Software supply chain attacks are on the rise and with it, the need to build transparent, evidence-based trust in software.
Cost / License
- Paid
- Proprietary
Platforms
- Mac
- Linux
- Online
- Google Chrome
- Software as a Service (SaaS)

Software supply chain attacks are on the rise and with it, the need to build transparent, evidence-based trust in software.

ReARM is an abbreviation for "Reliza's Artifact and Release Management". It is a Release Governance Platform to manage lifecycle for product and component releases and organize release metadata, including SBOMs, xBOMs, other security artifacts, vulnerability...


Mend.io offers the first AI native application security platform, purpose-built to secure AI-generated code and embedded AI components. Our unified platform enables companies to manage application risk effectively in modern software development.



European artifact repository SaaS for secure software supply chains, with package repositories, SBOMs, vulnerability visibility, access control, and CRA-relevant workflows.




sbomify is the trust center for your software supply chain. Store every SBOM and compliance document in one place, track them across products and releases, and share them with customers and regulators on demand. CycloneDX and SPDX, built for EU CRA compliance.




Generates SBOMs during CI from lockfiles, containers, and directories using native tooling with ecosystem coverage, metadata enrichment, trusted outputs, and OIDC publishing.

SCANOSS is the first affordable, open OSS Inventory & Intelligence platform that was built specifically for modern DevSecOps and supply chains. Empowering them to deliver greater license, security, quality and provenance visibility and control for DevSecOps teams and their...

