In our 38-criteria evaluation of software composition analysis (SCA) providers, we identified the six most significant ones — Black Duck Software, Flexera Software, Sonatype, Synopsys, Veracode, and WhiteSource Software — and researched, analyzed, and scored them. This report shows how each provider measures up and helps security professionals make the right choice for their organization.