OWASP dep-scan vs Veracode DAST

OWASP dep-scan

7.1 #21 in Software Composition Analysis Software

About OWASP dep-scan

Veracode DAST

7.4 #13 in Software Composition Analysis Software

About Veracode DAST
OWASP dep-scanVeracode DAST
Free planYes
Free trialNoYes
Paid fromFree
Platformsapi, Linux, macOS, self-hosted, Windowsapi, Linux, macOS, Web, Windows
Free planYesNo
Supported ecosystemsNode.js, Java/JVM, PHP, Python, Go, Ruby, Rust, .NET, Dart, Haskell, Elixir, C/C++, Clojure, Docker/OCI, GitHub Actions, Jenkins, YAML manifestsC#/.NET (DLL, NuGet); C/C++ (Make); Go (Dep, Glide, go get, Go modules, GoDep, GoVendor, Trash); Java (Ant, Gradle, JARs, Maven); JavaScript (Bower, NPM, Yarn); Kotlin (Gradle, JARs, Maven); Objective-C (CocoaPods); PHP (Composer); Python (pip, Pipenv, Poetry); Ruby (Bundler); Scala (JARs, SBT); Swift (CocoaPods); TypeScript (Bower, NPM, Yarn)
SBOM generationYesYes
Reachability analysisYesYes
Deployment optionsself_hostedcloud
Pull request scanningYes
Authenticated scanningYes
API testingYes
Browser-based scanningYes
CI/CD integrationYes
Deployment modelhybrid
Deploymentsaas
Instrumentationagent
Language coveragelanguage-agnostic agent; specific supported languages not published
Analysis targetssource code, bytecode, binaries
Pull request scansYes
IDE supportYes
Custom security rulesYes
Automated fixesYes
Custom rulesYes

Listed together in Best Software Composition Analysis Software