OWASP Dependency-Check
OWASP
Long running OWASP project that identifies dependencies by collecting evidence from artifacts, maps them to CPE identifiers, and reports matching CVEs from the National Vulnerability Database.
SCA
Identify open-source dependencies and match them against known vulnerability and license data.
28 tools profiled
How it differs Checks the open source packages you depend on for known vulnerabilities and license obligations. Flaws in code you wrote are SAST territory.
OWASP
Long running OWASP project that identifies dependencies by collecting evidence from artifacts, maps them to CPE identifiers, and reports matching CVEs from the National Vulnerability Database.
OWASP
Long running OWASP project that identifies dependencies by collecting evidence from artifacts, maps them to CPE identifiers, and reports matching CVEs from the National Vulnerability Database.