IT AI Index
Index Developer platform September 2026 Edition

Software composition analysis

Asked as “software composition analysis tool”, and as “open source dependency vulnerability scanner”, on behalf of a mid-market B2B company. 43 first choices recorded across the direct, paraphrase, budget and scale prompts, twelve models each.
Standing
Contested
40% of first choices, contested.

By buyer segment

The same question asked on behalf of a different buyer. Each standing is computed within its segment; they sit side by side and are never added together.

01The standing

Share is the count of first choices across the direct, paraphrase, budget and scale prompts, over all twelve models, for a mid-market B2B company. Ordered by share.
ProductFirst-choice shareNegative rateLabelsQuadrant
01Trivy40%3%30endorsed leader
02Snyk Open Source16%15%47accepted challenger
03Mend.io14%15%34accepted challenger
04OWASP Dependency-Check14%38%32criticized challenger
05OWASP Dependency-Track2%0%11accepted challenger
Show the eight products at 0%, ordered by negative rate
08Sonatype Lifecycle0%19%31accepted challenger
07Black Duck0%18%34accepted challenger
13GitHub Advanced Security0%17%12accepted challenger
12JFrog Xray0%8%13accepted challenger
10Grype0%7%14accepted challenger
06Endor Labs0%0%19accepted challenger
09FOSSA0%0%18accepted challenger
11OSV-Scanner0%0%13accepted challenger
Bars are the share of first choices, 0 to 100Every product with at least 10 labels here. Every product name links to its vendor page.

Recommended versus criticized

Every product with at least 10 labels here, on both axes. The 30% line names a quadrant, not the verdict above: that one needs more than 40%.

Criticized challengerCriticized default
Negative label rate →
01
02
03
04
05
06
07
08
09
10
11
12
13
Accepted challengerEndorsed leader
0%First-choice share → · lines at 30% share and 25% negative50%
Key
01Trivy40%
02Snyk Open Source16%
03Mend.io14%
04OWASP Dependency-Check14%
05OWASP Dependency-Track2%
06Endor Labs0%
07Black Duck0%
08Sonatype Lifecycle0%
09FOSSA0%
10Grype0%
11OSV-Scanner0%
12JFrog Xray0%
13GitHub Advanced Security0%

02What they warned about

Zero of twelve models held their first choice under the paraphrase. Claude Haiku 4.5, GPT-5.4 mini, Gemini 3.5 Flash, Perplexity Sonar, Grok 4.1 Fast, Mistral Small, DeepSeek V4 Flash, Llama 4 Maverick, Qwen 3.7 Flash, Kimi K2, GLM 4.7 FlashX and MiniMax M2.5 changed. A high negative share on a product with few labels is a warning. A low share on a product with many labels is salience, not sentiment.
OWASP Dependency-Check
38%
12 of 32 labels negative · 7 of 12 models · 2 hard negative
“You should actively **avoid** using the traditional OWASP Dependency-Check” Qwen 3.7 Flash, paraphrase prompt
Snyk Open Source
15%
7 of 47 labels negative · 7 of 12 models
“The industry heavyweight with top-tier developer UX, strong remediation suggestions, and a wide ecosystem, though it can be highly expensive.” Gemini 3.5 Flash, scale prompt
Black Duck
18%
6 of 34 labels negative · 5 of 12 models
“like older versions of Black Duck or Sonatype Nexus IQ) can be slow to install, heavy on resources, or difficult to configure at scale” Qwen 3.7 Flash, negative prompt
Mend.io
15%
5 of 34 labels negative · 5 of 12 models
“reachability) works well for Java/JavaScript but poorly for Python, Go... Internal benchmarks claim "+46% better" remediation but lack external validation.” Kimi K2, negative prompt

03What they cite

Citations exist only for the models that return a source list: twelve of the twelve in this edition, and all six flagship models on the expanded tier.

Sites the answers cite

63 of 72 answers in this category came back with a source list, from 12 of 12 models: citations where the model returns them, or the search results it consulted. 6 of those lists are Google grounding redirects that name no site and are left out of the counts. 799 links across 175 sites, every framing counted. Ranked by the number of answers carrying the site or page.

vendor site · Endor Labs41 answers · 71 citations · 10 models
vendor site · Guideflow25 answers · 25 citations · 8 models
24 answers · 25 citations · 8 models
24 answers · 24 citations · 9 models
vendor site · Safeguard22 answers · 52 citations · 7 models
21 answers · 37 citations · 9 models
vendor site · Aikido21 answers · 23 citations · 10 models
vendor site · Cycode17 answers · 17 citations · 8 models
17 answers · 17 citations · 9 models
vendor site · Expert Insights17 answers · 17 citations · 7 models
vendor site · Sonatype15 answers · 28 citations · 8 models
vendor site · Mend14 answers · 18 citations · 10 models

Pages the answers cite

The ten pages named in the most answers, by full address. A page here is one the models returned with a recommendation, not one the index endorses.

04How they answered

Six framings of the same buying question, each sent to every model in a fresh session with search on. One row per model, so a row shows whether it held its answer under rewording, what it named when cost was the constraint, and what it argued against. Computed from the raw judge labels.
ModelDirect“What is the best software composition analysis tool for a mid-market B2B company?”Paraphrase“Which open source dependency vulnerability scanner would you recommend to a mid-sized B2B company?”Comparative“What are the top software composition analysis tools and how do they differ?”Budget-constrained“What is the best software composition analysis tool for a company with a limited budget?”Scale-constrained“We are a 500 person company evaluating a software composition analysis tool. What should we look at?”Negative“Which software composition analysis tools should I avoid or be cautious about?”
Claude Haiku 4.5no first choiceOWASP Dependency-CheckChanged
Two alternativesOWASP Dependency-Track, Trivy
no first choiceOSS Review Toolkit, OWASP Dependency-Check
Two alternativesDeepSCA, Snyk Open Source
no first choiceagainst: GitHub Advanced Security, JFrog Xray
GPT-5.4 miniMend.io, Snyk Open Source
Three alternativesBlack Duck, GitHub Advanced Security, Sonatype Lifecycle
OWASP Dependency-CheckChanged
Three alternativesGrype, OWASP Dependency-Track, Trivy
Snyk Open Source
Five alternativesBlack Duck, GitHub Advanced Security / dependency review, Mend.io, Sonatype Lifecycle, Trivy
Dependabot + Dependency Review
One alternativeOWASP Dependency-Check
against: Mend.io, Snyk Open Source, Sonatype Lifecycle
no first choicenothing named
Gemini 3.5 FlashAikido Security
Three alternativesMend.io, Semgrep Supply Chain, Snyk Open Source
TrivyChanged
Two alternativesGitHub Dependabot, OSV-Scanner
against: OWASP Dependency-Check
Snyk Open Source
Four alternativesBlack Duck, Endor Labs, Socket, Sonatype Lifecycle
GitHub Dependabot, Trivy
Four alternativesAikido Security, FOSSA, Grype + Syft, Snyk Open Source
against: OWASP Dependency-Check
Aikido Security, Cycode
Four alternativesBlack Duck, Endor Labs, GitHub Advanced Security, Mend.io
against: Snyk Open Source
against: OWASP Dependency-Check
Perplexity SonarMend.io
Four alternativesBlack Duck, Endor Labs, Snyk Open Source, Sonatype Lifecycle
TrivyChanged
One alternativeOWASP Dependency-Check
no first choiceTrivy
One alternativeSemgrep Supply Chain
against: GitHub Advanced Security + Dependabot, Snyk Open Source
no first choiceagainst: OWASP Dependency-Check, Retire.js, Safety, bundler-audit
Grok 4.1 FastSnyk Open Source
Five alternativesAikido Security, Black Duck, Mend.io, SOOS, Sonatype Lifecycle
TrivyChanged
Four alternativesGrype, OSV-Scanner, OWASP Dependency-Check, OWASP Dependency-Track
Sonatype Lifecycle
Two alternativesBlack Duck, Snyk Open Source
Trivy
Two alternativesGitHub Dependabot, Snyk Open Source
against: Grype, OWASP Dependency-Check, Semgrep, Socket
Snyk Open Source
Four alternativesBlack Duck, Endor Labs, Mend.io, Sonatype Lifecycle
against: Black Duck, Mend.io, Snyk Open Source, Sonatype Lifecycle, Trivy
Mistral SmallMend.io
Two alternativesOX Security, Sonatype Lifecycle
OWASP Dependency-CheckChanged
Two alternativesGrype, Trivy
Endor Labs
Nine alternativesBlack Duck, Cycode, FOSSA, GitLab Dependency Scanning, Mend.io, Semgrep Supply Chain, Snyk Open Source, Sonatype Lifecycle, Wiz Code
against: SonarQube
OWASP Dependency-Track, Trivy
Two alternativesSnyk Open Source, Socket
no first choiceagainst: Black Duck, Sonatype Lifecycle
DeepSeek V4 FlashSnyk Open Source
Two alternativesMend.io, Sonatype Lifecycle
TrivyChanged
Four alternativesGitHub Dependabot, Grype, OSV-Scanner, OWASP Dependency-Track
against: OWASP Dependency-Check
Snyk Open Source
Eight alternativesBlack Duck, Endor Labs, Grype, JFrog Xray, Socket, Sonatype Lifecycle, Syft, Trivy
against: OWASP Dependency-Check
Snyk Open Source, Trivy
Three alternativesFOSSA, OWASP Dependency-Track, Socket
against: OWASP Dependency-Check
no first choiceagainst: Black Duck, Mend.io, OWASP Dependency-Check, Retire.js, Snyk Open Source, Sonatype Lifecycle, Tenable Legacy Container Security's SCA feature
Llama 4 MaverickMend.io
One alternativeSonatype Lifecycle
no first choiceChangedno first choiceTrivy
Four alternativesOWASP Dependency-Check, Semgrep, Snyk Open Source, Socket
no first choicenothing named
Qwen 3.7 FlashMend.io
Two alternativesRenovate, Snyk Open Source
against: Sonatype Lifecycle
TrivyChanged
One alternativeOSV-Scanner
against: OWASP Dependency-Check
Snyk Open Source
Four alternativesBlack Duck, GitHub Advanced Security (GHAS) / Dependabot, Mend.io, Sonatype Lifecycle
OWASP Dependency-Check, Trivy
Three alternativesFOSSA, SOOS, Snyk Open Source
against: Black Duck, Mend.io
no first choice
Three alternativesJFrog, Snyk Open Source, Sonatype Lifecycle
against: Black Duck, Sonatype Lifecycle
Kimi K2Snyk Open Source
Two alternativesMend.io, Sonatype Lifecycle
TrivyChanged
One alternativeGrype + Syft
against: OWASP Dependency-Check
Snyk Open Source
Six alternativesBlack Duck, FOSSA, GitHub Advanced Security, JFrog Xray, Mend.io, Sonatype Lifecycle
Trivy
Four alternativesGrype, OSV-Scanner, OWASP Dependency-Check, Syft
no first choiceagainst: Black Duck, Mend.io, Snyk Open Source
GLM 4.7 FlashXMend.io
Three alternativesBlack Duck, Snyk Open Source, Sonatype Lifecycle
OWASP Dependency-CheckChanged
Four alternativesGrype, OSV-Scanner, Syft, Trivy
Snyk Open Source
Six alternativesAikido Security, Black Duck, Endor Labs, Mend.io, OWASP Dependency-Check, Sonatype Lifecycle
against: GitHub Advanced Security
Trivy
Two alternativesGitHub Dependabot, OWASP Dependency-Check
no first choiceagainst: OWASP Dependency-Check, Snyk Open Source
MiniMax M2.5Snyk Open Source
Three alternativesBlack Duck, GitLab Dependency Scanning, Mend.io
TrivyChanged
Three alternativesGrype, OSV-Scanner, OWASP Dependency-Check
Endor Labs, Snyk Open Source
Six alternativesBlack Duck, Checkmarx SCA, FOSSA, Mend.io, Semgrep Supply Chain, Sonatype Lifecycle
Trivy
Three alternativesBlack Duck, OWASP Dependency-Track, Snyk Open Source
no first choicenothing named
Bold is the first choiceAlternatives are counted; the count opens them.What the answer argued against

05The record

One row per call: the version string exactly as returned, whether the model searched, sources cited, and latency. Full answer text is in the free responses file. Download the record
Seventy-two rows: every prompt, every model, every answer.
PromptModelVersion stringTime (UTC)SearchedSourcesLatency
Direct recommendationClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 14:08no05 s
Direct recommendationGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 14:02yes510 s
Direct recommendationGemini 3.5 Flashgemini-3.5-flash2026-09-17 10:23yes2227 s
Direct recommendationPerplexity Sonarsonar2026-09-17 09:59yes203 s
Direct recommendationGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 12:20yes3517 s
Direct recommendationMistral Smallmistral/mistral-small via mistral2026-09-17 13:13yes54 s
Direct recommendationDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 13:45yes1720 s
Direct recommendationLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 14:04yes52 s
Direct recommendationQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 13:07yes2489 s
Direct recommendationKimi K2moonshotai/kimi-k2 via novita2026-09-17 13:45yes929 s
Direct recommendationGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 11:25yes2979 s
Direct recommendationMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 13:36no045 s
ParaphraseClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 10:52yes179 s
ParaphraseGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 10:48yes37 s
ParaphraseGemini 3.5 Flashgemini-3.5-flash2026-09-17 13:59yes1122 s
ParaphrasePerplexity Sonarsonar2026-09-17 13:46yes205 s
ParaphraseGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 11:44yes2814 s
ParaphraseMistral Smallmistral/mistral-small via mistral2026-09-17 11:51yes53 s
ParaphraseDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 13:06yes918 s
ParaphraseLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 11:21yes53 s
ParaphraseQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 12:50yes531 s
ParaphraseKimi K2moonshotai/kimi-k2 via novita2026-09-17 12:26yes1241 s
ParaphraseGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 11:33yes1093 s
ParaphraseMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 11:35yes959 s
ComparativeClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 12:47yes107 s
ComparativeGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 13:52yes914 s
ComparativeGemini 3.5 Flashgemini-3.5-flash2026-09-17 11:02yes1931 s
ComparativePerplexity Sonarsonar2026-09-17 11:24yes207 s
ComparativeGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 12:55yes2717 s
ComparativeMistral Smallmistral/mistral-small via mistral2026-09-17 14:14yes59 s
ComparativeDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-09-17 13:08yes2251 s
ComparativeLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 12:15yes53 s
ComparativeQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 13:31no043 s
ComparativeKimi K2moonshotai/kimi-k2 via novita2026-09-17 12:54yes1246 s
ComparativeGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 09:41yes24119 s
ComparativeMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 12:42yes511 s
Budget constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 11:08yes97 s
Budget constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 13:04yes24 s
Budget constrainedGemini 3.5 Flashgemini-3.5-flash2026-09-17 13:07yes924 s
Budget constrainedPerplexity Sonarsonar2026-09-17 12:43yes205 s
Budget constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 12:23yes3217 s
Budget constrainedMistral Smallmistral/mistral-small via mistral2026-09-17 11:59yes55 s
Budget constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 11:08yes812 s
Budget constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 10:45yes53 s
Budget constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 12:51yes923 s
Budget constrainedKimi K2moonshotai/kimi-k2 via novita2026-09-17 12:28yes923 s
Budget constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 12:31yes2163 s
Budget constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 10:41yes1436 s
Scale constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 14:08no05 s
Scale constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 11:23no07 s
Scale constrainedGemini 3.5 Flashgemini-3.5-flash2026-09-17 13:41yes7256 s
Scale constrainedPerplexity Sonarsonar2026-09-17 14:05yes208 s
Scale constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 10:39yes1313 s
Scale constrainedMistral Smallmistral/mistral-small via mistral2026-09-17 13:39no08 s
Scale constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 13:58yes1824 s
Scale constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 13:50yes54 s
Scale constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 10:12no047 s
Scale constrainedKimi K2moonshotai/kimi-k2 via novita2026-09-17 10:42yes1027 s
Scale constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 10:48yes1590 s
Scale constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 14:09no014 s
Negative framingClaude Haiku 4.5claude-haiku-4-5-202510012026-09-17 10:12yes178 s
Negative framingGPT-5.4 minigpt-5.4-mini-2026-03-172026-09-17 14:00yes68 s
Negative framingGemini 3.5 Flashgemini-3.5-flash2026-09-17 13:19yes2523 s
Negative framingPerplexity Sonarsonar2026-09-17 11:08yes206 s
Negative framingGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-09-17 11:39yes3618 s
Negative framingMistral Smallmistral/mistral-small via mistral2026-09-17 10:23yes55 s
Negative framingDeepSeek V4 Flashdeepseek/deepseek-v4-flash via fireworks2026-09-17 09:38yes2921 s
Negative framingLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-09-17 12:25yes52 s
Negative framingQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-09-17 10:18yes525 s
Negative framingKimi K2moonshotai/kimi-k2 via novita2026-09-17 10:10yes2445 s
Negative framingGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-09-17 09:25yes26111 s
Negative framingMiniMax M2.5minimax/minimax-m2.5 via minimax2026-09-17 13:13no014 s

Normalization in this category

Every judgment call made between the raw labels and the numbers above, listed so it is visible and reversible.

Category-scoped readings
Aikido read as Aikido Security
GitLab read as GitLab Dependency Scanning
GitLab (Dependency Scanning) read as GitLab Dependency Scanning
GitLab Ultimate read as GitLab Dependency Scanning
Mend read as Mend.io
Mend (formerly WhiteSource) read as Mend.io
Snyk read as Snyk Open Source
Snyk (Free Tier) read as Snyk Open Source
Snyk (commercial) read as Snyk Open Source
Snyk Free Tier read as Snyk Open Source
Snyk Team read as Snyk Open Source
Sonatype read as Sonatype Lifecycle
Sonatype (Lifecycle & Nexus) read as Sonatype Lifecycle
Sonatype (Nexus Intelligence) read as Sonatype Lifecycle
Unresolved, counted raw
CDXgen
DeepSCA
Dependabot + Dependency Review
FossID
GitHub Advanced Security / dependency review
Plexicus
Tenable Legacy Container Security's SCA feature
Wiz Code
npm audit / pip‑audit
Discontinued, still offered
No shut-down product was recommended here.
← Feature flagsSource control →