Try our new research platform with insights from 80,000+ expert users
2022-04-19T09:20:00Z

Top 5 Software Composition Analysis (SCA) Solutions 2022

NC
  • 199
Published:Apr 19, 2022
Product comparison that may be of interest to you
PeerSpot user
PeerSpot user
Find out what your peers are saying about Black Duck, Veracode, Snyk and others in Software Composition Analysis (SCA). Updated: March 2025.
848,716 professionals have used our research since 2012.
Related Questions
TM
May 16, 2023
May 16, 2023
@Tej Muchhala ​: Code Quality and Security are 2 different domains and depending on how deep you want to go, the choice of tools will vary.1. SonarQube - This has both community editions and commercial editions. The community has limited scope and no reporting. The enterprise version has a far broader scope covered with excellent reporting capabilities. SQ does have rules to compare against OWA...
2 out of 3 answers
May 15, 2023
Hi Tej, as per my experience, SonarQube provides a better understanding of the code, it gives you a detailed analysis of the code up to the line level. It finds vulnerabilities in the code and runs test cases for you (if you add them). Also, you can customize the quality gate rules to define the parameters your code should pass like reliability, repetition of lines, etc. On the other hand, Snyk offers you an overview of the tools you are using, or the APIs you are using inside the code and gives vulnerability notifications and fixes. SonarQube doesn't fix or doesn't give any suggestions but Snyk will give you suggestions on which version of that dependency should be used and why. I have integrated both Snyk and SonarQube as both are open source up to a certain level. 
LL
May 15, 2023
Hi Tej, you should also check out CAST (castsoftware.com). Their kit does a very thorough analysis that may be a good option depending on the complexity of your codebase. 
Meri Harutyunyan - PeerSpot reviewer
Sep 15, 2023
Sep 15, 2023
Hello community, After the first full scan with Snyk, when the programmer changes something in the code, does he scan the code again completely or only the changes? Thank you for your help.
See 1 answer
it_user2268669 - PeerSpot reviewer
Sep 15, 2023
After the first full scan with Snyk, when the programmer changes something in the code, he can choose to scan the code again entirely or only the changes. Completely scanning the code again may be the most comprehensive option, as it will identify all potential security vulnerabilities, even those introduced in the most recent changes. However, this option can be resource-intensive and time-consuming. Scanning the changes only may be quicker and more efficient, as it will only identify the potential security vulnerabilities introduced in the most recent changes. It may not identify all of the potential security vulnerabilities, however. The best option for a programmer will depend on the specific circumstances. For example, completely scanning the code again may be best if the programmer is concerned about missing any potential security vulnerabilities. However, if the programmer is looking for a more efficient and quicker option, scanning only the changes may be the best option. Here are some additional things to keep in mind: Snyk offers various scanning options, including full, incremental, and targeted scans. The specific scanning option best for you will depend on your particular needs and requirements. It may be best to consult a Snyk expert to determine the best scanning option for your organization.
Product Comparisons
Download Free Report
Download our free Software Composition Analysis (SCA) Report and find out what your peers are saying about Snyk, Black Duck, Mend.io, and more! Updated: March 2025.
DOWNLOAD NOW
848,716 professionals have used our research since 2012.