# Black Duck alternatives: what AI models name instead, October 2026

IT AI Recommendation Index, October 2026 Edition. 195 of the 252 answers in the 1 category where Black Duck holds a standing named it neither first nor as an alternative; these are the first choices those answers made. Page: https://it-ai-index.com/vendors/black-duck/alternatives/

## Named instead, most often (every category and segment added)

- Snyk Open Source: 42
- Trivy: 34
- OWASP Dependency-Check: 18
- GitHub Dependabot: 11
- Aikido Security: 8
- Mend.io: 7

## Software composition analysis

**Small business**: 82 of 84 answers did not name Black Duck (Black Duck is #14 of 14 at 0%).

- Snyk Open Source: first choice in 37 of those 82
- Trivy: first choice in 13 of those 82
- OWASP Dependency-Check: first choice in 12 of those 82
- GitHub Dependabot: first choice in 7 of those 82
- Aikido Security: first choice in 6 of those 82
- FOSSA: first choice in 3 of those 82
- Dependancy Checker: first choice in 1 of those 82
- GitHub Advanced Security: first choice in 1 of those 82

**Mid-market**: 68 of 84 answers did not name Black Duck (Black Duck is #14 of 17 at 0%).

- Trivy: first choice in 16 of those 68
- Mend.io: first choice in 5 of those 68
- Snyk Open Source: first choice in 5 of those 68
- GitHub Dependabot: first choice in 4 of those 68
- OWASP Dependency-Check: first choice in 4 of those 68
- OWASP Dependency-Track: first choice in 4 of those 68
- Endor Labs: first choice in 2 of those 68
- Aikido Security: first choice in 1 of those 68

**Enterprise**: 45 of 84 answers did not name Black Duck (Black Duck is #1 of 14 at 23%).

- Trivy: first choice in 5 of those 45
- OWASP Dependency-Track: first choice in 3 of those 45
- Mend.io: first choice in 2 of those 45
- OSV-Scanner: first choice in 2 of those 45
- OWASP Dependency-Check: first choice in 2 of those 45
- Sonatype Lifecycle: first choice in 2 of those 45
- Aikido Security: first choice in 1 of those 45
- Endor Labs: first choice in 1 of those 45

Published under CC BY 4.0. The output is the models' output; nothing here is a recommendation by the index.
