Black Duck SCA vs CVE Binary Tool
| Black Duck SCA | CVE Binary Tool | |
|---|---|---|
| Free plan | No | No |
| Free trial | No | No |
| Paid from | — | — |
| Open source | No | No |
| Platforms | Web, Windows, macOS, Linux | Linux, Windows |
| Supported ecosystems | BitBake, Cargo, Carthage, CocoaPods, Conan, Conda, CPAN, CRAN, Dart, Go, Gradle, Hex, Ivy, Lerna, Maven, npm, NuGet, Packagist, PEAR, pip, pnpm, Poetry, RubyGems, SBT, Setuptools, Swift, Yarn, Xcode, OPAM, UV, Rush | Dart (pubspec.lock); Go (go.mod); Java (pom.xml, JAR/WAR/EAR); JavaScript (package-lock.json, yarn.lock); OpenWrt opkg (.control); Perl (cpanfile); Python (requirements.txt, PKG-INFO, METADATA, .whl, .egg); Rust (Cargo.lock); Ruby (Gemfile.lock); R (renv.lock); Swift (Package.resolved); Windows PE (.pyd) |
| SBOM generation | Yes | Yes |
| Reachability analysis | Yes | — |
| Pull request scanning | Yes | Yes |
| Deployment options | hybrid | self_hosted |
| Free plan | — | Yes |
Both are listed in Best Software Composition Analysis Software. On Samsung Mobile US Press, Black Duck SCA scores higher on our published basis.