Our business has been growing quickly, and I’ve been thrown into the deep end with evaluating Software Composition Analysis (SCA) tools. It’s a new challenge for me, and I’m hoping to get some advice from those who’ve been down this road before..
I’ve heard about Snyk and Black Duck, but I’m curious what other tools people are using and how they stack up. Specifically, I’m interested in hearing about your experiences with these tools. How do they differ, and which ones are better at identifying CVEs versus actually mitigating risks in open source packages?
Also, what do you think are the must-have features in an SCA tool? Are any of these tools open source, and do they help you prioritize the severity of issues? If they do, do you find that info useful in practice? Have heard about Chainguard and Endor if any have used them..
Thanks a bunch for any insights you can share!
I recently did a demo of Snyk and ran some initial scans on our codebase. It identified a lot of vulnerabilities, mostly CVEs – like issues with our dependencies, but I found it challenging to prioritize which issues were the most critical.
I was hoping for more guidance on mitigating risks and better tools to help contextualize and prioritize the severity of issues. Specifically, I expected features that would help me understand which vulnerabilities needed immediate attention and how to address them effectively.
secondwind2 is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.