101% more reported CVEs per day in 2026 than last year.

Alternatives

DefectDojo alternatives

DefectDojo collects findings from the security tools you already run, and its Pro edition adds SBOM management and a PSIRT workflow. If you want a different scope, a different hosting model, or a dependency record that starts in the build, these are the options worth comparing.

Updated

We build CRACI, so weigh that in; we describe every option from its own documentation and say when another tool fits better.

Why teams look beyond DefectDojo

The DefectDojo homepage
defectdojo.com

DefectDojo is an open-source vulnerability management platform and an OWASP Flagship project, with a commercial edition from DefectDojo Inc. in Austin, Texas. Its site lists more than 500 supported tools, and it deduplicates their results into one queue with owners, SLAs and Jira tickets. DefectDojo Pro adds Locations, a component-level asset model that imports CycloneDX and SPDX SBOMs, and the PSIRT Advisory Engine, which matches advisory feeds against that SBOM data, groups the results into cases and publishes branded PDF advisories. The Community Edition is free under the BSD 3-Clause license.

Teams still compare alternatives, usually for one of these reasons:

  • The SBOM is the weak point. DefectDojo does not generate SBOMs. Advisory matching depends on the SBOM data you load, and that is only as complete as the generator that produced it.
  • Products, not applications. Device makers often need binary and firmware analysis, or SBOMs built from what they receive from suppliers, rather than a findings queue.
  • Scale and automation. Some large programs want an exposure management platform with more correlation and AI agents on top of the aggregated findings.
  • Open source scope. The SBOM features and the PSIRT Advisory Engine are in Pro, and DefectDojo says role-based access control and SSO will not be supported in the v3 open-source edition.

What to look for

  • Where the component list comes from: generated by the tool, imported, or recorded from the build.
  • Whether the tool tells you how complete an SBOM is.
  • Whether you need one queue for every scanner, or a record of what each product contains.
  • How a new advisory gets matched to the products and releases it affects, and how fast.
  • VEX, triage and ownership workflows, if your PSIRT lives in them today.
  • Who operates it, and how pricing scales.

The options

1. CRACI (our product)

The CRACI homepage
craci.com

CRACI is not a findings aggregator. It is a GitHub Actions-compatible runner: you change runs-on to craci, and a package-aware proxy records what each job fetches from package sources, including packages restored from CI caches and hidden dependencies that no lockfile lists. The SBOM, in CycloneDX or SPDX, comes from that record, with a completeness state per job and per cache.

CRACI re-evaluates monitored SBOMs continuously, aggregates findings across builds and repositories, supports VEX, and lets security teams triage findings and route each one to the team that owns the fix. Build history shows which past builds contained a vulnerable dependency, within your retention period, and the inventory view shows which software versions are deployed to which products. You can add vendor SBOMs, and because CRACI runs the job, it enforces an egress policy that fails closed.

Best for: teams whose main exposure is the dependencies of software they build on GitHub Actions, and who want the build, the SBOM and the vulnerability tracking in one place. Consider if: you can keep SAST, DAST and cloud findings elsewhere; CRACI does not import other scanners' results, does not offer reachability analysis, and supports GitHub Actions only today, with GitLab CI and Jenkins on the roadmap. CRACI vs DefectDojo

2. OWASP Dependency-Track

The Dependency-Track homepage
dependencytrack.org

Dependency-Track is open source under the Apache 2.0 license. It tracks component usage across every version of every application in a portfolio, pulls vulnerability intelligence from sources including the NVD and GitHub Advisories, applies security, license and operational policies, and consumes and produces CycloneDX VEX. Pipelines upload SBOMs to it through its API; it does not generate them.

Best for: teams that use DefectDojo mainly for dependency findings and want a free, self-hosted platform built around SBOMs. Consider if: you are comfortable operating it and you already trust the SBOMs going in. CRACI vs Dependency-Track

3. ArmorCode

ArmorCode calls itself an "Agentic AI Platform for Unified Exposure Management." It unifies findings from hundreds of security tools (its home page says 400+ integrations), correlates them with assets, code repositories, cloud resources and ownership, and puts AI agents such as a Vulnerability Researcher, a Remediation Helper and a Zero-Day Hunter to work on triage and remediation. Its supply chain module consolidates components from your SBOMs. Named customers on its site include Visa, PayPal and Jaguar Land Rover.

Best for: large security programs that have outgrown a self-hosted aggregator and want commercial correlation and automation across application, cloud and infrastructure findings. Consider if: quote-based buying works for you; ArmorCode publishes no prices.

4. Cybellum

The Cybellum homepage
cybellum.com

Cybellum is a product security platform for device manufacturers in automotive, medical devices and industrial manufacturing. It creates SBOMs "by combining data from binary scanners, source code and external SBOM sources in SPDX, CycloneDX or CPEs CSV formats," triages vulnerabilities, and takes in findings from threat models, pen tests and fuzz tests. Its incident response module monitors vulnerability feeds, gives the team a workbench for investigations and tickets, and shares vulnerability status "via VEX/CSAF reports." Its compliance module covers FDA PMA, ISO 21434 and the CRA.

Best for: PSIRTs at device makers who want SBOMs, vulnerability management and investigations in one product security platform. Consider if: your products are connected devices rather than web services; Cybellum publishes no prices.

5. Finite State

The Finite State homepage
finitestate.io

Finite State analyzes firmware, binaries, source code and supplier SBOMs, with "support for 50+ binary instruction set architectures," and brings them into one system of record for shipped software. It ranks findings by reachability and exploit intelligence, records VEX decisions, offers "post-market monitoring with living SBOMs," and maps evidence to CRA and FDA controls. It embeds checks in GitHub Actions, GitLab CI and Jenkins.

Best for: connected-device makers who need to see inside firmware from many suppliers, with less noise from unreachable findings. Consider if: quote-based buying works for you; Finite State publishes no prices. CRACI vs Finite State

6. ONEKEY

The ONEKEY homepage
onekey.com

ONEKEY is a product cybersecurity and compliance platform for connected devices. It analyzes compiled firmware with "no source code or network access needed," generates an SBOM from the binary, imports supplier SBOMs, exports CycloneDX and SPDX, and re-analyzes uploaded firmware daily. Its zero-day analysis looks for issues such as hardcoded credentials, and its Compliance Wizard covers the CRA, IEC 62443-4-2, ETSI EN 303 645 and the Radio Equipment Directive.

Best for: device makers who need to analyze firmware they did not build. Consider if: you want findings beyond known CVEs in the image itself. CRACI vs ONEKEY

Side by side

Capability CRACI DefectDojo Dependency-Track ArmorCode Cybellum Finite State
Aggregates findings from other scanners 500+ supported tools Analyzes SBOMs 400+ integrations Threat models, pen tests, fuzz tests Third-party findings in one record
Produces the SBOM Recorded during the build Imports SBOMs (Pro) Analyzes uploads Not stated Merges binary, source and SBOM data From source and binaries
Imports third-party SBOMs Vendor SBOMs can be added CycloneDX and SPDX (Pro) Consolidates SBOMs SPDX, CycloneDX, CPE CSV
Continuous vulnerability monitoring Pro: advisory feeds matched to SBOMs Not stated Monitors vulnerability feeds Post-market, living SBOMs
VEX CycloneDX VEX export (Pro) Not stated
Runs your builds, with egress policy Jobs run on CRACI runners
Who operates it CRACI (managed) You (Community); Pro in the cloud or self-hosted You (self-hosted) Not stated Not stated Not stated
Price (October 2026) Pay per build minute, no monthly fee Community free; Pro from $100/mo plus $0.15 per finding Free, Apache 2.0 Not stated Not stated Not stated
  • Included
  • Partly
  • Not included

"Not stated" means we could not find it in the vendor's public pages, not that it is missing. ONEKEY is described above and left out of the table. DefectDojo cells marked Pro apply to DefectDojo Pro, not the Community Edition.

DefectDojo vs Dependency-Track

Both are free, open-source OWASP projects, and they are often confused. They start from different inputs:

  • DefectDojo starts from scanner results. It imports findings from SAST, DAST, SCA, cloud and container tools, deduplicates them and tracks remediation. SBOM import and advisory matching are in Pro.
  • Dependency-Track starts from SBOMs. It analyzes the CycloneDX SBOMs you upload against vulnerability sources and applies policies across a portfolio.

Neither generates the SBOM or records what your build fetched. That is the gap CRACI fills for software you build on GitHub Actions.

For PSIRT teams

The first question in most PSIRT cases is which products and versions contain the affected component. DefectDojo Pro, Cybellum and Finite State answer it from SBOM data and analysis inside their platforms. CRACI answers it from a record of what each build fetched, with build history and an inventory of what is deployed where. Read what a PSIRT does, CRACI for PSIRT teams and PSIRT tools compared.

For regulated products, CRACI automates a significant part of the software supply chain visibility and evidence that companies need for their wider CRA compliance process. No tool on this page makes a product compliant on its own.

When to stay with DefectDojo

  • It is the one queue where results from all your scanners meet, and deduplication is what you rely on.
  • You want a free, open-source platform you host yourself.
  • You rely on its PSIRT Advisory Engine for advisory feeds, cases and PDF advisories next to your findings.

For more, see build-time SBOM generation, vulnerability management tools compared and Dependency-Track alternatives.

DefectDojo alternatives FAQ

Short answers to the questions teams ask when they compare

What is DefectDojo?

DefectDojo is an open-source vulnerability management platform and an OWASP Flagship project. It imports results from security tools such as SAST, DAST, SCA, cloud and container scanners, deduplicates them into one queue and tracks remediation. The Community Edition is free under the BSD 3-Clause license; DefectDojo Pro, from DefectDojo Inc., adds SBOM management, a PSIRT Advisory Engine and hosted or self-hosted deployment.

Is DefectDojo free?

The Community Edition is free and open source. DefectDojo Pro on pay as you go is $100 per month plus $0.15 per finding processed, with discounts for annual prepayment (as of October 2026). SBOM management in Locations and the PSIRT Advisory Engine are Pro capabilities.

Does DefectDojo generate SBOMs?

No. Its documentation says DefectDojo does not generate SBOMs itself. Pro imports CycloneDX and SPDX files you upload and exports CycloneDX or SPDX, plus finding statuses as CycloneDX VEX. The SBOM still comes from a generator somewhere upstream, or from a supplier.

What is the DefectDojo PSIRT Advisory Engine?

A DefectDojo Pro capability launched in April 2026. It ingests advisories from feeds such as CISA KEV, the NVD, the EUVD, Red Hat and Exploit-DB, matches them against SBOM data or custom asset rules, prioritizes them by CVSS, EPSS and KEV status, groups them into cases with owners, and publishes branded PDF advisories. The September 2026 release added CSAF 2.0 and VEX advisory export and a CRA Article 14 reporting interface.

Can CRACI replace DefectDojo?

For the dependencies of software you build on GitHub Actions, yes: CRACI runs the build, records the SBOM from what it fetched, monitors it for new vulnerabilities and lets security teams triage and route findings. It does not import findings from other scanners, so if DefectDojo is where your SAST, DAST and cloud results meet, keep it for that job.

See your products' exposure from the build

Book a demo and we will run one of your GitHub Actions workflows on CRACI and walk through what it fetched and which vulnerabilities it carries.

Book a demo