Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Software Supply Chain Security

Software Supply Chain Security

Build an evaluation questionnaire →

Analyst coverage

Public fact of coverage — not proprietary ratings
📊

No analyst coverage recorded yet

Integration ecosystemUI-25 — integration network graphEvery Software Supply Chain Security vendor with a detected integration, plus the vendors they integrate with (any category) — integrations are mostly cross-category in practice, so this shows the real neighborhood, not just same-category edges. Software Supply Chain Security vendors are highlighted; connected vendors from other categories are dimmer. Circle size = how many integrations that vendor has. Sourced from each vendor's own published integration/partner pages (see UI-12).

323 edges

CVE exposure in Software Supply Chain SecurityUI-71 — vendor/CVE treemapEvery Software Supply Chain Security vendor with at least one tracked CVE, sized by count — same data and coloring as the full-catalog version on the Browse page, scoped to just this category.

RSS ⇢

12 vendors with at least one tracked CVE, sized by how many. Color = relative volume.About CVE trackingSourced from the public NVD database, matched by vendor name (same data as each vendor's own CVE list). Tracking is capped at 100 CVEs per vendor as a scan guard — no vendor has hit that cap yet. Vendor-level only, not per-product/version — always check the linked NVD record before drawing conclusions about a specific product.

Manifest71 CVEsJFrog43 CVEsSnyk17 CVEsSocket13 CVEsOPSWAT11 CVEsBlack Duck6 CVEsAqua Security4 CVEsVeracode3 CVEs

Security posture in Software Supply Chain SecurityUI-108 — category security rollupA category-level rollup of the same per-vendor signals shown on each vendor's own page (UI-90/99/102): security-header checks against each vendor's own homepage, and keyword-matched compliance certifications. Coverage is partial — only vendors checked so far are counted, not the whole category — so this describes what's known, not a claim about every vendor in Software Supply Chain Security.

16/19
checked vendors have a strong security-header posture (3+/5)
0
vendors with a disclosed certification
19/41
vendors in this category checked so far

Vendors (41)

⚖ Compare vendors side-by-side

Pick 2–4 vendors, then compare their products and neutral strengths/gaps.

0/4 selected
  • aDolus Technology6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    SaaS platform for software supply chain monitoring across IT, IoT, and OT.
    aDolus FACT Certificate Validation
  • Apiiro15 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security posture management.
    Apiiro SSCSApiiro Deliver
  • Aqua Security16 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Cloud-native application and container security.
    Aqua Software Supply Chain Security
  • Arnica6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Developer-native supply chain security.
    Pipelineless Security
  • Black Duck6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security and software composition analysis.
  • BoostSecurity4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    ASPM platform for monitoring and hardening app security across SDLC
    BoostSecurity Cloud-speed ComplianceBoostSecurity Software Supply Chain Protection
  • Chainguard6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Secure (minimal, zero-CVE) container images.
    Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard Zero-CVE Images
  • Cloudsmith1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Cloud-native artifact mgmt & software supply chain security platform.
    Cloudsmith
  • Codenotary3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered agentic orchestrator for IT automation with MCP, API, and CLI tools
    Codenotary Trustcenter
  • Cycode12 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security posture management and software supply chain security.
    CI/CD SecurityCycode CI/CD Security
  • DigiCert8 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Platform for managing 20+ types of publicly trusted digital certificates.
    DigiCert Software Trust Manager
  • EdgeBit1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    SCA & supply chain security platform for vuln detection, SBOM, and autofix.
    EdgeBit
  • Endor Labs7 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Software supply chain and ASPM.
    Endor Malware PreventionEndor SBOM & Compliance
  • Hunted Labs1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Detects foreign adversarial influence in open source software dependencies.
    Hunted Labs
  • JFrog5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    App security testing platform with SAST, SCA, secrets detection, and IaC scanning
    JFrog AppTrust Application Risk GovernanceJFrog ArtifactoryJFrog Software Supply Chain Platform
  • Karambit.AI1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Static binary analysis tool detecting behavioral changes in SW supply chain.
    Karambit.AI
  • Koi1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Tracks, governs, and secures software installs across endpoints and marketplaces.
    Koi Platform
  • Kosai1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Automated CVE patching for open source software components
    Kosai CVE-Free Open Source Software
  • Kusari5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Software supply chain security: a command center over the full transitive dependency graph with PR-embedded review, natural-language queries, and autonomous fixes.
    Kusari PlatformKusari InspectorKusari AgentKusari AutoFixKusari Software Supply Chain Security
  • Labrador Labs4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Integrated portal for open source vulnerability analysis and action plan mgmt.
    Labrador SCM
  • Legit Security9 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security posture and software supply chain.
    Legit Software Supply Chain SecurityLegit Security Continuous ComplianceLegit Security Software Supply Chain Security
  • Lineaje9 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Software supply chain management and SBOM.
    Gold Open SourceSCA360SBOM360Third Party Risk ManagerLineaje AILineaje Gold Open Source
  • Manifest5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Creates structured inventories of AI system components for transparency & risk mgmt
    Manifest Cyber Manifest PlatformManifest SBOMs
  • Mend6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security (SCA/SAST), formerly WhiteSource.
  • Minimus5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Minimal, secure container/application images.
    Minimus Hardened Container ImagesMinimus Image GalleryMinimus Supply Chain ProtectionMinimus Continuous Vulnerability Scanning
  • NetRise1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Binary code analysis platform for software supply chain security and SBOM gen.
    NetRise Platform
  • OPSWAT18 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Critical-infrastructure and OT protection on the MetaDefender platform: file security/CDR, OT security, industrial firewall, optical diode, and network access control.
    OPSWAT MetaDefender Software Supply Chain
  • Ox Security6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security posture management and supply chain.
    OX SBOMOX Software Supply Chain Security
  • Reliable Energy Analytics2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Patented SCRM tool that scores software supply chain trust via 62 risk factors.
    Reliable Energy Analytics SAGSAG-PM (Software Assurance Guardian Point Man)
  • ReversingLabs8 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Software supply chain security and binary/malware analysis.
    Spectra AssureReversingLabs Spectra Assure®
  • Root.io3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Automated vulnerability patching for open-source libraries and containers
    Root Image Drift
  • scribe security1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    SBOM management platform with enrichment, validation, and CI/CD security
    Scribe Platform
  • SignPath1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Policy-driven code signing & CI/CD pipeline integrity platform.
    SignPath Zero Trust Software Integrity
  • Snyk11 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Developer-first application security (SCA/SAST).
  • Socket1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Software supply chain / dependency security.
    Socket
  • Source Defense4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Client-side security for websites against 3rd party vendor attacks
    Source Defense Source Defense Detect
  • StepSecurity1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    CI/CD security platform for GitHub Actions with runtime threat detection
    StepSecurity CI/CD Security
  • Tacit1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Tacit unifies software supply chain security through structured vulnerability management.
    Tacit
  • Veracode12 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security testing and management.
    Veracode Package FirewallVeracode Secure Your Software Supply Chain
  • Wiz8 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Agentless cloud security platform (CNAPP).
    Wiz Supply Chain Security
  • Xygeni1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Secures CI/CD pipelines and DevOps workflows against supply chain attacks
    Xygeni CI/CD Security