Six weeks before Forrester published its newest scorecard of this market, the market's longtime king changed hands. Synopsys sold its Software Integrity Group on October 1, 2024, and relaunched it as Black Duck Software. On November 13, 2024, The Forrester Wave: Software Composition Analysis, Q4 2024 went live, and the vendor that took the throne was not the one that had been holding it. Sonatype captured the highest scores in both current offering and strategy.
Six weeks is not enough time for a company to change. It is enough time for a scorecard to be about the old one. The published flag on this category is correct, and the report it points to is a snapshot of a market mid-handover, which makes it unusually useful reading. Scorecards written during transitions record what stays when ownership moves.
The scanner that became an immune system
The newest edition evaluates ten providers across twenty five criteria, and the criteria themselves are the category's real story.
Software composition analysis began as a scanner: what open source did you import, and what licenses and vulnerabilities came with it. The Q4 2024 criteria describe a different machine. Malicious package detection, SBOM generation and ingestion, policy management, remediation and automation, risk intelligence, AI component analysis. The scanner stopped being a scanner. It became the supply chain's immune system.
The market context explains why. Forrester's headline statistic: an astonishing seventy seven percent of codebases are comprised of open source software. The question is no longer what you wrote. It is what you imported, who imported it into what they gave you, and whether anything malicious rode along. The 2021 edition's announcement blog already flagged the arrival of dependency confusion protection in vendor responses. By 2024 that defensive feature set had become the scorecard's center of gravity.
The Q4 2024 scorecard: The Forrester Wave: Software Composition Analysis, Q4 2024
The field of ten, tier by tier.
Leaders: Sonatype, Snyk, and Black Duck. Strong Performers: Checkmarx, Mend.io, and Veracode. Contenders: JFrog, GitHub, Aqua Security, and GitLab.
Sonatype finished first in current offering and first in strategy, with the highest possible scores in vision and roadmap, and maximum scores in malicious package detection, SBOM generation, export and sharing, SBOM ingestion and analysis, policy management, and AI component analysis. Forrester's language on the vision is the strongest in the report: Sonatype's approach to "blocking software supply chain attacks at the network firewall" is called "revolutionary," and reference customers said Sonatype is "the best provider for blocking malicious packages." The roadmap is described as "stellar."
Snyk was named a Leader and the report's Customer Favorite. Its strategy scores peak in vision, innovation, and supporting services, and its current-offering maximums land in risk intelligence, remediation and automation, reporting and analytics, software development toolchain integration, and component health. The quoted strategy is the opposite pole from Sonatype's: "to place the onus of secure software on the development systems and process, not the developer," with autonomous remediation as the vision. Forrester calls Snyk "a great fit for enterprises implementing DevSecOps at scale."
Black Duck, six weeks independent at scoring time, took the second-highest current-offering score and maximum scores in nine criteria: component identification and analysis, license detection, analysis and guidance, risk intelligence, SBOM generation, export and sharing, SBOM ingestion and analysis, policy management, language support, plus innovation and supporting services on the strategy side. Forrester praises "exceptional open-source, third-party, and closed-source component and snippet analysis," calls its SBOM capabilities "among the best in this evaluation," and notes the knowledge base spans more than eight point seven million projects.
Three Leaders, three philosophies
The three Leaders do not compete on the same question, and the report is honest enough to show it.
Sonatype's answer is the gate: block malicious packages at the network firewall, before they reach a build. It is the repository company's logic, Nexus Repository plus Lifecycle plus the firewall. Snyk's answer is the system: make the development platform itself distribute secure components, fix vulnerabilities through automation, and stop asking developers to be security experts. Black Duck's answer is the authority: the deepest component identification and license analysis in the evaluation, the SBOM standard-setter, the choice for manufacturing and regulated industries.
Every Leader carried a caveat, and the caveats are the buying guide. Black Duck's, per secondary reporting, include an undifferentiated product roadmap, an outdated user interface, and slow feature delivery. A buyer choosing the authority model is choosing the deepest analysis with the slowest product motion. A buyer choosing the system model is choosing automation that assumes a modern, well-instrumented pipeline. A buyer choosing the gate is choosing to trust the firewall layer. The tier column cannot decide among these. The architecture of your build can.
The king's six-week-old new clothes
The Black Duck situation deserves its own reading, because it is the market's clearest lesson.
For roughly a decade, the Synopsys Software Integrity Group was the category's establishment name, the leader of the earlier editions. Then a private equity combination, Clearlake Capital and Francisco Partners, bought the group for about two point one billion dollars and relaunched it as Black Duck on October 1, 2024. Forrester's Wave published forty three days later. The company that collected nine maximum scores had not yet existed for a quarter.
The timing produced the strangest pairing in the report: maximum scores for component identification and license analysis, attached to criticisms about roadmap and interface. The knowledge base survived the transaction. The product organization was still re-forming. For a buyer, that combination is a live demonstration of what acquisitions do to security vendors. The data endures. The cadence does not. Check the delivery rhythm of any vendor you shortlist, not just the knowledge they sit on.
The 2021 edition and the throne before it
The history arc makes the 2024 result legible.
The Forrester Wave: Software Composition Analysis, Q3 2021, evaluated ten vendors and crowned the Synopsys-led field, with Sonatype already a Leader holding the highest market presence score. Forrester's announcement blog for that edition is a time capsule: it notes that several SCA vendors referenced dependency confusion protection directly in their Wave responses. The dependency confusion attacks of 2021, malicious packages published under internal names, were this market's proof of concept. They turned SCA from a compliance utility into a defensive platform, and they set the trajectory that ended with Sonatype's firewall vision on top in 2024.
The earlier Q2 2019 edition sits further back in the same direction, when license compliance dominated the criteria. Three editions trace one arc: compliance, then supply chain defense, then the immune system.
The age limit on a November 2024 scorecard
The honest limitation is the calendar.
The scorecard is approaching two years old, and the supply chain did not stop moving. AI component analysis was a maximum-score criterion for two Leaders in November 2024. Since then, AI-generated code and agent-driven dependency selection have changed what an import even is, and no scorecard published in 2024 can price that. The evaluation measures the supply chain as it was then. Your contracts will live in the supply chain as it is now.
Second, the vendor materials disagree slightly on the report's exact title, some appending Software, which matters only because it signals how quickly vendor marketing layered the recognition onto a still-settling brand. The category name you are shopping by is the one Forrester published under. That is the important alignment.
Third, the transition risk is systemic, not specific to Black Duck. This market's history is consolidation. The king changed hands six weeks before the scorecard. When the next edition arrives, check which of these ten names still own themselves before you compare the scores.
Three questions for the supply chain buyer
One: which philosophy fits your build? If your organization blocks at the perimeter and wants nothing suspect reaching a build, Sonatype's gate model matches your architecture. If you have a modern instrumented pipeline and want fixes to flow automatically, Snyk's system model matches. If you are regulated and need license and component authority nobody disputes, Black Duck's depth matches. The philosophies, not the tiers, decide.
Two: what is your AI-component posture? AI component analysis was a differentiator in 2024. Ask every shortlisted vendor how they handle AI-generated code and agent-pulled dependencies today, and make them show it working on your own repositories. The 2024 scorecard cannot answer this for you.
Three: who owns the vendor you are buying? The market's king was sold six weeks before it was scored. Ask about ownership structure, acquisition history, and release cadence, and weight the answers against the scorecard. In this category, the knowledge survives acquisitions and the cadence does not.
The runtime half of the same application-security stack is scored separately in Web Application Protection Platforms, whose own next evaluation is being reframed as a market map rather than a scored Wave.
Analyst Source
Forrester Research
This article is built on The Forrester Wave: Software Composition Analysis, Q4 2024, published November 13, 2024, evaluating ten SCA providers across twenty five criteria spanning current offering and strategy. The field: Leaders Sonatype, Snyk, and Black Duck; Strong Performers Checkmarx, Mend.io, and Veracode; Contenders JFrog, GitHub, Aqua Security, and GitLab. The edition follows The Forrester Wave: Software Composition Analysis, Q3 2021 (ten vendors), announced in the Forrester blog "Software Composition Analysis Is A Core Tool To Protect Your Software Supply Chain," and the Q2 2019 edition. Market context: Synopsys sold its Software Integrity Group to Clearlake Capital and Francisco Partners, relaunching it as Black Duck on October 1, 2024, six weeks before publication.
Source research
- Sonatype: recognized as a Leader in the Forrester Wave for SCA software, Q4 2024
- Snyk: named a Leader and Customer Favorite in Software Composition Analysis
- Black Duck: Forrester ranks Black Duck top in Software Composition Analysis
- Mend.io: a Strong Performer in The Forrester Wave: Software Composition Analysis, Q4 2024
- Software Composition Analysis Is A Core Tool To Protect Your Software Supply Chain (Forrester blog, Q3 2021 edition)
Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.