AI Indexes
IT AI Index
October 2026 Edition · The permanent record of this edition. The unqualified address always carries the latest edition.
Index › Developer platform › October 2026 Edition

Software composition analysis

Asked as “software composition analysis tool”, and as “open source dependency vulnerability scanner”, on behalf of a mid-market B2B company. 51 first choices recorded across the direct, paraphrase, budget and scale prompts, fourteen models each.
Standing · first-choice share
31%
Contested · Snyk Open Source 16%
31Trivy16Snyk Open Source14Mend.io39others

31% of first choices, contested.

Since September 2026▼−5Since September 2026: 40% → 34%, −5 points. Inside the 11-point floor: within noise. Read over the models both editions asked.Trivy held the lead, −5 points on 40%, inside the 11-point floor.

By buyer segment

The same question asked on behalf of a different buyer. Each standing is computed within its segment; they sit side by side and are never added together.

The standing

Share is the count of first choices across the direct, paraphrase, budget and scale prompts, over all fourteen models, for a mid-market B2B company. Ordered by share.
ProductFirst-choice shareNegative rateLabelsQuadrantSince September 2026
01Trivy31%11%27endorsed leader▼−5Since September 2026: 40% → 34%, −5 points. Inside the 11-point floor: within noise. Read over the models both editions asked.40% → 34%
02Snyk Open Source16%16%55accepted challenger=heldSince September 2026: 16% → 16%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.16% → 16%
03Mend.io14%19%37accepted challenger=heldSince September 2026: 14% → 14%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.14% → 14%
04OWASP Dependency-Track8%0%21accepted challenger▲+4Since September 2026: 2% → 7%, +4 points. Inside the 11-point floor: within noise. Read over the models both editions asked.2% → 7%
05OWASP Dependency-Check8%23%35accepted challenger▼−5Since September 2026: 14% → 9%, −5 points. Inside the 11-point floor: within noise. Read over the models both editions asked.14% → 9%
06GitHub Dependabot8%18%17accepted challenger=heldSince September 2026: 5% → 5%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.5% → 5%
07Sonatype Lifecycle2%9%32accepted challenger▲+2Since September 2026: 0% → 2%, +2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 2%
08GitHub Advanced Security2%6%18accepted challenger▲+2Since September 2026: 0% → 2%, +2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 2%
09OSV-Scanner2%0%12accepted challenger▲+2Since September 2026: 0% → 2%, +2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 2%
10Socket2%0%12accepted challenger▲+2Since September 2026: 0% → 2%, +2 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 2%
Show the seven products at 0%, ordered by negative rate
14Black Duck0%32%38criticized challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
17Checkmarx SCA0%20%15accepted challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
15JFrog Xray0%8%13accepted challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
13FOSSA0%5%19accepted challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
11Grype0%0%16accepted challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
12Endor Labs0%0%14accepted challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
16Syft0%0%10accepted challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%

The floor is 11 points of share, measured: how far the models move a leader on their own when the same questions are asked twice with nothing changed. A larger change is movement; a smaller one is noise, and both are shown. Movement is read over the twelve models both editions asked; GPT-6 Luna, Muse Glimmer 30B joined this edition and are in the standing but not yet in the comparison. How the floor is measured

Bars are the share of first choices, 0 to 100Every product with at least 10 labels here. Every product name links to its product page.
All twenty-eight head-to-head pages: the top eight products, each against each

Recommended versus criticized

Every product with at least 10 labels here, on both axes. The 30% line names a quadrant, not the verdict above: that one needs more than 40%.

Criticized challengerCriticized default
Negative label rate →
01
02
03
04
05
06
07
08
09
10
G11
12
13
14
15
S16
17
Accepted challengerEndorsed leader
0%First-choice share → · lines at 30% share and 25% negative50%
Key
01Trivy31%
02Snyk Open Source16%
03Mend.io14%
04OWASP Dependency-Track8%
05OWASP Dependency-Check8%
06GitHub Dependabot8%
07Sonatype Lifecycle2%
08GitHub Advanced Security2%
09OSV-Scanner2%
10Socket2%
11Grype0%
12Endor Labs0%
13FOSSA0%
14Black Duck0%
15JFrog Xray0%
16Syft0%
17Checkmarx SCA0%

What they warned about

Zero of fourteen models held their first choice under the paraphrase. Claude Haiku 4.5, GPT-5.4 mini, Gemini 3.5 Flash, Perplexity Sonar, Grok 4.1 Fast, Mistral Small, DeepSeek V4 Flash, Llama 4 Maverick, Qwen 3.7 Flash, Kimi K2, GLM 4.7 FlashX, MiniMax M2.5, GPT-6 Luna and Muse Glimmer 30B changed. A high negative share on a product with few labels is a warning. A low share on a product with many labels is salience, not sentiment.
Snyk Open Source
16%
9 of 55 labels negative · 8 of 14 models
“enterprise buyers often cite "unpredictable ballooning costs"... some procurement models recommend avoiding it if strict cost-prediction budgets are required” Qwen 3.7 Flash, negative prompt
Black Duck
32%
12 of 38 labels negative · 7 of 14 models · 1 hard negative
“Tools/Approaches to Be Cautious About ... Black Duck (Synopsys) ... Slow scanning ... Complicated pricing” Kimi K2, negative prompt
Mend.io
19%
7 of 37 labels negative · 6 of 14 models · 1 hard negative
“This is the tool that surfaces most frequently in negative developer feedback” DeepSeek V4 Flash, negative prompt
OWASP Dependency-Check
23%
8 of 35 labels negative · 6 of 14 models
“useful as a free scanner, but I'd avoid treating its results as definitive ... can produce both false positives and false negatives” GPT-6 Luna, negative prompt

What they cite

Citations exist only for the models that return a source list: fourteen of the fourteen in this edition, and all six flagship models on the expanded tier.

Sites the answers cite

79 of 84 answers in this category came back with a source list, from 14 of 14 models: citations where the model returns them, or the search results it consulted. 1073 links across 228 sites, every framing counted. Ranked by the number of answers carrying the site or page. 3 of the 252 answers across every segment cited this index's own page for the category; the method page measures whether that reading tilts an answer.

vendor site · Guideflow42 answers · 44 citations · 11 models
vendor site · Sonatype34 answers · 48 citations · 12 models
vendor site · Endor Labs32 answers · 45 citations · 12 models
vendor site · Mend28 answers · 34 citations · 14 models
vendor site · Checkmarx28 answers · 30 citations · 11 models
vendor site · Safeguard27 answers · 43 citations · 10 models
25 answers · 25 citations · 10 models
24 answers · 32 citations · 10 models
23 answers · 23 citations · 10 models
vendor site · G218 answers · 29 citations · 9 models
vendor site · Aikido18 answers · 21 citations · 9 models
vendor site · OX18 answers · 18 citations · 9 models

Pages the answers cite

The ten pages named in the most answers, by full address. A page here is one the models returned with a recommendation, not one the index endorses.

Search against answers

Each company's standing in the answers beside its site's footprint in Google search, one row a site: the products the models named on it with their shares, and the share they add up to; monthly searches on Google, and DataForSEO's estimate of AI search demand (modeled from search signals, directional, not a count of queries to any assistant), for the most-searched of the company's and its products' names (the name is in each row's hover text); estimated monthly organic visits to the site; and its best position in Google's top ten for “best software composition analysis tool”, “software composition analysis tool”, “software composition analysis tools”. US estimates from DataForSEO and Google's Ads Transparency Center. A small company's site, or a mid-sized company's site for its flagship, is marked company; a product on a large parent's site (Google, Microsoft) has no site figures. A column with no figures for this category is left out, and an empty cell means none were seen, not none exist. Two measurements side by side: neither is read as the cause of the other.
Company and productsShareOwn site citedName searches, GoogleAI search demand, est.Organic visitsPaid search a month, est.Google ads, last 30 daysBest Google position
Trivy trivy.dev31%2075,4001823,093
Snyk snyk.io
Snyk Open Source 16%
16%17212,10058161,651 company60
OWASP Dependency-Track owasp.org
OWASP Dependency-Track 8%, OWASP Dependency-Check 8%
16%9572010365,2223
Mend.io mend.io14%1142101115,0597
GitHub parent site
GitHub Dependabot 8%, GitHub Advanced Security 2%
10%1111,500,00031,479
Sonatype sonatype.com
Sonatype Lifecycle 2%
2%12190171,814 company$1,87978
OSV-Scanner osv.dev2%3139022749
Socket socket.dev2%3360,50095,97916,4651
Semgrep semgrep.dev
Semgrep 2%, Semgrep Supply Chain 0%
2%1948,1001913,46143
Aikido aikido.dev
Aikido Security 2%
2%3422,400516,442 company$936120

Google's top ten for the three searches hold 22 sites; 3 of them are among the sites the models cited here (endorlabs.com, ox.security, sonatype.com). The first result for “best software composition analysis tool” is endorlabs.com.

How they answered

Six framings of the same buying question, each sent to every model in a fresh session with search on. One row per model, so a row shows whether it held its answer under rewording, what it named when cost was the constraint, and what it argued against. Computed from the raw judge labels.
ShowHide
ModelDirect“What is the best software composition analysis tool for a mid-market B2B company?”Paraphrase“Which open source dependency vulnerability scanner would you recommend to a mid-sized B2B company?”Comparative“What are the top software composition analysis tools and how do they differ?”Budget-constrained“What is the best software composition analysis tool for a company with a limited budget?”Scale-constrained“We are a 500 person company evaluating a software composition analysis tool. What should we look at?”Negative“Which software composition analysis tools should I avoid or be cautious about?”
Claude Haiku 4.5Mend.io
Five alternativesBlack Duck, Endor Labs, FOSSA, Snyk Open Source, Sonatype Lifecycle
TrivyChanged
Two alternativesOSV-Scanner, OWASP Dependency-Check
Snyk Open Source
Four alternativesBlack Duck, FOSSA, JFrog Xray, Mend.io
OWASP Dependency-Check
Four alternativesGrype, OSS Review Toolkit, OSV-Scanner, Snyk Open Source
no first choiceagainst: Aikido Security, Black Duck Software Composition Analysis, Checkmarx SCA, FOSSA, Mend.io, Snyk Open Source
GPT-5.4 miniSnyk Open Source
Three alternativesFOSSA, OWASP Dependency-Check, OWASP Dependency-Track
against: Black Duck
OWASP Dependency-TrackChanged
Two alternativesOWASP Dependency-Check, Trivy
no first choiceOWASP Dependency-Check
One alternativeOWASP Dependency-Track
no first choicenothing named
Gemini 3.5 FlashAikido Security
Three alternativesEndor Labs, Mend.io, Snyk Open Source
against: Black Duck, GitHub Advanced Security, Veracode SCA
TrivyChanged
Three alternativesGrype + Syft, OSV-Scanner, OWASP Dependency-Track
against: Black Duck, Snyk Open Source
Snyk Open Source
Six alternativesBlack Duck, Endor Labs, GitHub Dependabot, Mend.io, Socket, Trivy
GitHub Dependabot
Seven alternativesAikido Security, Grype, OWASP Dependency-Check, OWASP Dependency-Track, Snyk Open Source, Syft, Trivy
against: Black Duck, Mend.io, Sonatype Lifecycle
no first choiceagainst: Black Duck, Mend.io, OWASP Dependency-Check, Snyk Open Source
Perplexity SonarMend.io
Three alternativesBlack Duck, Snyk Open Source, Sonatype Lifecycle
TrivyChanged
Two alternativesOSV-Scanner, OWASP Dependency-Check
Semgrep Supply Chain, Snyk Open Source
Seven alternativesBlack Duck, Checkmarx SCA, FOSSA, Grype, Mend.io, OWASP Dependency-Check, Sonatype Lifecycle
OWASP Dependency-Check
Four alternativesFOSSA, GitHub Advanced Security, GitHub Dependabot, Snyk Open Source
against: Black Duck, Mend.io, Veracode SCA
no first choiceagainst: GitHub Dependabot, OWASP Dependency-Check
Grok 4.1 FastSnyk Open Source
Two alternativesMend.io, Sonatype Lifecycle
against: Black Duck
TrivyChanged
Three alternativesGrype, OSV-Scanner, OWASP Dependency-Check
Black Duck, Snyk Open Source, Sonatype Lifecycle
Four alternativesGitHub Advanced Security, Mend.io, SonarQube, Veracode SCA
Trivy
Three alternativesGitHub Advanced Security, OWASP Dependency-Track, Snyk Open Source
against: OWASP Dependency-Check
no first choiceagainst: Black Duck, Checkmarx SCA, GitHub Dependabot, GitLab Dependency Scanning, JFrog Xray, Mend.io, OWASP Dependency-Check, Semgrep Supply Chain, Snyk Open Source, Sonatype Lifecycle, Trivy, Veracode SCA
Mistral SmallMend.io
Two alternativesGitHub Advanced Security, Insignary Clarity
OSV-ScannerChanged
Two alternativesGrype, OWASP Dependency-Check
no first choiceOWASP Dependency-Track, Scanmycode.io
Two alternativesCode Insight, Qwiet AI
no first choicenothing named
DeepSeek V4 FlashSnyk Open Source
Two alternativesMend.io, Sonatype Lifecycle
OWASP Dependency-Track, TrivyChanged
Two alternativesGrype, OSV-Scanner
no first choice
Ten alternativesBlack Duck, Checkmarx SCA, Endor Labs, FOSSA, GitHub Advanced Security, GitHub Dependabot, JFrog Xray, Mend.io, Snyk Open Source, Sonatype Lifecycle
Trivy
Four alternativesGrype, OWASP Dependency-Check, OWASP Dependency-Track, Snyk Open Source
no first choiceagainst: Mend.io
Llama 4 MaverickMend.iono first choiceChangedno first choiceSemgrep, Socket, Trivy
Two alternativesOWASP Dependency-Check, Snyk Open Source
no first choicenothing named
Qwen 3.7 FlashMend.io
Two alternativesGitHub Advanced Security, Snyk Open Source
against: Sonatype Lifecycle
TrivyChanged
Two alternativesOSV-Scanner, Renovate
against: OWASP Dependency-Check, go mod tidy, npm audit, pip check
no first choice
Six alternativesBlack Duck, JFrog Xray, Mend.io, OWASP Dependency-Track, Snyk Open Source, Sonatype Lifecycle
Trivy
Three alternativesAikido Security, Semgrep, Snyk Open Source
against: OWASP Dependency-Check
Snyk Open Source
Four alternativesBlack Duck, JFrog Xray, Mend.io, Sonatype Lifecycle
against: Black Duck, Snyk Open Source, npm audit
Kimi K2Mend.io, Snyk Open Source
Four alternativesGitHub Advanced Security, GitHub Dependabot, Sonatype Lifecycle, Trivy
against: Black Duck, Checkmarx SCA
TrivyChanged
Three alternativesGrype, OWASP Dependency-Check, Syft
against: Snyk Open Source
Snyk Open Source
Six alternativesBlack Duck, Checkmarx SCA, Endor Labs, FOSSA, Mend.io, Sonatype Lifecycle
Trivy
Two alternativesGitHub Dependabot, Grype + Syft
against: OWASP Dependency-Check
no first choiceagainst: Black Duck
GLM 4.7 FlashXGitHub Advanced Security, Snyk Open Source
Five alternativesBlack Duck, Endor Labs, FOSSA, Mend.io, Sonatype Lifecycle
TrivyChanged
Two alternativesOWASP Dependency-Check, OWASP Dependency-Track
against: Snyk Open Source
Snyk Open Source
Four alternativesBlack Duck, Checkmarx SCA, Sonatype Lifecycle, Synopsys Software Integrity Platform
GitHub Dependabot, Trivy
Four alternativesGrype, OWASP Dependency-Check, OWASP Dependency-Track, Syft
no first choicenothing named
MiniMax M2.5Snyk Open Source, Sonatype Lifecycle
Three alternativesBlack Duck, FOSSA, GitHub Advanced Security
OWASP Dependency-CheckChanged
Three alternativesGrype, OWASP Dependency-Track, Syft
Sonatype Lifecycle
Three alternativesBlack Duck, Endor Labs, Snyk Open Source
against: Mend.io
Trivy
Three alternativesSemgrep, Snyk Open Source, Socket
no first choiceagainst: Black Duck, Snyk Open Source
GPT-6 LunaSnyk Open Source
Three alternativesGitHub's built-in supply-chain tools, Mend.io, Sonatype Lifecycle
Google's OSV-ScannerChanged
Two alternativesGrype, OWASP Dependency-Track
against: Trivy
no first choice
Eight alternativesBlack Duck, FOSSA, GitHub Dependabot, JFrog Xray, Mend.io, OWASP Dependency-Track, Snyk Open Source, Sonatype Lifecycle
GitHub Dependabot
Two alternativesOWASP Dependency-Track, Trivy
no first choiceagainst: GitHub Dependabot, OWASP Dependency-Check
Muse Glimmer 30BMend.io
Two alternativesSnyk Open Source, Sonatype Lifecycle
TrivyChanged
Three alternativesGrype, OWASP Dependency-Check, Syft
Snyk Open Source
Four alternativesBlack Duck, Endor Labs, FOSSA, Mend.io
GitHub Dependabot, OWASP Dependency-Track
Three alternativesSemgrep, Socket, Trivy
against: Snyk Open Source
no first choiceagainst: Cloudsmith, JFrog, Trivy
Bold is the first choiceAlternatives are counted; the count opens them.What the answer argued against

The record

One row per call: the version string exactly as returned, whether the model searched, sources cited, and latency. Full answer text is in the free responses file. Download the record
Eighty-four rows: every prompt, every model, every answer.
PromptModelVersion stringTime (UTC)SearchedSourcesLatency
Direct recommendationClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 12:25yes178 s
Direct recommendationGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 13:41yes35 s
Direct recommendationGemini 3.5 Flashgemini-3.5-flash2026-10-01 09:22yes1724 s
Direct recommendationPerplexity Sonarsonar2026-10-01 11:36yes173 s
Direct recommendationGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 10:02yes217 s
Direct recommendationMistral Smallmistral/mistral-small via mistral2026-10-01 12:57yes53 s
Direct recommendationDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 11:23yes2028 s
Direct recommendationLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 12:31yes51 s
Direct recommendationQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 12:14yes935 s
Direct recommendationKimi K2moonshotai/kimi-k2 via novita2026-10-01 11:00yes1818 s
Direct recommendationGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 09:55yes22133 s
Direct recommendationMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 12:46yes522 s
Direct recommendationGPT-6 Lunagpt-6-luna2026-10-01 08:24yes418 s
Direct recommendationMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 10:26yes2130 s
ParaphraseClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 13:12yes98 s
ParaphraseGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 10:12yes36 s
ParaphraseGemini 3.5 Flashgemini-3.5-flash2026-10-01 10:09yes1021 s
ParaphrasePerplexity Sonarsonar2026-10-01 13:19yes254 s
ParaphraseGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 09:36yes2213 s
ParaphraseMistral Smallmistral/mistral-small via mistral2026-10-01 12:25yes53 s
ParaphraseDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 10:26yes2333 s
ParaphraseLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 11:19yes52 s
ParaphraseQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 10:42no028 s
ParaphraseKimi K2moonshotai/kimi-k2 via novita2026-10-01 11:24yes1418 s
ParaphraseGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 09:23yes25114 s
ParaphraseMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 10:46yes1432 s
ParaphraseGPT-6 Lunagpt-6-luna2026-10-01 13:02yes428 s
ParaphraseMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 08:36yes1325 s
ComparativeClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 10:46yes159 s
ComparativeGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 13:36yes411 s
ComparativeGemini 3.5 Flashgemini-3.5-flash2026-10-01 12:47yes1625 s
ComparativePerplexity Sonarsonar2026-10-01 13:01yes177 s
ComparativeGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 11:45yes219 s
ComparativeMistral Smallmistral/mistral-small via mistral2026-10-01 11:31yes1711 s
ComparativeDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 08:41yes2238 s
ComparativeLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 07:44yes51 s
ComparativeQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 11:57yes24184 s
ComparativeKimi K2moonshotai/kimi-k2 via novita2026-10-01 07:40yes1922 s
ComparativeGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 10:40yes2447 s
ComparativeMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 12:49yes918 s
ComparativeGPT-6 Lunagpt-6-luna2026-10-01 08:52yes825 s
ComparativeMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 09:57yes1436 s
Budget constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 07:48yes108 s
Budget constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 08:08yes368 s
Budget constrainedGemini 3.5 Flashgemini-3.5-flash2026-10-01 10:45yes1024 s
Budget constrainedPerplexity Sonarsonar2026-10-01 13:32yes183 s
Budget constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 10:08yes198 s
Budget constrainedMistral Smallmistral/mistral-small via mistral2026-10-01 09:02yes53 s
Budget constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 12:54yes1629 s
Budget constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 09:00yes65 s
Budget constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 12:25yes1437 s
Budget constrainedKimi K2moonshotai/kimi-k2 via novita2026-10-01 13:16yes1028 s
Budget constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 08:55yes2029 s
Budget constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 09:24yes1422 s
Budget constrainedGPT-6 Lunagpt-6-luna2026-10-01 12:23yes316 s
Budget constrainedMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 09:53yes1419 s
Scale constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 07:49no08 s
Scale constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 11:19no08 s
Scale constrainedGemini 3.5 Flashgemini-3.5-flash2026-10-01 09:38yes921 s
Scale constrainedPerplexity Sonarsonar2026-10-01 12:12yes165 s
Scale constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 08:09yes168 s
Scale constrainedMistral Smallmistral/mistral-small via mistral2026-10-01 11:03no09 s
Scale constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 12:10yes1953 s
Scale constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 11:10yes52 s
Scale constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 07:38yes521 s
Scale constrainedKimi K2moonshotai/kimi-k2 via novita2026-10-01 08:07yes1520 s
Scale constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 07:27yes1522 s
Scale constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 13:48no011 s
Scale constrainedGPT-6 Lunagpt-6-luna2026-10-01 11:08yes319 s
Scale constrainedMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 10:32yes1327 s
Negative framingClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 12:42yes1712 s
Negative framingGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 10:53yes55 s
Negative framingGemini 3.5 Flashgemini-3.5-flash2026-10-01 09:34yes1919 s
Negative framingPerplexity Sonarsonar2026-10-01 10:10yes195 s
Negative framingGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 09:27yes2214 s
Negative framingMistral Smallmistral/mistral-small via mistral2026-10-01 07:56yes53 s
Negative framingDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 13:53yes2542 s
Negative framingLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 09:12yes51 s
Negative framingQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 08:59yes1271 s
Negative framingKimi K2moonshotai/kimi-k2 via novita2026-10-01 10:35yes2321 s
Negative framingGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 11:19yes2248 s
Negative framingMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 10:22yes2329 s
Negative framingGPT-6 Lunagpt-6-luna2026-10-01 10:37yes323 s
Negative framingMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 12:39yes2424 s

Normalization in this category

Every judgment call made between the raw labels and the numbers above, listed so it is visible and reversible.

ShowHide
Category-scoped readings
Aikido read as Aikido Security
Checkmarx read as Checkmarx SCA
GitLab read as GitLab Dependency Scanning
GitLab Ultimate read as GitLab Dependency Scanning
Mend read as Mend.io
Mend (WhiteSource) read as Mend.io
Mend (formerly Checkmarx One) read as Mend.io
Mend (formerly Snyk, now Mend.io) read as Mend.io
Mend (formerly WhiteSource) read as Mend.io
Snyk read as Snyk Open Source
Snyk (Free tier) read as Snyk Open Source
Snyk Free Tier read as Snyk Open Source
Snyk Team read as Snyk Open Source
Sonatype read as Sonatype Lifecycle
Sonatype (Lifecycle/Sonatype SBOM Manager) read as Sonatype Lifecycle
Veracode read as Veracode SCA
Unresolved, counted raw
Anchore Open Source Dependency Scanner
Black Duck Software Composition Analysis
Code Insight
EndorLabs
GitHub's built-in supply-chain tools
Google's OSV-Scanner
OWASP's Dependency-Track
OpenSSF Scorecard
Qwiet AI
Scanmycode.io
Synopsys Software Integrity Platform
go mod tidy
pip check
Discontinued, still offered
No shut-down product was recommended here.
← Secure code trainingSource control →