Compare Veracode Software Composition Analysis vs. WhiteSource

Cancel
You must select at least 2 products to compare!
Most Helpful Review
Find out what your peers are saying about Veracode Software Composition Analysis vs. WhiteSource and other solutions. Updated: January 2021.
464,857 professionals have used our research since 2012.
Quotes From Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:

Pricing and Cost Advice
Information Not Available
"Without getting too specific, I'd say the average yearly cost is around $50,000. The costs include licensing and maintenance support.""The Veracode price model is based on application profiles, which is how you package your components for scanning.""Compared to other similar products, the licensing and pricing are definitely competitive. If you see Checkmarx as the market leader, then we are talking about Veracode being a fraction of the cost. You also have to consider your hidden costs: you need a team to maintain it, a server, and resources. From that point of view, Veracode is great because the cost is really a fraction of many competitors."

More Veracode Software Composition Analysis Pricing and Cost Advice »

"The version that we are using, WhiteSource Bolt, is a free integration with Azure DevOps.""Pricing is competitive."

More WhiteSource Pricing and Cost Advice »

report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
464,857 professionals have used our research since 2012.
Questions from the Community
Ask a question

Earn 20 points

Top Answer: I have no idea what the licensing costs on the solution are. Our IT team handles the details.
Top Answer: The licensing model could be improved. If they can provide an automatic upload model, that would be really good. Right… more »
Ask a question

Earn 20 points

Popular Comparisons
Also Known As
Veracode SCA, SourceClear
Learn More
Overview

At Accurics™, we envision a world where organizations can innovate in the cloud with confidence. Our mission is to enable cyber resilience through self-healing as organizations embrace cloud native infrastructure. The Accurics platform self-heals cloud native infrastructure by codifying security throughout the development lifecycle. It programmatically detects and resolves risks across Infrastructure as Code before infrastructure is provisioned, and maintains the secure posture in runtime by programmatically mitigating risks from changes. Accurics enables organizations of all sizes to achieve cloud cyber resilience through free cloud-based and open source tools such as Terrascan™.

Veracode Software Composition detects open source vulnerabilities in the software development process with higher accuracy. Veracode SCA reduces false positives by prioritizing vulnerabilities in the execution path of the application. Its proprietary database contains significantly more vulnerabilities than the NVD because it datamines pull requests, bug reports, and release notes. It also looks for vulnerabilities in dependencies several layers deep. Veracode SCA is part of a comprehensive DevSecOps solution that covers multiple assessment types, enables developers, and helps organizations achieve AppSec governance.

The leading solution for agile open source security and license compliance management, WhiteSource integrates with the DevOps pipeline to detect vulnerable open source libraries in real-time.

It provides remediation paths and policy automation to speed up time-to-fix. It also prioritizes vulnerability alerts based on usage analysis.

We support over 200 programming languages and offer the widest vulnerability database aggregating information from dozens of peer-reviewed, respected sources.

Offer
Learn more about Accurics
Learn more about Veracode Software Composition Analysis
Learn more about WhiteSource
Sample Customers
Automation Anywhere, NBA, GroundTruth, ServiceMax, Navis, Edcast
Blue Prism, Advantasure, Automation Anywhere, Cox Automotive
Microsoft, Autodesk, NCR, Comcast, Nokia, Forgerock, indeed.com, GE digital, KPMG, LivePerson, Jack Henry and Associates
Top Industries
VISITORS READING REVIEWS
Computer Software Company29%
Comms Service Provider15%
Financial Services Firm14%
Energy/Utilities Company6%
VISITORS READING REVIEWS
Computer Software Company39%
Comms Service Provider10%
Financial Services Firm8%
Retailer5%
REVIEWERS
Computer Software Company38%
Media Company13%
Energy/Utilities Company13%
Consumer Goods Company13%
VISITORS READING REVIEWS
Computer Software Company40%
Comms Service Provider18%
Financial Services Firm5%
Manufacturing Company5%
Company Size
No Data Available
REVIEWERS
Small Business44%
Midsize Enterprise22%
Large Enterprise33%
REVIEWERS
Small Business42%
Midsize Enterprise8%
Large Enterprise50%
Find out what your peers are saying about Veracode Software Composition Analysis vs. WhiteSource and other solutions. Updated: January 2021.
464,857 professionals have used our research since 2012.

Veracode Software Composition Analysis is ranked 7th in Software Composition Analysis (SCA) with 8 reviews while WhiteSource is ranked 3rd in Software Composition Analysis (SCA) with 11 reviews. Veracode Software Composition Analysis is rated 7.8, while WhiteSource is rated 8.4. The top reviewer of Veracode Software Composition Analysis writes "Provides extensive guidance for writing secure code and pointing to vulnerable open source libraries". On the other hand, the top reviewer of WhiteSource writes "Policy automation and automatic fix suggestions help us to save time in finding and solving problems". Veracode Software Composition Analysis is most compared with Black Duck, JFrog Xray, Snyk, Sonatype Nexus Lifecycle and FOSSA, whereas WhiteSource is most compared with SonarQube, Black Duck, Snyk, Sonatype Nexus Lifecycle and HCL AppScan. See our Veracode Software Composition Analysis vs. WhiteSource report.

See our list of best Software Composition Analysis (SCA) vendors.

We monitor all Software Composition Analysis (SCA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.