+
+

Related Products

  • Wiz
    1,062 Ratings
    Visit Website
  • Aikido Security
    120 Ratings
    Visit Website
  • Source Defense
    7 Ratings
    Visit Website
  • Chainguard
    43 Ratings
    Visit Website
  • ZeroPath
    2 Ratings
    Visit Website
  • Jscrambler
    33 Ratings
    Visit Website
  • Nutrient SDK
    98 Ratings
    Visit Website
  • Docmosis
    48 Ratings
    Visit Website
  • cside
    23 Ratings
    Visit Website
  • Macaw AMS
    5 Ratings
    Visit Website

About

With the lowest false positive software composition analysis (SCA) scanner, comprehensive software bill of materials (SBOM) engine, and patented Java Dynamic Application Hardening capability, MergeBase provides the only software supply chain security solution offering real-time DevSecOps visibility of third-party risk from development into operation covering all major languages from C/C++, .NET, JavaScript/NPM to Java.

About

Phylum defends applications at the perimeter of the open-source ecosystem and the tools used to build software. Its automated analysis engine scans third-party code as soon as it’s published into the open-source ecosystem to vet software packages, identify risks, inform users and block attacks. Think of Phylum like a firewall for open-source code. Phylum’s database of open-source software supply chain risks is the most comprehensive and scalable offering available, and can be deployed throughout the development lifecycle depending on an organization’s infrastructure and appsec program maturity: in front of artifact repository managers, directly with package managers or in CI/CD pipelines. The Phylum policy library allows users to toggle on the blocking of critical vulnerabilities, attacks like typosquats, obfuscated code and dependency confusion, copyleft licenses, and more. Users can also leverage OPA to create custom policies.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

Developers and companies seeking a solution to manage their coding, building, and deployment process supply chain

Audience

Companies who are looking to secure the use open-source software, and address software supply chain risks associated with malicious software packages and zero-day vulnerabilities

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

$380 per month
Free Version
Free Trial

Pricing

No information available.
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

MergeBase
Founded: 2018
Canada
mergebase.com/sca-platform/

Company Information

Phylum
Founded: 2020
United States
phylum.io

Alternatives

Alternatives

Xygeni

Xygeni

Xygeni Security
Revenera SCA

Revenera SCA

Revenera
CodeSentry

CodeSentry

CodeSecure

Categories

Categories

Application Security Features

Analytics / Reporting
Open Source Component Monitoring
Source Code Analysis
Third-Party Tools Integration
Training Resources
Vulnerability Detection
Vulnerability Remediation

DevOps Features

Approval Workflow
Dashboard
KPIs
Policy Management
Portfolio Management
Prioritization
Release Management
Timeline Management
Troubleshooting Reports

Integrations

Bitbucket
GitHub
GitLab
Go
Java
JavaScript
Python
Ruby
Cargo
Docker
Elixir
GO hourly
JFrog Artifactory
Jenkins
Jira
NuGet
Rust
Slack
Sonatype Nexus Repository Community Edition
TypeScript

Integrations

Bitbucket
GitHub
GitLab
Go
Java
JavaScript
Python
Ruby
Cargo
Docker
Elixir
GO hourly
JFrog Artifactory
Jenkins
Jira
NuGet
Rust
Slack
Sonatype Nexus Repository Community Edition
TypeScript
Claim MergeBase and update features and information
Claim MergeBase and update features and information
Claim Phylum and update features and information
Claim Phylum and update features and information