AI Indexes
IT AI Index
October 2026 Edition · The permanent record of this edition. The unqualified address always carries the latest edition.
Index › Developer platform › SCA › Enterprise › October 2026 Edition

Software composition analysis for enterprise buyers

Asked as “software composition analysis tool”, and as “open source dependency vulnerability scanner”, on behalf of an enterprise B2B company. 56 first choices recorded across the direct, paraphrase, budget and scale prompts, fourteen models each.
Standing · first-choice share
23%
Contested · Sonatype Lifecycle 21%
23Black Duck21Sonatype Lifecycle14Mend.io41others

23% of first choices, contested.

Since September 2026↗new leaderNew leader since September 2026: Sonatype Lifecycle (22%) replaces Black Duck (19% then, 22% now), 0 points clear, inside the 11-point floor.Sonatype Lifecycle leads at 22%, replacing Black Duck, which led at 19% and stands at 22% now: 0 points clear, inside the floor, so the swap reads as unsettled.

By buyer segment

The same question asked on behalf of a different buyer. Each standing is computed within its segment; they sit side by side and are never added together.

The standing

Share is the count of first choices across the direct, paraphrase, budget and scale prompts, over all fourteen models, for an enterprise B2B company. Ordered by share.
ProductFirst-choice shareNegative rateLabelsQuadrantSince September 2026
01Black Duck23%18%60accepted challenger▲+3Since September 2026: 19% → 22%, +3 points. Inside the 11-point floor: within noise. Read over the models both editions asked.19% → 22%
02Sonatype Lifecycle21%9%45accepted challenger▲+3Since September 2026: 19% → 22%, +3 points. Inside the 11-point floor: within noise. Read over the models both editions asked.19% → 22%
03Mend.io14%25%48criticized challenger▲+5Since September 2026: 10% → 14%, +5 points. Inside the 11-point floor: within noise. Read over the models both editions asked.10% → 14%
04Trivy9%20%15accepted challenger▲+1Since September 2026: 7% → 8%, +1 point. Inside the 11-point floor: within noise. Read over the models both editions asked.7% → 8%
05Snyk Open Source5%32%60criticized challenger▼−3Since September 2026: 10% → 6%, −3 points. Inside the 11-point floor: within noise. Read over the models both editions asked.10% → 6%
06OWASP Dependency-Track5%0%11accepted challenger▼−8Since September 2026: 14% → 6%, −8 points. Inside the 11-point floor: within noise. Read over the models both editions asked.14% → 6%
07JFrog Xray4%12%17accepted challenger=heldSince September 2026: 2% → 2%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.2% → 2%
08Aikido Security4%0%10accepted challenger▼−10Since September 2026: 14% → 4%, −10 points. Inside the 11-point floor: within noise. Read over the models both editions asked.14% → 4%
09GitHub Advanced Security4%30%20criticized challenger▲+4Since September 2026: 0% → 4%, +4 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 4%
10OWASP Dependency-Check4%63%19criticized challenger▼−1Since September 2026: 5% → 4%, −1 point. Inside the 11-point floor: within noise. Read over the models both editions asked.5% → 4%
Show the four products at 0%, ordered by negative rate
14Veracode SCA0%33%15criticized challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
13FOSSA0%21%19accepted challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
12Checkmarx SCA0%18%17accepted challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%
11Endor Labs0%0%10accepted challenger=heldSince September 2026: 0% → 0%, ±0 points. Inside the 11-point floor: within noise. Read over the models both editions asked.0% → 0%

The floor is 11 points of share, measured: how far the models move a leader on their own when the same questions are asked twice with nothing changed. A larger change is movement; a smaller one is noise, and both are shown. Movement is read over the twelve models both editions asked; GPT-6 Luna, Muse Glimmer 30B joined this edition and are in the standing but not yet in the comparison. How the floor is measured

Bars are the share of first choices, 0 to 100Every product with at least 10 labels here. Every product name links to its product page.
All twenty-eight head-to-head pages: the top eight products, each against each

Recommended versus criticized

Every product with at least 10 labels here, on both axes. The 30% line names a quadrant, not the verdict above: that one needs more than 40%.

Criticized challengerCriticized default
Negative label rate →
01
02
03
04
05
06
07
08
09
10
11
12
13
14
Accepted challengerEndorsed leader
0%First-choice share → · lines at 30% share and 25% negative40%
Key
01Black Duck23%
02Sonatype Lifecycle21%
03Mend.io14%
04Trivy9%
05Snyk Open Source5%
06OWASP Dependency-Track5%
07JFrog Xray4%
08Aikido Security4%
09GitHub Advanced Security4%
10OWASP Dependency-Check4%
11Endor Labs0%
12Checkmarx SCA0%
13FOSSA0%
14Veracode SCA0%

What they warned about

Zero of fourteen models held their first choice under the paraphrase. Claude Haiku 4.5, GPT-5.4 mini, Gemini 3.5 Flash, Perplexity Sonar, Grok 4.1 Fast, Mistral Small, DeepSeek V4 Flash, Llama 4 Maverick, Qwen 3.7 Flash, Kimi K2, GLM 4.7 FlashX, MiniMax M2.5, GPT-6 Luna and Muse Glimmer 30B changed. A high negative share on a product with few labels is a warning. A low share on a product with many labels is salience, not sentiment.
Snyk Open Source
32%
19 of 60 labels negative · 12 of 14 models · 3 hard negative
“**Avoid per-developer seat models** (like Snyk or GitHub Advanced Security), as these can become unpredictable and expensive at scale” Mistral Small, budget prompt
OWASP Dependency-Check
63%
12 of 19 labels negative · 9 of 14 models · 6 hard negative
“Basic Repository-Native or Free Tools as your Sole Solution (e.g., OWASP Dependency-Check)... Why to avoid: They do not offer the centralized governance” Gemini 3.5 Flash, negative prompt
Mend.io
25%
12 of 48 labels negative · 9 of 14 models · 1 hard negative
“**Verdict:** Avoid if your org has many language polyglots and requires deep policy customization.” DeepSeek V4 Flash, negative prompt
Black Duck
18%
11 of 60 labels negative · 8 of 14 models · 2 hard negative
“Not recommended for your use case ... Quote-only, project/codebase-based pricing that's unpredictable at scale” DeepSeek V4 Flash, budget prompt

What they cite

Citations exist only for the models that return a source list: fourteen of the fourteen in this edition, and all six flagship models on the expanded tier.

Sites the answers cite

78 of 84 answers in this category came back with a source list, from 14 of 14 models: citations where the model returns them, or the search results it consulted. 1114 links across 227 sites, every framing counted. Ranked by the number of answers carrying the site or page. 3 of the 252 answers across every segment cited this index's own page for the category; the method page measures whether that reading tilts an answer.

vendor site · Guideflow53 answers · 55 citations · 11 models
vendor site · Sonatype42 answers · 75 citations · 14 models
vendor site · Mend36 answers · 60 citations · 14 models
29 answers · 42 citations · 10 models
vendor site · Endor Labs29 answers · 38 citations · 11 models
vendor site · Aikido25 answers · 38 citations · 10 models
vendor site · Checkmarx24 answers · 26 citations · 9 models
23 answers · 24 citations · 8 models
vendor site · Black Duck20 answers · 35 citations · 11 models
vendor site · Safeguard19 answers · 23 citations · 10 models
vendor site · Cycode17 answers · 22 citations · 9 models
17 answers · 20 citations · 9 models

Pages the answers cite

The ten pages named in the most answers, by full address. A page here is one the models returned with a recommendation, not one the index endorses.

Search against answers

Each company's standing in the answers beside its site's footprint in Google search, one row a site: the products the models named on it with their shares, and the share they add up to; monthly searches on Google, and DataForSEO's estimate of AI search demand (modeled from search signals, directional, not a count of queries to any assistant), for the most-searched of the company's and its products' names (the name is in each row's hover text); estimated monthly organic visits to the site; and its best position in Google's top ten for “best software composition analysis tool”, “software composition analysis tool”, “software composition analysis tools”. US estimates from DataForSEO and Google's Ads Transparency Center. A small company's site, or a mid-sized company's site for its flagship, is marked company; a product on a large parent's site (Google, Microsoft) has no site figures. A column with no figures for this category is left out, and an empty cell means none were seen, not none exist. Two measurements side by side: neither is read as the cause of the other.
Company and productsShareOwn site citedName searches, GoogleAI search demand, est.Organic visitsPaid search a month, est.Google ads, last 30 daysBest Google position
Black Duck blackduck.com23%13733,1003,08776,259733
Sonatype sonatype.com
Sonatype Lifecycle 21%, Sonatype Nexus IQ 0%
21%12190171,814 company$1,87978
Mend.io mend.io14%1142101115,0597
Trivy trivy.dev9%2075,4001823,093
OWASP Dependency-Track owasp.org
OWASP Dependency-Track 5%, OWASP Dependency-Check 4%
9%9572010365,2223
Snyk snyk.io
Snyk Open Source 5%
5%17212,10058161,651 company60
JFrog Xray jfrog.com4%365903738,697$37120
Aikido aikido.dev
Aikido Security 4%
4%3422,400516,442 company$936120
OSV-Scanner osv.dev4%3139022749
GitHub parent site
GitHub Advanced Security 4%
4%1111,500,00031,479

Google's top ten for the three searches hold 22 sites; 5 of them are among the sites the models cited here (blackduck.com, cycode.com, dev.to, endorlabs.com, sonatype.com). The first result for “best software composition analysis tool” is endorlabs.com.

How they answered

Six framings of the same buying question, each sent to every model in a fresh session with search on. One row per model, so a row shows whether it held its answer under rewording, what it named when cost was the constraint, and what it argued against. Computed from the raw judge labels.
ShowHide
ModelDirect“What is the best software composition analysis tool for an enterprise B2B company?”Paraphrase“Which open source dependency vulnerability scanner would you recommend to a large B2B company with thousands of employees?”Comparative“What are the top enterprise-grade software composition analysis tools and how do they differ?”Budget-constrained“What is the best software composition analysis tool for a large company that needs predictable total cost across thousands of users?”Scale-constrained“We are a 5,000 person company with SSO, SOC 2 and procurement review requirements evaluating a software composition analysis tool. What should we look at?”Negative“Which software composition analysis tools should a large enterprise avoid or be cautious about?”
Claude Haiku 4.5Mend.io
Three alternativesBlack Duck, Snyk Open Source, Sonatype Lifecycle
TrivyChanged
Three alternativesGitHub Dependabot, OWASP Dependency-Check, OWASP Dependency-Track
Mend.io
Five alternativesBlack Duck, Checkmarx SCA, OWASP Dependency-Track, Snyk Open Source, Sonatype Lifecycle
Mend.io
One alternativeBlack Duck
against: Snyk Open Source
no first choiceagainst: Black Duck, JFrog Xray, Mend.io, Snyk Open Source
GPT-5.4 miniMend.io
Three alternativesBlack Duck, Snyk Open Source, Veracode SCA
Sonatype LifecycleChanged
Three alternativesOWASP Dependency-Check, OWASP Dependency-Track, Snyk Open Source
Sonatype Lifecycle
Six alternativesBlack Duck, Checkmarx One, Checkmarx SCA, JFrog Xray, Mend.io, Snyk Open Source
Sonatype Lifecycle
One alternativeBlack Duck
no first choiceagainst: OWASP Dependency-Check
Gemini 3.5 FlashSnyk Open Source
Six alternativesBlack Duck, Endor Labs, FOSSA, GitHub Advanced Security, GitLab Dependency Scanning, Sonatype Lifecycle
Syft, TrivyChanged
One alternativeOWASP Dependency-Track
against: Black Duck, Mend.io, OWASP Dependency-Check, Snyk Open Source
Endor Labs, Snyk Open Source
Three alternativesBlack Duck, Mend.io, Sonatype Lifecycle
against: GitHub Advanced Security
JFrog Xray
Six alternativesAnchore Grype, Black Duck, OWASP Dependency-Track, SonarQube, Trivy, Veracode SCA
against: GitHub Advanced Security, Mend.io, Snyk Open Source
no first choiceagainst: Black Duck, Checkmarx SCA, Mend.io, OWASP Dependency-Check, Snyk Open Source, Sonatype Lifecycle, Veracode SCA
Perplexity SonarBlack Duck
Three alternativesCheckmarx SCA, Snyk Open Source, Sonatype Lifecycle
OWASP Dependency-CheckChanged
Two alternativesGrype, OSV-Scanner
against: Snyk Open Source
no first choiceBlack Duck
Two alternativesMend.io, Sonatype Lifecycle
against: Snyk Open Source
no first choiceagainst: GitHub Dependabot, OWASP Dependency-Check, Semgrep, Trivy
Grok 4.1 FastBlack Duck, Sonatype Lifecycle
Four alternativesCheckmarx SCA, JFrog Xray, Mend.io, Snyk Open Source
OWASP Dependency-TrackChanged
Three alternativesGrype, OWASP Dependency-Check, Trivy
Black Duck, Sonatype Lifecycle
Four alternativesCheckmarx SCA, Mend.io, Snyk Open Source, Veracode SCA
GitHub Advanced Securityagainst: Black Duck, Mend.io, Snyk Open Source, Sonatype LifecycleBlack Duck, Mend.io, Snyk Open Source, Sonatype Lifecycleagainst: Black Duck, JFrog, Mend.io, OWASP Dependency-Check, Snyk Open Source, Veracode SCA
Mistral SmallBlack Duck
Two alternativesGitHub Advanced Security, Snyk Open Source
OSV-ScannerChanged
Two alternativesGrype, Trivy
no first choiceMend.io, Sonatype Lifecycle
Three alternativesBlack Duck, Checkmarx SCA, HCL AppScan
against: GitHub Advanced Security, Snyk Open Source
no first choicenothing named
DeepSeek V4 FlashSonatype Lifecycle
Two alternativesBlack Duck, Snyk Open Source
OWASP Dependency-TrackChanged
Three alternativesGitHub Dependabot, OWASP Dependency-Check, Trivy
Black Duck, Sonatype Lifecycle
Five alternativesCheckmarx SCA, Endor Labs, JFrog Xray, Mend.io, Snyk Open Source
Mend.io
Two alternativesSnyk Open Source, Sonatype Lifecycle
against: Black Duck, FOSSA, Veracode SCA
no first choiceagainst: FOSSA, GitHub Advanced Security (GHAS) — Dependabot, JFrog Xray, Mend.io, OWASP Dependency-Check, Snyk Open Source, Veracode SCA
Llama 4 MaverickBlack Duck, Mend.io, Sonatype LifecycleOWASP Dependency-CheckChanged
Three alternativesAikido Security, GitLab Dependency Scanning, Snyk Open Source
no first choiceno first choiceBlack Duckagainst: Mend.io
Qwen 3.7 FlashSonatype Lifecycle
Three alternativesBlack Duck, Mend.io, Snyk Open Source
against: GitHub Advanced Security
TrivyChanged
Two alternativesGrype, OWASP Dependency-Track
no first choice
Five alternativesBlack Duck, Mend.io, Snyk Open Source, Sonatype Nexus IQ, Veracode SCA
Black Duck, Snyk Open Source
One alternativeProjeny
no first choiceagainst: Black Duck, Mend.io, Snyk Open Source, npm audit
Kimi K2Black Duck, Sonatype Lifecycle
Two alternativesMend.io, Snyk Open Source
TrivyChanged
Three alternativesFOSSA, Grype + Syft, OSS Review Toolkit
against: OWASP Dependency-Check
Sonatype Lifecycle
Four alternativesBlack Duck, JFrog Xray, Mend.io, Snyk Open Source
against: GitHub Advanced Security
GitHub Advanced Security
Two alternativesBlack Duck, Sonatype Lifecycle
against: Snyk Open Source
no first choice
Three alternativesBlack Duck, Snyk Open Source, Sonatype Lifecycle
against: Black Duck, Checkmarx SCA, FOSSA, Mend.io, Snyk Open Source, Veracode SCA
GLM 4.7 FlashXBlack Duck, Sonatype Lifecycle
Two alternativesMend.io, Snyk Open Source
OWASP Dependency-TrackChanged
Five alternativesGrype, OSV-Scanner, Syft, Trivy, cdxgen
Sonatype Lifecycle
Three alternativesBlack Duck, Mend.io, Snyk Open Source
against: Checkmarx SCA, GitHub Advanced Security
Aikido Security
Two alternativesDebricked, SonarQube
against: Black Duck, Snyk Open Source
no first choiceagainst: Black Duck, FOSSA, JFrog, Mend.io, Snyk Open Source
MiniMax M2.5Black Duck, Sonatype Lifecycle
Three alternativesCheckmarx SCA, Mend.io, OpenText Fortify
OSV-ScannerChanged
Three alternativesOWASP Dependency-Check, Syft, Trivy
Sonatype Lifecycle
Three alternativesBlack Duck, GitHub Advanced Security, Snyk Open Source
against: OWASP Dependency-Check
Aikido Security
Three alternativesBlack Duck, Checkmarx One, Sonatype Nexus IQ
against: Snyk Open Source
no first choiceagainst: OWASP Dependency-Check, npm audit, yarn audit
GPT-6 LunaSonatype Lifecycle
Three alternativesBlack Duck, JFrog Xray, Snyk Open Source
Google OSV-ScannerChanged
Two alternativesGrype, OWASP Dependency-Track
against: Trivy
no first choice
Eight alternativesBlack Duck, Checkmarx One SCA, FOSSA, JFrog Xray, Mend.io, Snyk Open Source, Sonatype Lifecycle, Veracode SCA
against: GitHub's Dependabot
Mend.ioagainst: Snyk Open Source, Sonatype Lifecycleno first choiceagainst: GitHub Dependabot, OWASP Dependency-Check
Muse Glimmer 30BBlack Duck
Three alternativesMend.io, Snyk Open Source, Sonatype Lifecycle
TrivyChanged
Four alternativesGrype, OSV-Scanner, OWASP Dependency-Track, Syft
against: OWASP Dependency-Check
Synopsys Black Duck SCA
Six alternativesEndor Labs, FOSSA, JFrog Xray, Mend.io – Mend SCA, Snyk Open Source, Sonatype Lifecycle
Black Duck, JFrog Xray
One alternativeFOSSA
against: Mend.io, Snyk Open Source
no first choiceagainst: Black Duck, GitHub Dependabot, Grype, OWASP Dependency-Check, Sonatype Lifecycle, Trivy
Bold is the first choiceAlternatives are counted; the count opens them.What the answer argued against

The record

One row per call: the version string exactly as returned, whether the model searched, sources cited, and latency. Full answer text is in the free responses file. Download the record
Eighty-four rows: every prompt, every model, every answer.
PromptModelVersion stringTime (UTC)SearchedSourcesLatency
Direct recommendationClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 08:48yes189 s
Direct recommendationGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 11:56yes15 s
Direct recommendationGemini 3.5 Flashgemini-3.5-flash2026-10-01 08:07yes1532 s
Direct recommendationPerplexity Sonarsonar2026-10-01 12:59yes164 s
Direct recommendationGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 07:59yes219 s
Direct recommendationMistral Smallmistral/mistral-small via mistral2026-10-01 08:20yes106 s
Direct recommendationDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 09:44yes2329 s
Direct recommendationLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 08:13yes51 s
Direct recommendationQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 11:48yes932 s
Direct recommendationKimi K2moonshotai/kimi-k2 via novita2026-10-01 11:25yes1723 s
Direct recommendationGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 10:06yes2251 s
Direct recommendationMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 09:45yes1029 s
Direct recommendationGPT-6 Lunagpt-6-luna2026-10-01 12:49yes419 s
Direct recommendationMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 09:26yes2133 s
ParaphraseClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 10:30yes179 s
ParaphraseGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 09:51yes47 s
ParaphraseGemini 3.5 Flashgemini-3.5-flash2026-10-01 08:36yes1729 s
ParaphrasePerplexity Sonarsonar2026-10-01 12:13yes233 s
ParaphraseGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 10:49yes226 s
ParaphraseMistral Smallmistral/mistral-small via mistral2026-10-01 11:29yes53 s
ParaphraseDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 13:50yes2340 s
ParaphraseLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 07:45yes51 s
ParaphraseQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 09:17yes1040 s
ParaphraseKimi K2moonshotai/kimi-k2 via novita2026-10-01 11:13yes1931 s
ParaphraseGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 12:25yes1355 s
ParaphraseMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 13:11yes553 s
ParaphraseGPT-6 Lunagpt-6-luna2026-10-01 07:26yes431 s
ParaphraseMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 08:09yes1518 s
ComparativeClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 12:11yes99 s
ComparativeGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 12:31yes69 s
ComparativeGemini 3.5 Flashgemini-3.5-flash2026-10-01 09:39yes1827 s
ComparativePerplexity Sonarsonar2026-10-01 07:46yes176 s
ComparativeGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 09:57yes208 s
ComparativeMistral Smallmistral/mistral-small via mistral2026-10-01 09:07yes78 s
ComparativeDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 11:46yes1840 s
ComparativeLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 13:45yes53 s
ComparativeQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 11:29yes1033 s
ComparativeKimi K2moonshotai/kimi-k2 via novita2026-10-01 11:47yes1831 s
ComparativeGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 10:50yes2148 s
ComparativeMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 09:16yes2449 s
ComparativeGPT-6 Lunagpt-6-luna2026-10-01 10:11yes1026 s
ComparativeMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 09:11yes2150 s
Budget constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 09:04yes158 s
Budget constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 11:26yes45 s
Budget constrainedGemini 3.5 Flashgemini-3.5-flash2026-10-01 12:58yes1828 s
Budget constrainedPerplexity Sonarsonar2026-10-01 10:11yes174 s
Budget constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 07:57yes2010 s
Budget constrainedMistral Smallmistral/mistral-small via mistral2026-10-01 10:07yes54 s
Budget constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 09:35yes2538 s
Budget constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 10:23yes51 s
Budget constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 08:06no031 s
Budget constrainedKimi K2moonshotai/kimi-k2 via novita2026-10-01 07:50yes2224 s
Budget constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 08:20yes22199 s
Budget constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 13:30yes2243 s
Budget constrainedGPT-6 Lunagpt-6-luna2026-10-01 13:39yes320 s
Budget constrainedMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 10:16yes1837 s
Scale constrainedClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 12:41yes1913 s
Scale constrainedGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 11:38no012 s
Scale constrainedGemini 3.5 Flashgemini-3.5-flash2026-10-01 13:51no015 s
Scale constrainedPerplexity Sonarsonar2026-10-01 10:14yes166 s
Scale constrainedGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 09:24yes187 s
Scale constrainedMistral Smallmistral/mistral-small via mistral2026-10-01 13:47no09 s
Scale constrainedDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 10:12yes2445 s
Scale constrainedLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 08:08yes52 s
Scale constrainedQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 13:39no034 s
Scale constrainedKimi K2moonshotai/kimi-k2 via novita2026-10-01 13:41yes2434 s
Scale constrainedGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 12:30yes2255 s
Scale constrainedMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 11:28yes525 s
Scale constrainedGPT-6 Lunagpt-6-luna2026-10-01 13:02yes226 s
Scale constrainedMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 10:49yes1325 s
Negative framingClaude Haiku 4.5claude-haiku-4-5-202510012026-10-01 10:44yes1711 s
Negative framingGPT-5.4 minigpt-5.4-mini-2026-03-172026-10-01 11:25yes610 s
Negative framingGemini 3.5 Flashgemini-3.5-flash2026-10-01 10:26yes2029 s
Negative framingPerplexity Sonarsonar2026-10-01 07:54yes185 s
Negative framingGrok 4.1 Fastspacexai/grok-4.1-fast-non-reasoning via vertex2026-10-01 08:42yes2210 s
Negative framingMistral Smallmistral/mistral-small via mistral2026-10-01 13:03yes55 s
Negative framingDeepSeek V4 Flashdeepseek/deepseek-v4-flash via deepinfra2026-10-01 09:16yes2038 s
Negative framingLlama 4 Maverickmeta/llama-4-maverick via bedrock2026-10-01 12:42yes53 s
Negative framingQwen 3.7 Flashalibaba/qwen3.7-flash via alibaba2026-10-01 11:49no041 s
Negative framingKimi K2moonshotai/kimi-k2 via novita2026-10-01 07:45yes2248 s
Negative framingGLM 4.7 FlashXzai/glm-4.7-flashx via zai2026-10-01 11:17yes2038 s
Negative framingMiniMax M2.5minimax/minimax-m2.5 via minimax2026-10-01 09:05yes1769 s
Negative framingGPT-6 Lunagpt-6-luna2026-10-01 11:22yes332 s
Negative framingMuse Glimmer 30Bmeta/muse-glimmer-30b via togetherai2026-10-01 11:48yes1741 s

Normalization in this category

Every judgment call made between the raw labels and the numbers above, listed so it is visible and reversible.

ShowHide
Category-scoped readings
Aikido read as Aikido Security
Checkmarx read as Checkmarx SCA
GitLab Ultimate read as GitLab Dependency Scanning
Mend read as Mend.io
Mend (Sonatype) read as Mend.io
Mend (WhiteSource) read as Mend.io
Mend (formerly WhiteSource) read as Mend.io
Snyk read as Snyk Open Source
Snyk (Snyk Open Source) read as Snyk Open Source
Snyk Team read as Snyk Open Source
Sonatype read as Sonatype Lifecycle
Sonatype (Lifecycle/SBOM Manager) read as Sonatype Lifecycle
Sonatype (Nexus Lifecycle) read as Sonatype Lifecycle
Veracode read as Veracode SCA
Unresolved, counted raw
Anchore Grype
Checkmarx One SCA
GitHub Advanced Security (GHAS) — Dependabot
GitHub's Dependabot
Google OSV-Scanner
Mend.io – Mend SCA
Projeny
Revenera (Flexera)
yarn audit
Discontinued, still offered
No shut-down product was recommended here.
← Secure code trainingSource control →