Open source sca projects

Every project in the registry tagged sca, ranked by real GitHub adoption.

projects 3 combined stars ★ 3.1K refresh nightly
01 dep-scan ★ 1.3K

OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. B

last push6 days ago languagePython licenseMIT
02 cdxgen ★ 1.1K

Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI

last push27 hours ago languageJavaScript licenseApache-2.0
03 cve-lite-cli ★ 740

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output,

last push17 hours ago languageTypeScript licenseMIT

Related tags

← all tags

Frequently asked questions

How many open source sca projects are there?

This registry tracks 3 projects tagged sca, with 3,106 GitHub stars between them. The most-adopted is dep-scan at 1,289 stars.

Are these sca projects free to use?

Yes — 3 of the 3 carry an explicit open-source licence across 2 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which sca project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these sca projects still maintained?

3 of the 3 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.