# Top Free Software Supply Chain Security Solutions

## How Many Software Supply Chain Security Solutions Products Does G2 Track?

**Total Products under this Category:** 43

### Category Stats (Aug 2026)

- **Average Rating:** 4.49/5 (↑0.01 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Finite State (+1.29%) - Among all products in this category, Finite State recorded the largest rating increase compared to last month

_Last updated: August 01, 2026_

## How Does G2 Rank Software Supply Chain Security Solutions Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 1,300+ Authentic Reviews
- 43+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Software Supply Chain Security Solutions
 ![G2 Grid® for Software Supply Chain Security Solutions plotting products by satisfaction and market presence](https://www.g2.com/categories/software-supply-chain-security-tools/grids.png?focus%5B%5D=1259627&focus%5B%5D=143017&focus%5B%5D=36094&focus%5B%5D=14032&focus%5B%5D=7362&focus%5B%5D=100655&focus%5B%5D=1312693&focus%5B%5D=108052)

Highlighted products: Aikido Security, JFrog, Snyk, Mend.io, Veracode Application Security Platform, Harness Platform, OX Security, and Sonatype Nexus Repository.

Underlying data: [Grid® JSON](https://www.g2.com/categories/software-supply-chain-security-tools/grids.json?focus%5B%5D=aikido-security&focus%5B%5D=jfrog-2024-03-28&focus%5B%5D=snyk&focus%5B%5D=mend-io&focus%5B%5D=veracode-application-security-platform&focus%5B%5D=harness-platform&focus%5B%5D=ox-security&focus%5B%5D=sonatype-nexus-repository)

**Sponsored**

### JFrog

JFrog Ltd. (Nasdaq: FROG), the creators of the unified DevOps, DevSecOps, DevGovOps and MLOps platform, is on a mission to create a world of software delivered without friction from development to production. Driven by a “Liquid Software” vision to keep software continuously flowing, secure, and always up to date, the JFrog Platform serves as the definitive software supply chain system of record. It is uniquely engineered to power organizations as they build, manage, and distribute trusted software with unprecedented speed, security, and scale across hybrid and multi-cloud environments. As software engineering evolves in the AI era, JFrog’s newest offerings address the industry's most pressing trend: the rise of agentic software development and the hidden security risks of "Shadow AI." In response to threat actors increasingly targeting developer workflows including a massive surge in malicious open-source AI models and infected packages; JFrog has expanded its platform capabilities to deliver absolute end-to-end visibility and automated compliance. Key new innovations include the JFrog AI Catalog, which enables organizations to centralize, govern, and control the lifecycle of AI models approved for enterprise use. To secure autonomous coding environments, JFrog introduced the Universal MCP Registry and the Agent Skills Registry (developed alongside NVIDIA). These new solutions establish the industry’s first enterprise-grade trust layer to safely manage and store AI agent skills, monitor connections, and instantly block unsafe developer tools or malicious coding extensions right where developers work. Furthermore, the integration of advanced DevGovOps and Runtime Security tools allows teams to replace slow, manual compliance audits with continuous, background policy enforcement. By shifting security left directly into the binary pipeline, JFrog ensures that the volume of AI-assisted code does not outpace an organization's ability to verify its safety. Today, millions of users and approximately 6,600 organizations worldwide, including a majority of the Fortune 100, depend on the universal JFrog Platform to eliminate point-solution fatigue, bridge the governance gap, and securely embrace digital transformation. Learn more at www.jfrog.com or follow us on X @JFrog.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=1006186&secure%5Bchosen_at%5D=2026-08-01T07%3A49%3A03Z&secure%5Bdisplayable_resource_id%5D=1006186&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=page_category&secure%5Bplacement_resource_ids%5D%5B%5D=1006186&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=143017&secure%5Bresource_id%5D=1006186&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsoftware-supply-chain-security-tools%2Ffree%3Fopen_modal_url%3D%252Fproducts%252Fxygeni%252Fwishlists%253Fhost_path%253D%25252Fcategories%25252Fsoftware-supply-chain-security-tools%25252Ffree%2526source%253Dcategory&secure%5Btoken%5D=cbbd4694c46ef954e90e960564f2d1b09e050b85e0e98ea1e9665d1b44cdb3d9&secure%5Burl%5D=https%3A%2F%2Fjfrog.com%2Fartifactory%2F%3Futm_source%3Dg2%26utm_medium%3Dcpc_social%26utm_campaign%3Dbrand_awareness_banner_ad%26utm_content%3Du-bin&secure%5Burl_type%5D=custom_url)

### [Aikido Security](https://www.g2.com/fr/products/aikido-security/reviews)

Aikido Security est la plateforme de sécurité axée sur les développeurs qui unifie le code, le cloud, la protection et les tests d'attaque en une suite de produits de premier ordre. Conçu par des développeurs pour des développeurs, Aikido aide les équipes de toute taille à livrer des logiciels sécurisés plus rapidement, à automatiser la protection et à simuler des attaques réelles avec une précision pilotée par l'IA. L'IA propriétaire de la plateforme réduit le bruit de 95 %, offre des correctifs en un clic et permet aux développeurs d'économiser plus de 10 heures par semaine. Aikido Intel découvre de manière proactive les vulnérabilités dans les packages open source avant leur divulgation, aidant à sécuriser plus de 50 000 organisations dans le monde, y compris Revolut, Niantic, Visma, Montblanc et GoCardless.

**Average Rating:** 4.6/5.0

**Total Reviews:** 251

#### Who Is the Company Behind Aikido Security?

- **Vendeur:** [Aikido Security](https://www.g2.com/fr/sellers/aikido-security)
- **Site Web de l'entreprise:** aikido.dev
- **Année de fondation:** 2022
- **Emplacement du siège social:** Ghent, Belgium
- **Twitter:** @AikidoSecurity  
11,770 abonnés Twitter
- **Page LinkedIn®:** [www.linkedin.com](https://www.g2.com/fr/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=79406802efc597500b142b19f023ee80eb82879906d7e1e458900293346529a9&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Faikido-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
241 employés sur LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Fondateur, Directeur technique
- **Top Industries:** Logiciels informatiques, Technologie de l'information et services
- **Company Size:** 80% Small, 13% Medium

#### What Do G2 Reviewers Say About Aikido Security?

_AI-generated summary from verified user reviews_

##### Pros

- Les utilisateurs apprécient la **facilité d'utilisation** d'Aikido Security, bénéficiant de ses informations claires et exploitables ainsi que de son intégration transparente.
- Les utilisateurs louent Aikido Security pour son **identification rapide et conviviale des problèmes de sécurité** dans les bases de code, améliorant ainsi les pratiques de développement.
- Les utilisateurs apprécient les **fonctionnalités robustes d'Aikido Security** , valorisant son utilisation et son efficacité dans l'amélioration des flux de travail de sécurité.
- Les utilisateurs apprécient les **intégrations faciles** avec GitLab, permettant un démarrage rapide et un suivi efficace des problèmes de sécurité.
- Les utilisateurs louent la **facilité d'installation** d'Aikido Security, simplifiant l'intégration et améliorant considérablement leur flux de travail en matière de sécurité.

##### Cons

- Les utilisateurs notent les **fonctionnalités manquantes** dans Aikido Security, souhaitant plus d'intégration et d'options de configuration avancées.
- Les utilisateurs trouvent le **prix excessif** , en particulier pour les startups, malgré la reconnaissance de la valeur du produit.
- Les utilisateurs trouvent que Aikido Security a **des fonctionnalités limitées** , notamment en matière de personnalisation avancée et de rapports pour des environnements complexes.
- Les utilisateurs trouvent que le **prix d'entrée** d'Aikido Security est trop élevé pour les startups, ce qui limite l'adoption et l'expérimentation.
- Les utilisateurs sont frustrés par le **manque de fonctionnalités** , en particulier avec les limitations de la numérisation locale et de la gestion des branches.

#### What Are Recent G2 Reviews of Aikido Security?

**["Intégration transparente de GitHub avec des résultats de sécurité solides et une analyse intelligente des faux positifs"](https://www.g2.com/fr/survey_responses/aikido-security-review-13109689)**

**Rating:** 4.5/5.0 stars

_— Jordan B._

[Read full review](https://www.g2.com/fr/survey_responses/aikido-security-review-13109689)

**["Sécurité d'entreprise sans équipe de sécurité d'entreprise"](https://www.g2.com/fr/survey_responses/aikido-security-review-13108704)**

**Rating:** 4.0/5.0 stars

_— Ian M._

[Read full review](https://www.g2.com/fr/survey_responses/aikido-security-review-13108704)

### [JFrog](https://www.g2.com/fr/products/jfrog-2024-03-28/reviews)

JFrog Ltd. (Nasdaq : FROG), les créateurs de la plateforme unifiée DevOps, DevSecOps, DevGovOps et MLOps, a pour mission de créer un monde où le logiciel est livré sans friction du développement à la production. Animée par une vision de « Liquid Software » pour maintenir le logiciel en flux continu, sécurisé et toujours à jour, la plateforme JFrog sert de système de référence définitif pour la chaîne d'approvisionnement logicielle. Elle est conçue de manière unique pour alimenter les organisations alors qu'elles construisent, gèrent et distribuent des logiciels de confiance avec une vitesse, une sécurité et une échelle sans précédent à travers des environnements hybrides et multi-cloud. Alors que l'ingénierie logicielle évolue à l'ère de l'IA, les nouvelles offres de JFrog répondent à la tendance la plus pressante de l'industrie : la montée du développement logiciel agentique et les risques de sécurité cachés de l'« IA de l'ombre ». En réponse aux acteurs malveillants ciblant de plus en plus les flux de travail des développeurs, y compris une augmentation massive des modèles d'IA open-source malveillants et des packages infectés ; JFrog a élargi les capacités de sa plateforme pour offrir une visibilité absolue de bout en bout et une conformité automatisée. Les nouvelles innovations clés incluent le JFrog AI Catalog, qui permet aux organisations de centraliser, gouverner et contrôler le cycle de vie des modèles d'IA approuvés pour une utilisation en entreprise. Pour sécuriser les environnements de codage autonomes, JFrog a introduit le Universal MCP Registry et le Agent Skills Registry (développé avec NVIDIA). Ces nouvelles solutions établissent la première couche de confiance de qualité entreprise de l'industrie pour gérer et stocker en toute sécurité les compétences des agents d'IA, surveiller les connexions et bloquer instantanément les outils de développement non sécurisés ou les extensions de codage malveillantes là où les développeurs travaillent. De plus, l'intégration d'outils avancés de DevGovOps et de sécurité à l'exécution permet aux équipes de remplacer les audits de conformité manuels et lents par une application continue et en arrière-plan des politiques. En déplaçant la sécurité vers la gauche directement dans le pipeline binaire, JFrog s'assure que le volume de code assisté par l'IA ne dépasse pas la capacité d'une organisation à vérifier sa sécurité. Aujourd'hui, des millions d'utilisateurs et environ 6 600 organisations dans le monde, y compris une majorité du Fortune 100, dépendent de la plateforme universelle JFrog pour éliminer la fatigue des solutions ponctuelles, combler le fossé de la gouvernance et adopter en toute sécurité la transformation numérique. Apprenez-en plus sur www.jfrog.com ou suivez-nous sur X @JFrog.

**Average Rating:** 4.2/5.0

**Total Reviews:** 149

#### Who Is the Company Behind JFrog?

- **Vendeur:** [JFrog Ltd](https://www.g2.com/fr/sellers/jfrog-ltd)
- **Site Web de l'entreprise:** jfrog.com
- **Année de fondation:** 2008
- **Emplacement du siège social:** Sunnyvale, CA
- **Twitter:** @jfrog  
23,186 abonnés Twitter
- **Page LinkedIn®:** [www.linkedin.com](https://www.g2.com/fr/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9e9f01c1efeb3f3e7b4535b3aefc16344bbb21773bc11bf4ad186f193dbcaabf&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fjfrog-ltd%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,364 employés sur LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Ingénieur logiciel, Ingénieur DevOps
- **Top Industries:** Technologie de l'information et services, Logiciels informatiques
- **Company Size:** 50% Large, 31% Medium

#### What Do G2 Reviewers Say About JFrog?

_AI-generated summary from verified user reviews_

##### Pros

- Les utilisateurs apprécient l' **intégration complète et le support multi-format** de JFrog, rationalisant efficacement leurs processus DevOps.
- Les utilisateurs apprécient la **gestion centralisée des artefacts** de JFrog, ce qui améliore l'efficacité du stockage et du suivi des composants à travers les environnements.
- Les utilisateurs apprécient l' **intégration de déploiement transparente** de JFrog, améliorant efficacement les pipelines CI/CD et la gestion de la sécurité.
- Les utilisateurs apprécient les **intégrations transparentes** de JFrog, améliorant leurs processus CI/CD à travers divers formats de paquets.
- Les utilisateurs apprécient les **intégrations faciles** de JFrog avec divers outils, améliorant ainsi leurs flux de travail CI/CD de manière transparente.

##### Cons

- Les utilisateurs trouvent que la plateforme de JFrog est **excessivement complexe** , nécessitant une formation significative pour naviguer efficacement dans ses nombreuses fonctionnalités.
- Les utilisateurs trouvent que JFrog est **cher** , avec des coûts posant des défis pour les petites équipes et les développeurs individuels.
- Les utilisateurs sont souvent confrontés à une **courbe d'apprentissage abrupte** avec JFrog, nécessitant un temps considérable pour maîtriser sa complexité.
- Les utilisateurs trouvent que la **courbe d'apprentissage difficile** de JFrog nécessite une formation approfondie pour naviguer efficacement dans ses fonctionnalités complexes.
- Les utilisateurs trouvent que JFrog a une **courbe d'apprentissage abrupte** , nécessitant un temps et des efforts considérables pour atteindre la maîtrise.

#### What Are Recent G2 Reviews of JFrog?

**["JFrog simplifie la gestion des artefacts pour des déploiements organisés et fiables"](https://www.g2.com/fr/survey_responses/jfrog-review-12870354)**

**Rating:** 4.5/5.0 stars

_— Subhashree S._

[Read full review](https://www.g2.com/fr/survey_responses/jfrog-review-12870354)

**["Gestion efficace et évolutive des artefacts qui rationalise le cycle de vie de la livraison logicielle"](https://www.g2.com/fr/survey_responses/jfrog-review-12788318)**

**Rating:** 4.0/5.0 stars

_— Arkajit D._

[Read full review](https://www.g2.com/fr/survey_responses/jfrog-review-12788318)

#### What Are G2 Users Discussing About JFrog?

- [Quels sont les avantages et les défis de l'utilisation de JFrog pour gérer votre chaîne d'approvisionnement logicielle ?](https://www.g2.com/fr/discussions/what-are-the-benefits-and-challenges-of-using-jfrog-for-managing-your-software-supply-chain)
- [What does Jfrog Platform do?](https://www.g2.com/fr/discussions/what-does-jfrog-platform-do)
- [What is difference between JFrog and Nexus?](https://www.g2.com/fr/discussions/what-is-difference-between-jfrog-and-nexus)
- [What is Artifactory software used for?](https://www.g2.com/fr/discussions/what-is-artifactory-software-used-for)

### [Mend.io](https://www.g2.com/products/mend-io/reviews)

Modern risk doesn't live in one layer, it lives between them. Mend.io is built for every risk, across AI and AppSec, securing the code layer, the AI layer, and the interactions between them. From discovery and red teaming to guardrails and runtime protection, Mend.io delivers continuous protection across the entire AI application lifecycle. Mend.io solutions include: 1. Mend AI secures the layer where modern risk actually lives—the interaction between code and AI. It continuously discovers AI components (agents, prompts, models), tests real behavioral risk through automated red teaming, and enforces in-app runtime guardrails for one continuous control system for the AI lifecycle. 2. Mend AppSec secures the modern code layer by continuously discovering and prioritizing risk across code, libraries, containers, and dependencies, giving teams the clarity they need to reduce exposure and ship secure software faster. 3. Mend Renovate secures the foundation of every codebase by automatically updating dependencies, rating the likelihood each update will succeed without breaking changes, and grouping them by confidence level so teams can resolve them faster.

**Average Rating:** 4.3/5.0

**Total Reviews:** 113

#### Who Is the Company Behind Mend.io?

- **Seller:** [Mend](https://www.g2.com/sellers/mend-ab79a83a-6747-4682-8072-a3c176489d0b)
- **Company Website:** mend.io
- **Year Founded:** 2011
- **HQ Location:** Boston, Massachusetts
- **Twitter:** @Mend\_io  
11,256 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=041c6c79eefb0ef528e05bab57503847c90096672ecceb998f987d3daebef99a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2440656%2F&secure%5Burl_type%5D=linkedin_company_website)  
257 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer
- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 35% Small, 33% Medium

#### What Do G2 Reviewers Say About Mend.io?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **scanning efficiency** of Mend.io, appreciating its quick and accurate results across multiple repositories.
- Users appreciate the **ease of use** of Mend.io, highlighting simple integration and efficient navigation to find vulnerabilities.
- Users appreciate the **easy integrations** of Mend.io, enabling efficient scanning and streamlined workflows across multiple repositories.
- Users appreciate the **quick and accurate scanning** capabilities of Mend.io, enhancing their development workflow and security.
- Users commend the **excellent automated vulnerability detection** in Mend.io, enhancing efficiency in their CI/CD processes.

##### Cons

- Users struggle with **integration issues** , finding the setup process for tools like Jira and on-premise systems challenging.
- Users find **limited features** in Mend.io, struggling with functionality and integration challenges for various tools and cases.
- Users note that Mend.io lacks **essential features** , requiring additional tools and workarounds for effective integration.
- Users experience **complex implementation** with Mend.io, citing difficulties in integration and frequent false positives.
- Users find the **confusing interface** of Mend.io awkward, especially when switching between different product portals.

#### What Are Recent G2 Reviews of Mend.io?

**["Great Tool for Managing 3rd party libraries"](https://www.g2.com/survey_responses/mend-io-review-6728890)**

**Rating:** 4.5/5.0 stars

_— Johannes B._

[Read full review](https://www.g2.com/survey_responses/mend-io-review-6728890)

**["Effortless Integration with Budget-Friendly Scanning"](https://www.g2.com/survey_responses/mend-io-review-4261734)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/mend-io-review-4261734)

#### What Are G2 Users Discussing About Mend.io?

- [What is your experience regarding pricing and costs for Mend.io, and how does it compare to other open-source security solutions?](https://www.g2.com/discussions/what-is-your-experience-regarding-pricing-and-costs-for-mend-io-and-how-does-it-compare-to-other-open-source-security-solutions)
- [What is Mend (formerly WhiteSource) used for?](https://www.g2.com/discussions/what-is-mend-formerly-whitesource-used-for)
- [What is white Source bolt?](https://www.g2.com/discussions/what-is-white-source-bolt)
- [What are SCA tools?](https://www.g2.com/discussions/what-are-sca-tools)
- [What is software composition analysis SCA?](https://www.g2.com/discussions/what-is-software-composition-analysis-sca)

### [Harness Platform](https://www.g2.com/products/harness-platform/reviews)

Simplify your developer experience with the world's first AI-augmented software delivery platform. Upgrade your software delivery with Harness' innovative CI/CD, Feature Flags, Infrastructure as Code Management, and Chaos Engineering tools. We are a software delivery platform that helps developers and infrastructure engineers build and ship code for cloud and on-premise projects. We automate the continuous integration and continuous delivery (CI/CD) process to help teams build faster, ship more frequently, and improve quality, efficiency, and governance. We help companies in four key areas: Number one, we accelerate innovation through DevOps modernization. We provide an approach for software delivery that automates processes, reduces manual interventions, consolidates tools, and accelerates time-to-market for new products, features, and fixes. Number two, we improve developer experience. We give you the ability to attract, retain, and onboard high-caliber engineering talent while fostering a culture of continuous innovation and improvement. Number three, we secure software delivery. We give you the ability to integrate security into every phase of the SDLC. And last but not least is, we optimize cloud costs. We give you the ability to eliminate waste and to ensure that appropriate cloud resources are allocated at the right place at the right time.

**Average Rating:** 4.6/5.0

**Total Reviews:** 301

#### Who Is the Company Behind Harness Platform?

- **Seller:** [Harness](https://www.g2.com/sellers/harness-25016f40-e80f-4417-bea8-39412055d17a)
- **Company Website:** harness.io
- **Year Founded:** 2018
- **HQ Location:** San Francisco
- **Twitter:** @HarnessWealth  
1,389 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fbec562b1d7a892f3293de88d17cc0509949905a19856805c612616710bc3a7d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fharnessinc%2F&secure%5Burl_type%5D=linkedin_company_website)  
1,701 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Software Engineer, DevOps Engineer
- **Top Industries:** Computer Software, Financial Services
- **Company Size:** 43% Large, 37% Medium

#### What Do G2 Reviewers Say About Harness Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Harness Platform, making implementation and configuration seamless and efficient.
- Users value the **ease of use and flexibility** in targeting features within the Harness Platform.
- Users appreciate the **user-friendly interface** of Harness Platform for easily managing and deploying feature flags.
- Users find the **easy setup** of Harness Platform quick and efficient, leading to immediate cost savings and satisfaction.
- Users value the **easy integrations** with SSO and tools that streamline software delivery on the Harness Platform.

##### Cons

- Users note a **lack of multiple filters** in Harness Platform, limiting flexibility for advanced customization and usability.
- Users face **limitations in configuration management** , including issues with renaming and deleting toggles that complicate usability.
- Users note a **lack of multiple filters** and missing features in the Harness Platform, limiting its overall usability.
- Users find the **steep learning curve** challenging, particularly due to complicated settings and insufficient documentation.
- Users find the **UI complex and clunky** , which can complicate the overall user experience with the platform.

#### What Are Recent G2 Reviews of Harness Platform?

**["Harness - World of automation"](https://www.g2.com/survey_responses/harness-platform-review-11792426)**

**Rating:** 4.5/5.0 stars

_— Sunil A._

[Read full review](https://www.g2.com/survey_responses/harness-platform-review-11792426)

**["End-to-End DevOps Automation with Powerful, Flexible CI/CD Pipelines"](https://www.g2.com/survey_responses/harness-platform-review-13164505)**

**Rating:** 4.5/5.0 stars

_— Ravindra N._

[Read full review](https://www.g2.com/survey_responses/harness-platform-review-13164505)

#### What Are G2 Users Discussing About Harness Platform?

- [What is Harness Continuous Delivery used for?](https://www.g2.com/discussions/what-is-harness-continuous-delivery-used-for) - 1 comment
- [What is Propelo used for?](https://www.g2.com/discussions/what-is-propelo-used-for)
- [What is Harness Cloud Cost Management used for?](https://www.g2.com/discussions/what-is-harness-cloud-cost-management-used-for)
- [What is the difference between harness and Jenkins?](https://www.g2.com/discussions/what-is-the-difference-between-harness-and-jenkins) - 1 comment
- [What is streaming Split IO?](https://www.g2.com/discussions/what-is-streaming-split-io) - 1 comment

### [OX Security](https://www.g2.com/fr/products/ox-security/reviews)

OX réorganise votre programme de sécurité pour l'ère Mythos : l'époque où l'IA écrit le code, enchaîne les exploits et évolue plus rapidement que les défenses construites par l'homme ne peuvent suivre. OX est une plateforme de protection d'application native à l'IA (AINAPP) unifiant la sécurité du prompt à l'exécution. Elle déplace votre surface de contrôle en amont vers le prompt, prévenant et gouvernant le risque à la source au lieu de le poursuivre en aval lors de l'exécution. OX Mind et OX AI Context Lake connectent la gouvernance des utilisateurs d'IA, la sécurité du code, l'application des règles dans le cloud et à l'exécution, et le pentesting agentique en un seul système qui partage le contexte à travers tout le cycle de développement agentique (ADLC), remplaçant les outils fragmentés par une plateforme unique. La plateforme fonctionne sur quatre piliers connectés : OX VibeSec : Empêche les décisions dangereuses de l'IA au moment de la création et gouverne chaque utilisateur d'IA dans l'organisation, pas seulement les développeurs utilisant des assistants de codage. Visibilité complète sur quels agents, MCPs, compétences et packages sont exécutés, avec quelles autorisations, sur quelles données. OX Code : Sépare le risque exploitable du bruit théorique en utilisant des preuves de votre déploiement réel, modèle de menace et renseignement sur les menaces. OX Cloud : Empêche les mauvaises configurations et applique les limites d'exécution que le code et les agents ne peuvent franchir, surveillant ce qui est réellement exécuté en production. OX Agentic Pentester : Simule en continu le comportement des agents adversaires pour prouver les chemins d'exploitation jusqu'à leur source exacte, réinjectant ce qu'il trouve dans OX VibeSec pour affiner la gouvernance. OX se connecte à votre pile existante et retrace chaque découverte jusqu'à son origine (le prompt, l'utilisateur d'IA ou le point de terminaison qui l'a créé), puis corrige les problèmes à la source plutôt que de les signaler après coup. Pour les nouveaux déploiements, OX consolide la gouvernance, la sécurité du code, l'application des règles dans le cloud et le pentesting en une seule plateforme. Pour les piles existantes, OX superpose la gouvernance et rend les outils actuels plus intelligents grâce à l'apprentissage continu, de sorte que le même problème ne soit jamais créé deux fois. Visitez https://ox.security pour plus d'informations.

**Average Rating:** 4.8/5.0

**Total Reviews:** 51

#### Who Is the Company Behind OX Security?

- **Vendeur:** [OX Security](https://www.g2.com/fr/sellers/ox-security)
- **Année de fondation:** 2021
- **Emplacement du siège social:** New York, USA
- **Page LinkedIn®:** [www.linkedin.com](https://www.g2.com/fr/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ee8e1fc166aedd5d2f8edd57605f86ae8eec3007f5eee8810871f0e4645b4f4d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fox-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
199 employés sur LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Ingénieur en sécurité
- **Top Industries:** Services financiers, Technologie de l'information et services
- **Company Size:** 63% Medium, 25% Large

#### What Do G2 Reviewers Say About OX Security?

_AI-generated summary from verified user reviews_

##### Pros

- Les utilisateurs apprécient le **tableau de bord intuitif et l'intégration transparente** d'OX Security, améliorant leur gestion de la sécurité et l'efficacité de leur flux de travail.
- Les utilisateurs apprécient la **collaboration fluide** permise par OX Security, ce qui améliore leur concentration sur les tâches de développement critiques.
- Les utilisateurs louent le **support client réactif** d'OX Security, améliorant ainsi leur efficacité opérationnelle globale et leur satisfaction.
- Les utilisateurs apprécient les **intégrations transparentes** avec les outils existants, améliorant les flux de travail et augmentant l'efficacité globale du développement.
- Les utilisateurs apprécient la **rapidité** d'OX Security, permettant une remédiation plus rapide des vulnérabilités et des mauvaises configurations du cloud.

##### Cons

- Les utilisateurs trouvent la **complexité** de la sécurité OX intimidante, faisant face à une courbe d'apprentissage abrupte et à une documentation insuffisante.
- Les utilisateurs trouvent l' **interface accablante** , avec une courbe d'apprentissage abrupte et une documentation insuffisante pour guider les nouveaux utilisateurs.
- Les utilisateurs trouvent la **configuration complexe** difficile, surtout en raison d'une documentation inadéquate et d'une interface utilisateur écrasante pour les nouveaux utilisateurs.
- Les utilisateurs trouvent le **tableau de bord exécutif limitant** , ce qui impacte l'efficacité des rapports sur les améliorations de la sécurité des produits à la direction.
- Les utilisateurs trouvent que la **courbe d'apprentissage difficile** d'OX Security est un défi, notamment en raison de son interface complexe et de sa documentation insuffisante.

#### What Are Recent G2 Reviews of OX Security?

**["Solution de sécurité holistique avec intégration transparente"](https://www.g2.com/fr/survey_responses/ox-security-review-10487561)**

**Rating:** 4.5/5.0 stars

_— Sharon S._

[Read full review](https://www.g2.com/fr/survey_responses/ox-security-review-10487561)

**["Un outil puissant et complet qui répond à la plupart des meilleures pratiques pour les tests de sécurité des applications web."](https://www.g2.com/fr/survey_responses/ox-security-review-10961361)**

**Rating:** 4.5/5.0 stars

_— Utilisateur vérifié à Jeux d'argent et casinos_

[Read full review](https://www.g2.com/fr/survey_responses/ox-security-review-10961361)

### [Sonatype Nexus Repository](https://www.g2.com/products/sonatype-nexus-repository/reviews)

World’s #1 Repository Manager with Free and Pro versions - Single source of truth for all of your components, binaries, and build artifacts. - Efficiently distribute parts and containers to developers. - Used by more than 5 million developers globally. Centralize Give your teams a single source of truth for every component they use. Store Optimize build performance and reliability by caching proxies of remote repositories. Adapt Deliver universal coverage for all major package types and formats Scale Install on an unlimited amount of servers for an unlimited amount of users. Universal Support for all Popular Build Tools Store and distribute Maven/Java, npm, NuGet, Helm, Docker, P2, OBR, APT, GO, R, Conan components and more. Manage components from dev through delivery: binaries, containers, assemblies, and finished goods. Awesome support for the Java Virtual Machine (JVM) ecosystem, including Gradle, Ant, Maven, and Ivy. Compatible with popular tools like Eclipse, IntelliJ, Hudson, Jenkins, Puppet, Chef, Docker, and more. Enterprise Control of Binaries and Build Artifacts Deliver innovation 24x7x365 with high availability. A single source of truth for components used across your entire software development lifecycle including QA, staging, and operations. Easily integrate with existing user and access provisioning systems including LDAP, Atlassian Crowd, and more. SAML/SSO authentication for enhanced security and single sign-on experience. See the Health of Your Software Supply Chain Repository Health Check (RHC) provides up-to-date component intelligence, so your teams make informed decisions early on. View components in need of remediation, prioritized by the severity of vulnerability. Easily avoid known security and license issues for Maven/Java, npm, NuGet, and PyPI components. Modern Features for Continuous Innovation Deploy directly to a desired repository with your choice of build or deployment tool or directly via HTTP. Stage and manage releases with dedicated security and automated rule validation. Enhanced staging provides streamlined oversight and approval of workflows for release candidates. Share binaries, snapshots and releases between groups of developers or post a collection of related, staged artifacts which can be easily tested, promoted, or discarded.

**Average Rating:** 4.5/5.0

**Total Reviews:** 21

#### Who Is the Company Behind Sonatype Nexus Repository?

- **Seller:** [Sonatype](https://www.g2.com/sellers/sonatype)
- **Year Founded:** 2008
- **HQ Location:** Fulton, US
- **Twitter:** @sonatype  
10,589 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=dd965bcc74ef94929b9eb731aaa8ab372133c521cbfc49096fe776e20652458f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F210324%2F&secure%5Burl_type%5D=linkedin_company_website)  
551 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 43% Large, 39% Medium

#### What Are Recent G2 Reviews of Sonatype Nexus Repository?

**["Perfect solution for artifact management"](https://www.g2.com/survey_responses/sonatype-nexus-repository-review-9115886)**

**Rating:** 4.0/5.0 stars

_— Juan Diego P._

[Read full review](https://www.g2.com/survey_responses/sonatype-nexus-repository-review-9115886)

**["Easy to use repository for sharing artifacts within team"](https://www.g2.com/survey_responses/sonatype-nexus-repository-review-9407466)**

**Rating:** 4.0/5.0 stars

_— Ardhiya C._

[Read full review](https://www.g2.com/survey_responses/sonatype-nexus-repository-review-9407466)

#### What Are G2 Users Discussing About Sonatype Nexus Repository?

- [What does a repository manager do?](https://www.g2.com/discussions/nexus-repository-manager-what-does-a-repository-manager-do)
- [What does a repository manager do?](https://www.g2.com/discussions/what-does-a-repository-manager-do)
- [What is Nexus repository tool?](https://www.g2.com/discussions/what-is-nexus-repository-tool)
- [What is Nexus software used for?](https://www.g2.com/discussions/what-is-nexus-software-used-for) - 1 comment
- [What is Nexus repository manager used for?](https://www.g2.com/discussions/what-is-nexus-repository-manager-used-for)

### [SOOS](https://www.g2.com/products/soos/reviews)

SOOS is the complete application security posture management platform. Scan your software for vulnerabilities, control the introduction of new dependencies, exclude unwanted license types, generate and manage Software Bill of Materials (SBOM), and fill out your compliance worksheets across all your teams. SOOS’s ASPM is a dynamic, comprehensive approach to safeguarding your application infrastructure from vulnerabilities across the Software Development Life Cycle (SDLC) and live deployments. Easy to integrate, all in one dashboard. SCA - Deep tree vulnerability scanning, license compliance, governance DAST - Automated Web & API vulnerability scanning Containers - Scan contents for vulnerabilities SAST - Analyze code for security vulnerabilities IaC - Cloud security coverage SBOMs - Create – monitor – manage

**Average Rating:** 4.6/5.0

**Total Reviews:** 42

#### Who Is the Company Behind SOOS?

- **Seller:** [SOOS](https://www.g2.com/sellers/soos)
- **Year Founded:** 2019
- **HQ Location:** Winooski, US
- **Twitter:** @soostech  
44 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=61bd56b45756b75fc0339880cc3369c6d2af3971839c773abcfbf38d4d05a283&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F53122310&secure%5Burl_type%5D=linkedin_company_website)  
24 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 50% Medium, 43% Small

#### What Do G2 Reviewers Say About SOOS?

_AI-generated summary from verified user reviews_

##### Pros

- Users find SOOS to be **easy to use** , benefiting from user-friendly configurations and excellent support.
- Users praise the **awesome customer support** from SooS, ensuring a smooth onboarding and configuration process.
- Users commend SOOS for its **easy integrations** , enabling seamless workflows and efficient vulnerability management in development.
- Users value the **seamless integrations** of SOOS, enhancing workflow efficiency and simplifying vulnerability management.
- Users find the **easy setup** of SOOS to be intuitive and efficient, enhancing their overall experience.

##### Cons

- Users note a **lack of guidance** in documentation and processes, hindering onboarding and remediation efforts.
- Users find the **poor reporting** of SOOS limits their ability to analyze vulnerabilities effectively across projects.
- Users find the **dashboard issues** frustrating, particularly with limited reporting and filtering options that hinder analysis.
- Users find SOOS lacks **adequate reporting** , needing better customization and filtering options for effective analysis.
- Users find the **lack of features** in SOOS limits usability, especially with reporting and intuitive navigation.

#### What Are Recent G2 Reviews of SOOS?

**["Awesome tool for detecting vulnerabilities within project dependecies"](https://www.g2.com/survey_responses/soos-review-7753830)**

**Rating:** 4.5/5.0 stars

_— Nayan C._

[Read full review](https://www.g2.com/survey_responses/soos-review-7753830)

**["Reliable continuous security assessment for our pipelines"](https://www.g2.com/survey_responses/soos-review-7744758)**

**Rating:** 4.0/5.0 stars

_— Brallan G._

[Read full review](https://www.g2.com/survey_responses/soos-review-7744758)

### [Cybeats](https://www.g2.com/products/cybeats/reviews)

Cybeats is at the forefront of cybersecurity innovation and is focused explicitly on automating Software Bill of Materials (SBOM) and Vulnerability Exploitability eXchange (VEX) management. Our platform has built-in support for HBOM and AIBOM. Our mission is to empower organizations to rapidly identify and address vulnerabilities, significantly reducing costs while enhancing the security posture of their products. With our focus on the vision of "Building trust in every layer of your technology," Cybeats provides a robust platform that ensures transparency and security throughout the technological stack. Core Offerings - SBOM Management & Continuous Monitoring Cybeats offers a scalable solution for managing and monitoring SBOMs. Our platform stores enriches and distributes SBOMs efficiently across the organization and the organization's customers. This continuous monitoring helps proactively identify and mitigate software component risks. - SBOM Inventory & Management We provide a centralized system for SBOM inventory management that ensures all software components are accounted for, up-to-date, and secure. This systematic approach helps maintain a clear overview of all software elements, facilitating easier management and compliance. - Vulnerability Lifecycle Management (VLM) Our VLM capabilities integrate Vulnerability Exploitability Exchange (VEX) and Vulnerability Disclosure Program (VDP) processes. This integration helps identify, assess, manage, and mitigate vulnerabilities throughout their lifecycle, ensuring continuous protection against potential software supply chain threats. - Regulatory Compliance Cybeats aligns with global regulatory requirements, assisting organizations in staying compliant with evolving cybersecurity standards. Our solution simplifies compliance management, reducing the complexity and resources required to meet legal and industry standards. With the introduction of regulatory requirements of the FDA pre-market and post-market, the EU CRA, PCI-SSF, and others, companies that develop software-based products must align with the SBOM and Vulnerability management requirements. - OSS and Comercial Licensing Risk Assessment Understanding and managing licensing risks associated with software components is crucial. Cybeats provides tools to assess these risks, helping organizations avoid legal and financial repercussions related to software licensing. - SBOM Sharing and Exchange We facilitate secure sharing and exchange of SBOMs within and across organizations. This capability ensures that all parties in the software supply chain have access to accurate and timely information, enhancing collaborative efforts toward secure software development.

**Average Rating:** 4.4/5.0

**Total Reviews:** 15

#### Who Is the Company Behind Cybeats?

- **Seller:** [CYBEATS](https://www.g2.com/sellers/cybeats)
- **Year Founded:** 2017
- **HQ Location:** Toronto, Ontario
- **Twitter:** @cybeatstech  
616 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=2663143089be0432d313d1e538a94c0aa900c3536fc6ddc68eb338c35cf31f18&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcybeats%2F&secure%5Burl_type%5D=linkedin_company_website)  
32 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 47% Small, 33% Medium

#### What Are Recent G2 Reviews of Cybeats?

**["Great Computer Security Service Solutin"](https://www.g2.com/survey_responses/cybeats-review-7160083)**

**Rating:** 4.5/5.0 stars

_— Patrícia P._

[Read full review](https://www.g2.com/survey_responses/cybeats-review-7160083)

**["A safe and secure enterprise supply chain management system is created and enabled by Cybeats"](https://www.g2.com/survey_responses/cybeats-review-7468992)**

**Rating:** 4.5/5.0 stars

_— Karan C._

[Read full review](https://www.g2.com/survey_responses/cybeats-review-7468992)

### [Socket](https://www.g2.com/products/socket-socket/reviews)

Socket is the leading developer-first security platform that protects modern applications from malicious and vulnerable open source dependencies. By combining real-time package monitoring with AI-powered code analysis, Socket detects and blocks supply chain attacks within minutes of publication. With advanced reachability analysis, automated remediation, and license compliance features, Socket enables teams to focus on building software, while we keep their open source code secure.

**Average Rating:** 4.7/5.0

**Total Reviews:** 10

#### Who Is the Company Behind Socket?

- **Seller:** [Socket](https://www.g2.com/sellers/socket)
- **Year Founded:** 2020
- **HQ Location:** San Francisco, US
- **Twitter:** @SocketSecurity  
21,558 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=333fcd28dd311ff160a9395ac69327d82d0f595897ba65d2388e7b628c0687bf&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsocketinc%2F&secure%5Burl_type%5D=linkedin_company_website)  
115 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 40% Medium, 30% Large

#### What Do G2 Reviewers Say About Socket?

_AI-generated summary from verified user reviews_

##### Pros

- Users value Socket's **exceptional security features** , particularly in monitoring and mitigating supply chain attacks effectively.
- Users praise Socket for its **effective open source security analysis** , streamlining package reviews and enhancing reliability.
- Users value the **accuracy of findings** from Socket, appreciating the thorough analysis it offers for open source security.
- Users value the **proactive alerts** from Socket, ensuring quick responses to potential supply chain threats.
- Users value the **comprehensive security** features of Socket, enhancing decision-making and risk management in software supply chains.

##### Cons

- Users find the **missing features** in Socket limit its ability to consolidate multiple use cases effectively.
- Users report experiencing **system slowness** , particularly noting the UI's slow loading times impacting their overall experience.

#### What Are Recent G2 Reviews of Socket?

**["Unique Approach to Supply Chain Security Problem and Does It Really Well"](https://www.g2.com/survey_responses/socket-review-12052484)**

**Rating:** 5.0/5.0 stars

_— Sindhoor H._

[Read full review](https://www.g2.com/survey_responses/socket-review-12052484)

**["Essential Tool for Application Security with Stellar MCP Feature"](https://www.g2.com/survey_responses/socket-review-12686360)**

**Rating:** 5.0/5.0 stars

_— Shreejal M._

[Read full review](https://www.g2.com/survey_responses/socket-review-12686360)

### [Arnica](https://www.g2.com/products/arnica/reviews)

Arnica is a comprehensive application security posture management (ASPM) platform that protects developers, source code, and products throughout the software development lifecycle. The platform provides real-time application security scanning with 100% coverage across the software supply chain, addressing risks in Static Application Security Testing (SAST), Software Composition Analysis (SCA), Infrastructure as Code (IaC), hardcoded secrets detection, and more. At its core, Arnica offers AI-native security governance that takes control of AI-generated code through advanced AI SAST scanning and agentic rules enforcement. The platform automatically injects centrally-controlled security requirements into AI coding agents like Copilot, Cursor, and Claude at the point of code generation, ensuring every line of AI-written code is secure by default before vulnerabilities reach production. This approach addresses 92% of risks before they ever reach production environments. Arnica's pipelineless architecture provides automatic coverage for every repository without requiring CI/CD pipeline integrations or IDE deployments. The platform scans every code change at the feature branch level, delivering developer-native workflows that keep teams focused on building features rather than chasing security issues. Risk prioritization is enhanced through OWASP Top 10, CVSS, EPSS, and KEV scoring, combined with organizational context to surface the most critical vulnerabilities. The platform excels in developer experience by delivering security findings directly within existing workflows through Slack, Microsoft Teams, pull request comments, and automated ticket management in Jira and Azure DevOps Boards. AI-powered mitigation suggestions provide context-aware, automated fixes that align with organizational coding standards, significantly reducing mean-time-to-remediation. Key security capabilities include real-time secrets detection with automatic validation and mitigation, comprehensive container scanning that maps vulnerabilities directly to source code, and intelligent dependency management with automated SCA upgrades. The platform maintains SOC 2 Type 2 compliance and ISO 27001 certification, ensuring enterprise-grade security standards. Arnica's unique value proposition lies in its ability to scale security across entire organizations while maintaining development velocity, providing complete visibility into code risks, and enabling proactive security measures that prevent vulnerabilities from reaching production environments.

**Average Rating:** 4.9/5.0

**Total Reviews:** 8

#### Who Is the Company Behind Arnica?

- **Seller:** [Arnica](https://www.g2.com/sellers/arnica)
- **Company Website:** www.arnica.io
- **Year Founded:** 2021
- **HQ Location:** Alpharetta, Georgia
- **Twitter:** @arnicaio  
124 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=35b6c80888a16d99de6aed67226d5eee0835f227fc79936eb37367fea6278187&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Farnica-io%2Fabout&secure%5Burl_type%5D=linkedin_company_website)  
60 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 63% Large, 25% Small

#### What Do G2 Reviewers Say About Arnica?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **accuracy of findings** from Arnica, which helps identify and minimize unnecessary elevated privileges.
- Users value the **actionable recommendations** provided by Arnica, facilitating effective management of elevated privileges in code repositories.
- Users love the **easy setup and administration** of Arnica, saving time while meeting their needs effectively.
- Users love the **easy setup** of Arnica, finding it quick and efficient for their needs.
- Users value Arnica for its ability to **simplify remediation of overprovisioning** and enhance security through effective privilege management.

##### Cons

- Users note that **paid features** in Arnica restrict access for smaller teams, limiting comprehensive protections.

#### What Are Recent G2 Reviews of Arnica?

**["Intuitive Dashboards and AI That Finds Real Issues"](https://www.g2.com/survey_responses/arnica-review-12972680)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/arnica-review-12972680)

**["Developer-friendly AppSec with a flexible policy engine"](https://www.g2.com/survey_responses/arnica-review-12962349)**

**Rating:** 5.0/5.0 stars

_— Thomas G._

[Read full review](https://www.g2.com/survey_responses/arnica-review-12962349)

#### What Are G2 Users Discussing About Arnica?

- [What is Arnica used for?](https://www.g2.com/discussions/what-is-arnica-used-for)

### [Jscrambler](https://www.g2.com/products/jscrambler/reviews)

Jscrambler is the leader in Client-Side Security for the modern, composable web. As organizations increasingly build digital experiences through third-party software supply chains and AI-powered agents, sensitive data is now created directly in the browser — the point of creation for digital interactions — making it one of the enterprise’s most privileged yet least governed attack surfaces. Jscrambler’s Client-Side Security Platform is powered by a Behavioral Enforcement Core that governs how application code, third-party scripts, and sensitive data behave at runtime. By enforcing software integrity and data governance directly in the browser, the platform ensures sensitive data and AI inputs are controlled according to enterprise policy at the point of creation — before they leave the client environment. Trusted by leading global retailers, airlines, financial services providers, and healthcare organizations, Jscrambler provides the visibility and enforcement organizations need to stop client-side attacks, prevent data leakage, and maintain compliance with regulations including PCI DSS, GDPR, HIPAA, CCPA, and the EU AI Act.

**Average Rating:** 4.4/5.0

**Total Reviews:** 31

#### Who Is the Company Behind Jscrambler?

- **Seller:** [Jscrambler](https://www.g2.com/sellers/jscrambler)
- **Company Website:** jscrambler.com
- **Year Founded:** 2014
- **HQ Location:** San Francisco, California
- **Twitter:** @Jscrambler  
1,161 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=1f232d3698f51e50cca5f27217404c5fdc451925ba67a491d9048732abcf939f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1005462%2F&secure%5Burl_type%5D=linkedin_company_website)  
89 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 35% Medium, 29% Small

#### What Do G2 Reviewers Say About Jscrambler?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **robust security features** of Jscrambler, ensuring their intellectual property is well-protected during deployment.
- Users appreciate the **ease of use** of Jscrambler, finding the interface user-friendly and easy to navigate.
- Users praise the **user-friendly interface** of Jscrambler, making management and implementation straightforward and efficient.
- Users find Jscrambler's **automation capabilities** seamlessly integrate into CI/CD pipelines, enhancing security without disrupting development.
- Users value the **comprehensive overview** of Jscrambler, enhancing security and performance with gradual feature activation.

##### Cons

- Users experience a **difficult initiation** with Jscrambler due to its complex installation and setup processes.
- Users experience **slow performance** that negatively affects user experience, requiring additional tuning and lacking adequate documentation.
- Users note that the **dashboard could provide more detailed information** about each installation for better insights.
- Users often face **obfuscation issues** with large applications, leading to functionality problems and project file limit challenges.
- Users often face **limited guidance** with Jscrambler, leading to challenges in exporting reports effectively.

#### What Are Recent G2 Reviews of Jscrambler?

**["Unmatched Code Protection with Jscrambler"](https://www.g2.com/survey_responses/jscrambler-review-12607132)**

**Rating:** 5.0/5.0 stars

_— Bruno V._

[Read full review](https://www.g2.com/survey_responses/jscrambler-review-12607132)

**["Jscrambler Integrates Seamlessly Into CI/CD for Enhanced Web App Security"](https://www.g2.com/survey_responses/jscrambler-review-11802189)**

**Rating:** 5.0/5.0 stars

_— Daniel G._

[Read full review](https://www.g2.com/survey_responses/jscrambler-review-11802189)

#### What Are G2 Users Discussing About Jscrambler?

- [What is Jscrambler used for?](https://www.g2.com/discussions/what-is-jscrambler-used-for)

### [Cloudsmith](https://www.g2.com/products/cloudsmith/reviews)

Cloudsmith is the modern artifact management and software supply chain security platform. It gives engineering teams a unified control layer for every package, container, binary, and ML model moving through their software supply chain – across 30+ formats, with built-in policy enforcement and continuous security monitoring. Modern engineering teams assemble software more than they author it and AI agents pull in open source dependencies at a pace that exceeds ad hoc governance. Cloudsmith functions as a private registry that sits between public sources and your builds; It is the first place every artifact lands and where policy enforcement occurs before anything enters your environment. Splitting artifact management and security across disconnected tools causes teams to lose the consistent visibility and control they need to move fast – and with confidence. Cloudsmith replaces that complexity with a unified platform that scales with your organization. Built for platform engineering teams, security leads, and the engineering leaders who support them, Cloudsmith reduces the operational burden of managing artifact infrastructure, enforces governance consistently across every team and format, and gives organizations full traceability across their supply chain.

**Average Rating:** 4.5/5.0

**Total Reviews:** 44

#### Who Is the Company Behind Cloudsmith?

- **Seller:** [Cloudsmith](https://www.g2.com/sellers/cloudsmith)
- **Company Website:** cloudsmith.com
- **Year Founded:** 2016
- **HQ Location:** Belfast, Northern Ireland
- **Twitter:** @cloudsmith  
1,094 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ed3ea9e062dddfc8e4cc06cf24ff5cad448805d24492bded400ddd53715bee83&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcloudsmith%2F&secure%5Burl_type%5D=linkedin_company_website)  
152 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer Software, Information Technology and Services
- **Company Size:** 36% Medium, 36% Small

#### What Do G2 Reviewers Say About Cloudsmith?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Cloudsmith, enabling efficient artifact management without the complexity of multiple registries.
- Users appreciate the **seamless integrations** of Cloudsmith, enhancing efficiency and simplifying artifact management across various formats.
- Users value the **reliability** of Cloudsmith, with consistent performance and seamless integration into their workflows.
- Users praise Cloudsmith for its **comprehensive cloud integration** , streamlining artifact management and improving efficiency across multiple formats.
- Users value the **development efficiency** of Cloudsmith, streamlining artifact management and simplifying the software delivery process.

##### Cons

- Users find the **difficult setup** of Cloudsmith frustrating, experiencing issues with onboarding and native integrations.
- Users find Cloudsmith's pricing model **expensive** , especially for teams with high storage and bandwidth needs.
- Users face **integration issues** with Cloudsmith, leading to potential confusion during onboarding and high costs for large teams.

#### What Are Recent G2 Reviews of Cloudsmith?

**["Streamlined Artifact Management with Stellar Support"](https://www.g2.com/survey_responses/cloudsmith-review-12919092)**

**Rating:** 4.5/5.0 stars

_— Benjamin J._

[Read full review](https://www.g2.com/survey_responses/cloudsmith-review-12919092)

**["Exemplary Support and an Easy Web UI That Boosts Team Efficiency"](https://www.g2.com/survey_responses/cloudsmith-review-13174852)**

**Rating:** 5.0/5.0 stars

_— Dan M._

[Read full review](https://www.g2.com/survey_responses/cloudsmith-review-13174852)

#### What Are G2 Users Discussing About Cloudsmith?

- [What is Cloudsmith used for?](https://www.g2.com/discussions/what-is-cloudsmith-used-for) - 1 comment

### [DryRun Security](https://www.g2.com/products/dryrun-security/reviews)

Security leaders face a paradox: ship faster and enable agentic development while staying secure and keeping developers productive. DryRun Security resolves this by securing every pull request and repo with a high-precision, automated security engineer review right where developers and their agents build. DryRun Security is the industry’s most accurate agentic code security intelligence platform. Powered by its proprietary Contextual Security Analysis (CSA) engine, DryRun Security delivers the AI moment for security teams in an AI-native developer world. Traditional static application security testing (SAST) floods teams with alerts, misses higher-order risk, and burns time in triage. DryRun Security goes beyond SAST with contextual analysis that prioritizes what is exploitable and impactful in your codebase, then helps engineers remediate fast. Instead of “find everything and hope someone sorts it out,” DryRun Security delivers code security intelligence that is ready to act on. DryRun Security puts a security engineer directly into developer workflows. In pull requests, the Code Review Agent reviews changes in context, explains risk in plain language, and guides fixes where developers already work. In repos, the DeepScan Agent produces focused, human-grade findings for the issues that actually matter, without weeks of manual review before major milestones. The Custom Policy Agent enforces guardrails with Natural Language Code Policies, so you can standardize security and compliance requirements across teams without brittle rule sets. Codebase Insights allows leaders to ask questions of their entire codebase like "Are we exposed to this new vulnerability" and have confidence in minutes. DryRun Security also integrates with AI coding workflows, so remediation happens with the precision of a security engineer working at machine speed. Teams connect DryRun Security insights and guidance into Claude, Cursor, OpenAI Codex, and Windsurf, helping developers and their agents fix issues with contextual, security-engineered direction tied to the PR and codebase. What DryRun Security delivers (beyond SAST) • Automated secure code review in every pull request with high-signal findings and low noise • Contextual Security Analysis that catches common vulnerabilities and deeper multi-dependency and logic risks • Automated remediation guidance that helps engineers fix faster, with explanations and next steps • Secrets analysis identifies genuine hardcoded secrets and suppresses the usual false alarms • Policy enforcement in PRs using Natural Language Code Policies for consistent guardrails across repos • Codebase intelligence and reporting for AppSec visibility, prioritization, and audit-ready evidence DryRun Security supports most code environments, languages, and frameworks, including: • GitHub, GitLab • C#, Golang, Elixir, JavaScript, TypeScript, Python, Ruby, Java, Kotlin, PHP, Swift, HTML • Infrastructure as Code (Terraform, YAML) • And more

**Average Rating:** 4.9/5.0

**Total Reviews:** 20

#### Who Is the Company Behind DryRun Security?

- **Seller:** [DryRun Security](https://www.g2.com/sellers/dryrun-security)
- **Year Founded:** 2023
- **HQ Location:** Austin, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6a05a774e1320fb12547e26ce7fe95d94335bc0c4be6317172500089b5b6db36&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fdryrun-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
16 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security
- **Company Size:** 40% Small, 30% Medium

#### What Do G2 Reviewers Say About DryRun Security?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **context-aware security feedback** from DryRun Security, enhancing vulnerability mitigation during development in GitHub.
- Users appreciate the **quick and context-aware vulnerability detection** of DryRun Security, enhancing security during the development process.
- Users value the **seamless integration and advanced detections** of DryRun Security, enhancing code security and development efficiency.
- Users value the **accuracy of feedback** from DryRun Security, effectively minimizing false positives and identifying complex vulnerabilities.
- Users appreciate the **easy setup** of DryRun Security, enabling seamless integration and quick vulnerability detection.

##### Cons

- Users find the **slow performance** of DryRun Security's management portal frustrating, impacting their overall experience.
- Users experience **slow speed** issues with the management portal, impacting overall usability and efficiency.
- Users note the **sluggish UI** of DryRun Security, which hampers the overall developer experience during use.
- Users feel there are **limited customization options** for analyzers, though improvements may be forthcoming.
- Users feel that there are **workflow issues** that hinder the developer experience and adoption of DryRun Security.

#### What Are Recent G2 Reviews of DryRun Security?

**["Catches Logic and Authorization Flaws Traditional SAST Often Misses"](https://www.g2.com/survey_responses/dryrun-security-review-12357188)**

**Rating:** 5.0/5.0 stars

_— Jabez A._

[Read full review](https://www.g2.com/survey_responses/dryrun-security-review-12357188)

**["Next Gen of SAST Tool That Has Cutting Edge Tech"](https://www.g2.com/survey_responses/dryrun-security-review-12462338)**

**Rating:** 5.0/5.0 stars

_— Francis D._

[Read full review](https://www.g2.com/survey_responses/dryrun-security-review-12462338)

### [Xygeni](https://www.g2.com/products/xygeni/reviews)

Secure your Software Development and Delivery! Xygeni Security specializes in Application Security Posture Management (ASPM), using deep contextual insights to effectively prioritize and manage security risks while minimizing noise and overwhelming alerts. Our innovative technologies automatically detect malicious code in real-time upon new and updated components publication, immediately notifying customers and quarantining affected components to prevent potential breaches. With extensive coverage spanning the entire Software Supply Chain—including Open Source components, CI/CD processes and infrastructure, Anomaly detection, Secret leakage, Infrastructure as Code (IaC), and Container security—Xygeni ensures robust protection for your software applications. Trust Xygeni to protect your operations and empower your team to build and deliver with integrity and security.

**Average Rating:** 4.6/5.0

**Total Reviews:** 4

#### Who Is the Company Behind Xygeni?

- **Seller:** [Xygeni Security](https://www.g2.com/sellers/xygeni-security)
- **Year Founded:** 2021
- **HQ Location:** Madrid, ES
- **Twitter:** @xygeni  
178 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0302db05d62f71019af9c96a9c2a81cfa4c370ac1ddef2c863b931a5bb7be15a&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fxygeni%2F&secure%5Burl_type%5D=linkedin_company_website)  
30 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 60% Small, 40% Medium

#### What Do G2 Reviewers Say About Xygeni?

_AI-generated summary from verified user reviews_

##### Pros

- Users commend Xygeni for its **comprehensive security features** , enhancing protection while maintaining efficient software development processes.
- Users value the **contextual risk prioritization** of Xygeni, enabling focus on the most critical security issues efficiently.
- Users value the **effective risk management** of Xygeni, ensuring security without hindering development speed.
- Users praise the **robust security features** of Xygeni, ensuring efficient vulnerability management and compliance throughout development.
- Users value the **seamless CI/CD integration** of Xygeni, enhancing security without hindering development speed.

##### Cons

- Users experience **difficult setup** with Xygeni due to manual adjustments needed for specific CI/CD configurations.
- Users find the **learning curve for first-time users** challenging, needing familiarity with AppSec best practices for deeper insights.

#### What Are Recent G2 Reviews of Xygeni?

**["Revolutionized Our Security Workflow with Unified, AI-Driven Efficiency"](https://www.g2.com/survey_responses/xygeni-review-11998435)**

**Rating:** 5.0/5.0 stars

_— Yerassyl K._

[Read full review](https://www.g2.com/survey_responses/xygeni-review-11998435)

**["The essential tool for proactive security and confident development"](https://www.g2.com/survey_responses/xygeni-review-11393516)**

**Rating:** 4.5/5.0 stars

_— Marcos C._

[Read full review](https://www.g2.com/survey_responses/xygeni-review-11393516)

### [ReversingLabs](https://www.g2.com/products/reversinglabs/reviews)

ReversingLabs is the trusted name in file and software security. We provide the modern cybersecurity platform to verify and deliver safe binaries. Trusted by the Fortune 500 and leading cybersecurity vendors, RL Spectra Core powers the software supply chain and file security insights, tracking over 422 billion searchable files with the ability to deconstruct full software binaries in seconds to minutes. Only ReversingLabs provides that final exam to determine whether a single file or full software binary presents a risk to your organization and your customers.

**Average Rating:** 4.7/5.0

**Total Reviews:** 10

#### Who Is the Company Behind ReversingLabs?

- **Seller:** [ReversingLabs](https://www.g2.com/sellers/reversinglabs)
- **Year Founded:** 2009
- **HQ Location:** Cambridge, US
- **Twitter:** @ReversingLabs  
7,022 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=a0adaa8657020403414851b990a81c3a6a6e60c4899834e4a7ca68c7abd667e5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Freversinglabs%2F&secure%5Burl_type%5D=linkedin_company_website)  
321 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 80% Small, 10% Medium

#### What Do G2 Reviewers Say About ReversingLabs?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **accuracy of information** provided by ReversingLabs, ensuring effective risk management and resource utilization.
- Users appreciate the **excellent customer support** at ReversingLabs, highlighting their involvement and effectiveness in the onboarding process.
- Users praise ReversingLabs for its **efficiency** in onboarding and risk management, leading to a seamless user experience.
- Users commend the **effective prioritization** of risk management in ReversingLabs, enhancing their overall satisfaction and security.
- Users value the **high reliability** of ReversingLabs, appreciating its seamless onboarding and extensive file repository.

##### Cons

- Users find the **complex querying** for usage endpoints confusing, which can hinder their overall experience.
- Users find the **interface confusing** , particularly when it comes to checking usage endpoints.
- Users find the **navigation issues** of ReversingLabs challenging, leading to confusion in checking usage endpoints.
- Users feel the **UI could be improved** , although it doesn’t significantly block their overall experience.

#### What Are Recent G2 Reviews of ReversingLabs?

**["Deep File Reputation Intelligence with Excellent Format Coverage"](https://www.g2.com/survey_responses/reversinglabs-review-12547875)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/reversinglabs-review-12547875)

**["Very good, with small drawbacks in the interface"](https://www.g2.com/survey_responses/reversinglabs-review-12310983)**

**Rating:** 4.5/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/reversinglabs-review-12310983)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/software-supply-chain-security-tools/free?open_modal_url=%2Fproducts%2Fxygeni%2Fwishlists%3Fhost_path%3D%252Fcategories%252Fsoftware-supply-chain-security-tools%252Ffree%26source%3Dcategory&order=g2_score&page=2#product-list)
- [Next &rsaquo;Next ›](/categories/software-supply-chain-security-tools/free?open_modal_url=%2Fproducts%2Fxygeni%2Fwishlists%3Fhost_path%3D%252Fcategories%252Fsoftware-supply-chain-security-tools%252Ffree%26source%3Dcategory&order=g2_score&page=2#product-list)

Spotlight Categories

[Voice Recognition Software](https://www.g2.com/categories/voice-recognition)

[Digital Signage Software](https://www.g2.com/categories/digital-signage)

[Contact Center Software](https://www.g2.com/categories/contact-center)

[Webinar Platforms](https://www.g2.com/categories/webinar)

[Sales Enablement Software](https://www.g2.com/categories/sales-enablement)

Similar Categories

- [Cloud Platform as a Service (PaaS)](/categories/cloud-platform-as-a-service-paas)
- [Integrated Development Environments (IDE)](/categories/integrated-development-environments-ide)
- [Software Testing](/categories/software-testing)
- [Communication Platform as a Service (CPaaS)](/categories/communication-platform-as-a-service-cpaas)
- [Help Authoring Tool (HAT)](/categories/help-authoring-tool-hat)

- [Other Development](/categories/other-development)
- [AI Documentation Generators](/categories/ai-documentation-generators)
- [API Development](/categories/api-development)
- [API Documentation Management](/categories/api-documentation-management)
- [API Generation](/categories/api-generation)

- [API Management](/categories/api-management)
- [API Marketplace](/categories/api-marketplace)
- [API Mocking](/categories/api-mocking)
- [API Platforms](/categories/api-platforms)
- [Application Development](/categories/application-development)

[Browse Software Supply Chain Security Tools Themes](/categories/software-supply-chain-security-tools/themes)