Software supply chain security
Protection of build pipelines, artifacts, container images and package ecosystems against tampering and malicious components.
8 vendors · alphabetical, never ranked
- Aqua SecurityAqua Security sells a cloud native application protection platform that scans code, images and cloud workloads before deployment and enforces policy on running containers, virtual machines and serverless functions at runtime, along with a separate module for AI usage governance.Privately held
- ChainguardChainguard sells hardened, rebuilt-from-source versions of open-source software, including container images, language libraries, virtual machine images, OS packages, CI/CD actions, and AI agent skills, aimed at reducing the attack surface these components introduce.Privately held · primary category
- CycodeCycode sells an application security platform that combines testing, software supply chain security, and posture management, using deterministic and AI scanning engines to correlate findings from code to runtime.Ownership not established
- Finite StateFinite State sells a platform that analyzes firmware, binaries, source code and supplier software bills of materials to find vulnerabilities in connected devices and software supply chains, producing SBOMs and remediation guidance for engineering teams.Ownership not established
- Legit SecurityLegit Security sells an application security posture management platform that discovers AppSec issues across code, secrets, and cloud, coordinates and de-duplicates findings from other scanning tools, and automates remediation and policy enforcement across the software development lifecycle.Ownership not established
- SnykSnyk sells a platform for application security that combines static code analysis, open-source dependency scanning, container and infrastructure-as-code checks, and secrets detection engines, alongside newer tools aimed at code generated by AI assistants and autonomous coding agents.Ownership not established
- SonatypeSonatype sells software composition analysis and repository management tools that control which open-source components, containers, and AI models developers and AI agents pull into production.Ownership not established
- VeracodeVeracode sells an application security platform covering static and dynamic testing, software composition analysis, and container and infrastructure-as-code scanning.Owned by Thoma Bravo since 2019
No vendor pays to be listed or to change what we write. Descriptions are ours, drawn from each company's own site and filings. Corrections: /corrections.