cast-highlight-review-12250186)

**["Portfolio Insights in One Place with CAST Highlight"](https://www.g2.com/survey_responses/cast-highlight-review-12977472)**

**Rating:** 4.5/5.0 stars

_— Verified User in Government Administration_

[Read full review](https://www.g2.com/survey_responses/cast-highlight-review-12977472)

#### What Are G2 Users Discussing About CAST Highlight?

- [What is cast imaging?](https://www.g2.com/discussions/what-is-cast-imaging) - 1 comment
- [How does a cast tool work?](https://www.g2.com/discussions/how-does-a-cast-tool-work)
- [What is CAST software tool?](https://www.g2.com/discussions/what-is-cast-software-tool) - 1 comment
- [What does cast highlight do?](https://www.g2.com/discussions/what-does-cast-highlight-do) - 1 comment

### [Socket](https://www.g2.com/products/socket-socket/reviews)

Socket is the leading developer-first security platform that protects modern applications from malicious and vulnerable open source dependencies. By combining real-time package monitoring with AI-powered code analysis, Socket detects and blocks supply chain attacks within minutes of publication. With advanced reachability analysis, automated remediation, and license compliance features, Socket enables teams to focus on building software, while we keep their open source code secure.

**Average Rating:** 4.7/5.0

**Total Reviews:** 10

#### How Do G2 Users Rate Socket?

- **Quality of Support:** 9.0/10 (Category avg: 9.0/10)
- **Language Support:** 8.9/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 8.3/10 (Category avg: 8.7/10)
- **Integration:** 8.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Socket?

- **Seller:** [Socket](https://www.g2.com/sellers/socket)
- **Year Founded:** 2020
- **HQ Location:** San Francisco, US
- **Twitter:** @SocketSecurity  
21,558 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=333fcd28dd311ff160a9395ac69327d82d0f595897ba65d2388e7b628c0687bf&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsocketinc%2F&secure%5Burl_type%5D=linkedin_company_website)  
115 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 40% Medium, 30% Large

#### What Do G2 Reviewers Say About Socket?

_AI-generated summary from verified user reviews_

##### Pros

- Users value Socket's **exceptional security features** , particularly in monitoring and mitigating supply chain attacks effectively.
- Users praise Socket for its **effective open source security analysis** , streamlining package reviews and enhancing reliability.
- Users value the **accuracy of findings** from Socket, appreciating the thorough analysis it offers for open source security.
- Users value the **proactive alerts** from Socket, ensuring quick responses to potential supply chain threats.
- Users value the **comprehensive security** features of Socket, enhancing decision-making and risk management in software supply chains.

##### Cons

- Users find the **missing features** in Socket limit its ability to consolidate multiple use cases effectively.
- Users report experiencing **system slowness** , particularly noting the UI's slow loading times impacting their overall experience.

#### What Are Recent G2 Reviews of Socket?

**["Unique Approach to Supply Chain Security Problem and Does It Really Well"](https://www.g2.com/survey_responses/socket-review-12052484)**

**Rating:** 5.0/5.0 stars

_— Sindhoor H._

[Read full review](https://www.g2.com/survey_responses/socket-review-12052484)

**["Essential Tool for Application Security with Stellar MCP Feature"](https://www.g2.com/survey_responses/socket-review-12686360)**

**Rating:** 5.0/5.0 stars

_— Shreejal M._

[Read full review](https://www.g2.com/survey_responses/socket-review-12686360)

### [SOOS](https://www.g2.com/products/soos/reviews)

SOOS is the complete application security posture management platform. Scan your software for vulnerabilities, control the introduction of new dependencies, exclude unwanted license types, generate and manage Software Bill of Materials (SBOM), and fill out your compliance worksheets across all your teams. SOOS’s ASPM is a dynamic, comprehensive approach to safeguarding your application infrastructure from vulnerabilities across the Software Development Life Cycle (SDLC) and live deployments. Easy to integrate, all in one dashboard. SCA - Deep tree vulnerability scanning, license compliance, governance DAST - Automated Web & API vulnerability scanning Containers - Scan contents for vulnerabilities SAST - Analyze code for security vulnerabilities IaC - Cloud security coverage SBOMs - Create – monitor – manage

**Average Rating:** 4.6/5.0

**Total Reviews:** 42

#### How Do G2 Users Rate SOOS?

- **Quality of Support:** 9.3/10 (Category avg: 9.0/10)
- **Language Support:** 9.5/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 9.4/10 (Category avg: 8.7/10)
- **Integration:** 9.5/10 (Category avg: 8.8/10)

#### Who Is the Company Behind SOOS?

- **Seller:** [SOOS](https://www.g2.com/sellers/soos)
- **Year Founded:** 2019
- **HQ Location:** Winooski, US
- **Twitter:** @soostech  
44 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=61bd56b45756b75fc0339880cc3369c6d2af3971839c773abcfbf38d4d05a283&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F53122310&secure%5Burl_type%5D=linkedin_company_website)  
23 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 50% Medium, 43% Small

#### What Do G2 Reviewers Say About SOOS?

_AI-generated summary from verified user reviews_

##### Pros

- Users find SOOS to be **easy to use** , benefiting from user-friendly configurations and excellent support.
- Users praise the **awesome customer support** from SooS, ensuring a smooth onboarding and configuration process.
- Users commend SOOS for its **easy integrations** , enabling seamless workflows and efficient vulnerability management in development.
- Users value the **seamless integrations** of SOOS, enhancing workflow efficiency and simplifying vulnerability management.
- Users find the **easy setup** of SOOS to be intuitive and efficient, enhancing their overall experience.

##### Cons

- Users note a **lack of guidance** in documentation and processes, hindering onboarding and remediation efforts.
- Users find the **poor reporting** of SOOS limits their ability to analyze vulnerabilities effectively across projects.
- Users find the **dashboard issues** frustrating, particularly with limited reporting and filtering options that hinder analysis.
- Users find SOOS lacks **adequate reporting** , needing better customization and filtering options for effective analysis.
- Users find the **lack of features** in SOOS limits usability, especially with reporting and intuitive navigation.

#### What Are Recent G2 Reviews of SOOS?

**["Awesome tool for detecting vulnerabilities within project dependecies"](https://www.g2.com/survey_responses/soos-review-7753830)**

**Rating:** 4.5/5.0 stars

_— Nayan C._

[Read full review](https://www.g2.com/survey_responses/soos-review-7753830)

**["Reliable continuous security assessment for our pipelines"](https://www.g2.com/survey_responses/soos-review-7744758)**

**Rating:** 4.0/5.0 stars

_— Brallan G._

[Read full review](https://www.g2.com/survey_responses/soos-review-7744758)

### [Black Duck SCA](https://www.g2.com/products/black-duck-sca/reviews)

Black Duck builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands. Black Duck solutions help developers to secure code as fast as they write it, development and DevSecOps teams to automate testing within development pipelines without compromising velocity, and security teams to proactively manage risk and focus remediation efforts on what matters most. With Black Duck, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle.

**Average Rating:** 4.1/5.0

**Total Reviews:** 31

#### How Do G2 Users Rate Black Duck SCA?

- **Quality of Support:** 8.0/10 (Category avg: 9.0/10)
- **Language Support:** 9.3/10 (Category avg: 8.5/10)
- **Continuous Monitoring:** 8.6/10 (Category avg: 8.7/10)
- **Integration:** 8.3/10 (Category avg: 8.8/10)

#### Who Is the Company Behind Black Duck SCA?

- **Seller:** [Black Duck](https://www.g2.com/sellers/black-duck)
- **Year Founded:** 2024
- **HQ Location:** Burlington, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ca66ef383f133f101804712b9ed7a89aec2633a8efa048bd261db3b92eb47e73&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fblack-duck-software&secure%5Burl_type%5D=linkedin_company_website)  
1,304 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 44% Large, 34% Medium

#### What Do G2 Reviewers Say About Black Duck SCA?

_AI-generated summary from verified user reviews_

##### Pros

- Users praise the **accuracy of findings** in Black Duck, citing its powerful engine for identifying open source issues.
- Users praise Black Duck for its **powerful engine in identifying open source issues** and vast knowledge base.

##### Cons

- Users face **huge resource constraints** when deploying Black Duck on-prem, which complicates implementation efforts.

#### What Are Recent G2 Reviews of Black Duck SCA?

**["Accurate Vulnerability Insights and Remediation—A Must-Have SCA Platform"](https://www.g2.com/survey_responses/black-duck-sca-review-13130414)**

**Rating:** 5.0/5.0 stars

_— Sonal K._

[Read full review](https://www.g2.com/survey_responses/black-duck-sca-review-13130414)

**["Reliable Open Source Security Tool with Strong CI/CD Integration"](https://www.g2.com/survey_responses/black-duck-sca-review-13033411)**

**Rating:** 5.0/5.0 stars

_— Md Sarfaraz H._

[Read full review](https://www.g2.com/survey_responses/black-duck-sca-review-13033411)

#### What Are G2 Users Discussing About Black Duck SCA?

- [What languages does Black Duck support?](https://www.g2.com/discussions/what-languages-does-black-duck-support)
- [What is software composition analysis?](https://www.g2.com/discussions/what-is-software-composition-analysis)
- [What is Black Duck analysis?](https://www.g2.com/discussions/what-is-black-duck-analysis)
- [What is the use of Black Duck software?](https://www.g2.com/discussions/what-is-the-use-of-black-duck-software)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/software-composition-analysis?order=g2_score&page=2#product-list)
- [3](/categories/software-composition-analysis?order=g2_score&page=3#product-list)
- [4](/categories/software-composition-analysis?order=g2_score&page=4#product-list)
- [5](/categories/software-composition-analysis?order=g2_score&page=5#product-list)
- [Next &rsaquo;Next ›](/categories/software-composition-analysis?order=g2_score&page=2#product-list)

Spotlight Categories

[Social Media Listening Tools](https://www.g2.com/categories/social-media-listening-tools)

[Sales Intelligence Software](https://www.g2.com/categories/sales-intelligence)

[Remote Monitoring & Management (RMM) Software](https://www.g2.com/categories/remote-monitoring-management-rmm)

[Contract Management Software](https://www.g2.com/categories/contract-management)

[Event Registration and Ticketing Software](https://www.g2.com/categories/event-registration-ticketing)

Similar Categories

- [Static Code Analysis](/categories/static-code-analysis)
- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)

- [Log Analysis](/categories/log-analysis)
- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Bill of Materials (SBOM)](/categories/software-bill-of-materials-sbom)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Software Composition Analysis Themes](/categories/software-composition-analysis/themes)

 ![Adam Crivello](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Adam Crivello")
AC

Researched and written by [Adam Crivello](https://research.g2.com/insights/author/adam-crivello)

Updated October 3, 2024

Software composition analysis (SCA) tools enables users to analyze and manage the open-source elements of their applications. Companies and developers use SCA tools to verify licensing and assess vulnerabilities associated with each of their applications’ open-source components. More robust than [vulnerability scanner software](https://www.g2.com/categories/vulnerability-scanner), SCA tools automatically scan all open-source components to check for policy and license compliance, security risks, and version updates. SCA software also provides insights for remedying identified vulnerabilities, usually within the reports generated after a scan.

Companies and developers often use SCA tools in conjunction with [static code analysis software](https://www.g2.com/categories/static-code-analysis), which scans the code behind their applications as opposed to the open-source components.

To qualify for inclusion within the Software Composition Analysis (SCA) category, a product must:

- Automatically track and analyze an application’s open source-components
- Identify component vulnerabilities, licensing and compliance issues, and version updates
- Provide insight into vulnerability remediation

Top Tools at a Glance

| Product | Best for | User Review |
| --- | --- | --- |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_65c94fd396adf448fb1d27e503b86982/wiz-wiz.png "Product Avatar Image")](https://www.g2.com/products/wiz-wiz/reviews)[Wiz](https://www.g2.com/products/wiz-wiz/reviews)[4.7/5(840)](https://www.g2.com/products/wiz-wiz/reviews) | Agentless code-to-cloud SCA with contextual risk prioritization | "Unmatched Security Insights, Excellent Reporting, and Strong Post-Sales Support" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_8ec3c17e3fb1df25b6a8bd7cc69cf2d1/github.png "Product Avatar Image")](https://www.g2.com/products/github/reviews)[GitHub](https://www.g2.com/products/github/reviews)[4.7/5(2,394)](https://www.g2.com/products/github/reviews) | Dependency vulnerability tracking with CI/CD-integrated code review | "Essential Version Control and Collaboration for Building CanniComply" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_94d889d0ae592ea0ec1ff00c075582b1/aikido-security.png "Product Avatar Image")](https://www.g2.com/products/aikido-security/reviews)[Aikido Security](https://www.g2.com/products/aikido-security/reviews)[4.6/5(256)](https://www.g2.com/products/aikido-security/reviews) | Reachability-filtered dependency scanning with low-noise triage | "Enterprise Security Without an Enterprise Security Team" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_630875599869fc792265ba9508dc29e9/snyk.png "Product Avatar Image")](https://www.g2.com/products/snyk/reviews)[Snyk](https://www.g2.com/products/snyk/reviews)[4.5/5(135)](https://www.g2.com/products/snyk/reviews) | Developer-native SCA with IDE-embedded remediation | "Seamless Dev-First Security with Fast Scans and Actionable Fixes" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_1eff145289f3ee8649ba9d287a4fc68a/gitlab.jpeg "Product Avatar Image")](https://www.g2.com/products/gitlab/reviews)[GitLab](https://www.g2.com/products/gitlab/reviews)[4.5/5(900)](https://www.g2.com/products/gitlab/reviews) | Pipeline-embedded dependency and vulnerability scanning | "GitLab’s All-in-One DevOps Platform with CI/CD and Security Scanning" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_5cf4ee793f73c672ce8aa94bc061fa90/jfrog-2024-03-28.png "Product Avatar Image")](https://www.g2.com/products/jfrog-2024-03-28/reviews)[JFrog](https://www.g2.com/products/jfrog-2024-03-28/reviews)[4.2/5(156)](https://www.g2.com/products/jfrog-2024-03-28/reviews) | Artifact-native SCA with supply chain traceability | "JFrog Simplifies Artifact Management for Organized, Reliable Deployments" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_5b6c8c01ee01e707745077e01a01cbc6/semgrep.png "Product Avatar Image")](https://www.g2.com/products/semgrep/reviews)[Semgrep](https://www.g2.com/products/semgrep/reviews)[4.6/5(56)](https://www.g2.com/products/semgrep/reviews) | Reachability-filtered SCA inside CI/CD pipelines | "Streamlined Code Security with Semgrep" |
| [![Product Avatar Image](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_8b3109519c061f3739371275d691098a/cortex-cloud.png "Product Avatar Image")](https://www.g2.com/products/cortex-cloud/reviews)[Cortex Cloud](https://www.g2.com/products/cortex-cloud/reviews)[4.1/5(127)](https://www.g2.com/products/cortex-cloud/reviews) | Multi-cloud vulnerability detection with automated remediation | "Cortex Cloud earned it's place before every release." |

* * *

Show More

### Software Composition Analysis Topics

- [What is Software Composition Analysis Software?](#what-is-software-composition-analysis-software)
- [Why Use Software Composition Analysis Software?](#why-use-software-composition-analysis-software)
- [Who Uses Software Composition Analysis Software?](#who-uses-software-composition-analysis-software)
- [Software Composition Analysis Software Features](#software-composition-analysis-software-features)
- [Trends Related to Software Composition Analysis Software](#trends-related-to-software-composition-analysis-software)
- [Software and Services Related to Software Composition Analysis Software](#software-and-services-related-to-software-composition-analysis-software)

[
### Software Composition Analysis Topics
Expand/Collapse ](#)
- [What is Software Composition Analysis Software?](#what-is-software-composition-analysis-software)
- [Why Use Software Composition Analysis Software?](#why-use-software-composition-analysis-software)
- [Who Uses Software Composition Analysis Software?](#who-uses-software-composition-analysis-software)
- [Software Composition Analysis Software Features](#software-composition-analysis-software-features)
- [Trends Related to Software Composition Analysis Software](#trends-related-to-software-composition-analysis-software)
- [Software and Services Related to Software Composition Analysis Software](#software-and-services-related-to-software-composition-analysis-software)

## Learn More About Software Composition Analysis Tools

### What is Software Composition Analysis Software?

Software composition analysis (SCA) refers to the management and evaluation of open source and third-party components within the development environment. Software developers and development teams use SCA to keep tabs on the hundreds of open source components incorporated in their builds. These components fall out of compliance and require version updates; if left unchecked they can pose major security risks. With so many components to track, developers lean on SCA to automatically manage issues. SCA tools scan for actionable items and alerts developers, allowing teams to focus on development rather than manually combing through a mess of software components.

In conjunction with tools such as [vulnerability scanner](https://www.g2.com/categories/vulnerability-scanner) and [dynamic application security testing (DAST) software](https://www.g2.com/categories/dynamic-application-security-testing-dast), software composition analysis integrates with the development environment to curate a secure DevOps workflow. The synergy between cybersecurity and DevOps, sometimes referred to as DevSecOps, answers an urgent call for developers to approach software development with a security-first mindset. For a long time, software developers have relied on open source and third-party components, leaving siloed cybersecurity professionals to clean up builds. This outdated standard often leaves large unresolved gaps in security for stretches of time. Software composition analysis presents a solution for ensuring secure compliance before the worst happens.

Key Benefits of Software Composition Analysis Software

- Help keep development secure
- Ease the workloads of developers
- Build a productive workflow across teams

### Why Use Software Composition Analysis Software?

Security best practices are a necessary staple in any DevOps environment. Beyond industry standards, secure development is increasingly important as issues such as API vulnerabilities come to the forefront of cybersecurity. There are often many open source and third-party components in a software build—ensuring components are constantly updated and secure is a task better left to software. Software composition analysis does the job and saves development teams significant time and energy.

**Peace of mind —** Software composition analysis software constantly evaluates open source components. This means developers and teams can focus on advancing their projects without worrying about a mess of unchecked components. In the event of any issues, SCA software alerts users and provides suggestions for remediation.

**Seamless security —** Most SCA software integrates with preexisting development environments, meaning users don’t have to navigate between windows to address vulnerabilities. Developers can receive important and relevant information about the open source and third-party components in their builds without detaching themselves from their workspace.

### Who Uses Software Composition Analysis Software?

DevOps teams that want to implement security best practices use SCA software as an integral part of the DevSecOps tool kit. SCA software empowers developers to proactively keep their open source and third-party components secure, rather than leave a mess of vulnerabilities for siloed cybersecurity team members to clean up. Tools like SCA software help break down the barriers between DevOps and cybersecurity practices, curating an integrated and agile workflow.

**Solo developers —** While SCA software does wonders for larger teams looking to marry their cybersecurity and DevOps processes, solo developers benefit from their own automated security watchdog. Developers working alone on personal projects can’t expect cybersecurity to be taken care of by someone else, so tools like SCA software help them manage their open source vulnerabilities without eating into their time and energy.

**Small development teams —** Similar to solo developers, small development teams often lack the assets to employ a full-time cybersecurity professional. SCA software also aids these teams, allowing them to focus their limited resources on building their project.

**Large DevOps teams —** Midsize and enterprise DevOps teams rely on SCA software to shape a secure and common sense DevSecOps workflow. Rather than isolate cybersecurity professionals from the DevOps process, companies use tools like SCA to integrate cybersecurity as a default standard for development. This practice mitigates stressors on both developers and IT teams by enabling a more agile environment.

### Software Composition Analysis Software Features

**Comprehensive insights —** SCA software gives users meaningful visibility into the open source and third-party components they use. These tools organize relevant and timely information and present developers with useful updates. This interface often requires some level of development knowledge, meaning the onus is on developers to act on any information presented by SCA tools. Version updates, compliance issues, and vulnerabilities are constantly evaluated so users can be alerted as soon as issues arise.

**Remediation information —** Beyond identifying issues with developers’ open source components, SCA software provides users with relevant documentation for remediation. These suggestions give knowledgeable developers a jumping off point so they can address vulnerabilities in a timely manner. These remediation suggestions typically require development knowledge to understand, but developers can often pass these remediation tasks to cybersecurity professionals on their team.

### Trends Related to Software Composition Analysis Software

**DevOps —** DevOps refers to the marriage of development and IT operations management to make unified software development pipelines. Teams have implemented DevOps best practices to build, test, and release software. SCA software’s seamless blending with integrated development environments (IDEs) means it fits right in with any DevOps cycle.

**Cybersecurity —** Calls for standardized cybersecurity best practices as part of DevOps philosophy, often referred to as DevSecOps, have shifted the responsibility for secure applications to developers. SCA software’s vulnerability detection and remediation features play a necessary role in establishing secure DevOps practices.

### Software and Services Related to Software Composition Analysis Software

[**Vulnerability scanner software**](https://www.g2.com/categories/vulnerability-scanner) **—** Vulnerability scanners constantly monitor applications and networks to identify vulnerabilities. These tools scan full applications and networks then test them against known vulnerabilities. All of these functions work in conjunction with SCA software to form a comprehensive security stack.

[**Static application security testing (SAST) software**](https://www.g2.com/categories/static-application-security-testing-sast) **—** SAST software inspects and analyzes an application’s code to discover security vulnerabilities without actually executing code. Similar to SCA software, these tools identify vulnerabilities and provide remediation suggestions. There is functional overlap with static code analysis software, but SAST software specifically focuses on security, while static code analysis software has a broader scope.

[**Dynamic application security testing (DAST) software**](https://www.g2.com/categories/dynamic-application-security-testing-dast) **—** DAST tools automate security tests for a variety of real-world threats. These tools run applications against simulated attacks and other cybersecurity scenarios using black box testing, or testing performed outside an application.

[**Static code analysis software**](https://www.g2.com/categories/static-code-analysis) **—** Static code analysis is a debugging and quality assurance method that inspects a computer program’s code without executing the program. Static code analysis software scans code to identify security vulnerabilities, catch bugs, and ensure the code adheres to industry standards. These tools help software developers automate the core aspects of program comprehension. While static code analysis is similar to static application security testing, this software covers a broader scope as opposed to focusing solely on security.