SCA
ONE CVE SHOULDN'T MEAN A THOUSAND ALERTS.
One CVE becomes one deduplicated finding, no matter how many repos it haunts.
DefectDojo parses every major software composition analysis tool into one data model, so results from different scanners are finally comparable. Run one SCA tool or five; the findings land in the same deduplicated queue. Vulnerabilities in your open source dependencies, with fix versions attached where they exist.
All Integrations20 Events
Every SCA Tool We Parse
If your scanner writes a report, DefectDojo reads it. Browse the full SCA catalog below; every parser normalizes into the same finding model.
AuditJS
SCA
View integrationBlack Duck
SCA
View integrationBundler-Audit
SCA
View integrationCycloneDX
SCA
View integration
Endor Labs
SCA
View integration
Fortify
SCA
View integration
Govulncheck
SCA
View integrationJFrog
SCA
View integration
Mend (Formerly known as Whitesource)
SCA
View integration
Nancy
SCA
View integrationNPM Audit
SCA
View integration
OSV Scanner
SCA
View integrationOWASP Dependency Check
SCA
View integrationOWASP Dependency Track
SCA
View integrationPHP Symfony Security Check
SCA
View integrationpip-audit
SCA
View integrationRetire.js
SCA
View integrationSnyk
SCA
View integration
Sonatype
SCA
View integrationYarn
SCA
View integration