No more typing reviews! Try our Samantha, our new voice AI agent.

Top 5 Software Composition Analysis (SCA) Solutions 2022

NC
Content Manager at PeerSpot
  • 31
Published:Apr 19, 2022
Product comparison that may be of interest to you
PeerSpot user
PeerSpot user
Find out what your peers are saying about Snyk, Black Duck, Veracode and others in Software Composition Analysis (SCA). Updated: March 2026.
885,376 professionals have used our research since 2012.
Related Questions
Julia Miller - PeerSpot reviewer
Community Director at PeerSpot
Dec 7, 2025
Dec 7, 2025
From my experience, the licensing side is pretty straightforward to handle. Most of the cost and pricing considerations really come down to how the solution is deployed. Since we work with partners and other OEMs who help run Sonatype Lifecycle through their services, the final pricing details are usually best explained by the sales teams who manage pricing and licensing more directly.
See 2 answers
AJ
DevOps engineer at a tech vendor with 10,001+ employees
Apr 24, 2025
Pricing is out of my context as a developer. This is known by the project managers.
@RahulVerma  - PeerSpot reviewer
Presales Engineer at Rah Infotech Pvt Ltd
Dec 7, 2025
From my experience, the licensing side is pretty straightforward to handle. Most of the cost and pricing considerations really come down to how the solution is deployed. Since we work with partners and other OEMs who help run Sonatype Lifecycle through their services, the final pricing details are usually best explained by the sales teams who manage pricing and licensing more directly.
TM
Works at Network Appliance ASIAPAC
May 16, 2023
May 16, 2023
@Tej Muchhala ​: Code Quality and Security are 2 different domains and depending on how deep you want to go, the choice of tools will vary.1. SonarQube - This has both community editions and commercial editions. The community has limited scope and no reporting. The enterprise version has a far broader scope covered with excellent reporting capabilities. SQ does have rules to compare against OWA...
2 out of 3 answers
May 15, 2023
Hi Tej, as per my experience, SonarQube provides a better understanding of the code, it gives you a detailed analysis of the code up to the line level. It finds vulnerabilities in the code and runs test cases for you (if you add them). Also, you can customize the quality gate rules to define the parameters your code should pass like reliability, repetition of lines, etc. On the other hand, Snyk offers you an overview of the tools you are using, or the APIs you are using inside the code and gives vulnerability notifications and fixes. SonarQube doesn't fix or doesn't give any suggestions but Snyk will give you suggestions on which version of that dependency should be used and why. I have integrated both Snyk and SonarQube as both are open source up to a certain level. 
LL
Board Member at a tech vendor with 1,001-5,000 employees
May 15, 2023
Hi Tej, you should also check out CAST (castsoftware.com). Their kit does a very thorough analysis that may be a good option depending on the complexity of your codebase. 
Product Comparisons
Download Free Report
Download our free Software Composition Analysis (SCA) Report and find out what your peers are saying about Snyk, Black Duck, Mend.io, and more! Updated: March 2026.
DOWNLOAD NOW
885,376 professionals have used our research since 2012.