Snyk is a developer-first security company that helps software-driven businesses develop fast and stay secure.
Contact for pricing
GitHub Dependabot monitors repository dependencies for known vulnerabilities and outdated versions. It is designed for teams already using GitHub that want alerts and automated pull requests to update dependencies.
Snyk is a developer-first security company that helps software-driven businesses develop fast and stay secure.
Contact for pricing
Retire.js project
Retire.js is an open-source vulnerability scanner for outdated JavaScript libraries in web pages, source trees, and package manifests. It provides command-line, Grunt,...
Socket analyzes open-source packages for known vulnerabilities and suspicious supply-chain behavior. It targets development and security teams that need package-risk analysis, dependency...
Freemium, paid plans available
OWASP Dependency-Check is a software composition analysis tool that identifies vulnerable components in applications.
Google Open Source Security Team
OSV-Scanner is an open-source tool that finds known vulnerabilities in project dependencies using the OSV vulnerability database. It is intended for developers...
Free, open source
npm
npm audit checks Node.js project dependencies against the npm security advisory database. It is built into npm and suits JavaScript developers who...
Your feedback helps us improve the AI rankings.
β Thanks for your feedback!
Suggest a product and our AI will verify it's a real alternative to GitHub Dependabot before adding it to the list.