17 years helping Singaporean businesses
choose better software

What Is WhiteSource?

The leading solution for agile open source security and license compliance management, WhiteSource integrates with the DevOps pipeline to detect vulnerable open source libraries in real-time.

It provides remediation paths and policy automation to speed up time-to-fix. It also prioritizes vulnerability alerts based on usage analysis.
We support over 200 programming languages and offer the widest vulnerability database aggregating information from dozens of peer-reviewed, respected sources.

Who Uses WhiteSource?

We help software, security and DevOps teams, and companies developing software applications.

WhiteSource Software - 1
WhiteSource Software - 2
WhiteSource Software - 3
WhiteSource Software - 4

Not sure about WhiteSource? Compare with a popular alternative

WhiteSource

WhiteSource

4.3 (7)
US$4,000.00
Free version
Free trial
33
9
4.0 (7)
3.7 (7)
4.2 (7)
VS.
Starting Price
Pricing Options
Features
Integrations
Ease of Use
Value for Money
Customer Service
US$160.00
year
Free version
Free trial
34
4
4.3 (61)
4.5 (61)
4.1 (61)
Green rating bars show the winning product based on the average rating and number of reviews.

Other great alternatives to WhiteSource

SonarQube
Top rated features
Application Security
Continuous Delivery
For Developers
GitLab
Top rated features
Access Controls/Permissions
Authentication
Source Control
GitHub
Top rated features
Access Controls/Permissions
Collaboration Tools
Source Control
Snyk
Top rated features
Patch Management
Vulnerability Assessment
Vulnerability Scanning
Microsoft Defender for Cloud Apps
Top rated features
Activity Dashboard
Alerts/Notifications
Behavioral Analytics
Jira
Top rated features
Issue Management
Task Management
Ticket Management
BuildPiper
Top rated features
Approval Workflow
Configuration Management
Continuous Deployment
Sigrid
Top rated features
Monitoring
Static Analysis
Version Control
Bytesafe
Top rated features
Collaboration Tools
Continuous Deployment
Continuous Integration

Reviews of WhiteSource

Average score

Overall
4.3
Ease of Use
4.0
Customer Service
4.2
Features
3.3
Value for Money
3.7

Reviews by company size (employees)

  • <50
  • 51-200
  • 201-1,000
  • >1,001

Find reviews by score

5
57%
4
29%
2
14%
Mo
Mo
Lead DevOps Engineer in US
Verified LinkedIn User
Legal Services, 501–1,000 Employees
Used the Software for: 2+ years
Reviewer Source

Alternatives Considered:

Good supplement to other SAST tools for "shift left" security.

4.0 2 years ago

Pros:

Easy integration with Azure DevOps and Mend for Github and the fact that you can run as a task during the pipeline but you don't have to see the output from a CLI since they provide a tab on the pipeline run to see a good report on used libraries and vulnerabilities.

Cons:

Other tools have auto fixing which is not a need but good to have. Auto-fixing is not always "auto" and might need review which doesn't make it a big con.

Elyes
Elyes
Application Security Engineer in Tunisia
Verified LinkedIn User
Information Technology & Services, 1,001–5,000 Employees
Used the Software for: 6-12 months
Reviewer Source

WhiteSource Review

5.0 3 years ago

Pros:

WhiteSource give you the ability to scan open source packages within your source code. The ability to integrate it with Azure pipelines is a huge plus

Cons:

Duplicated result for same packages and within the same project

Don
VP Software Development in US
Used the Software for: 1-5 months
Reviewer Source

Tons of false positives, prepare to spend hours fixing it manually

2.0 7 years ago

Comments: After much manual configuration, a nicely formatted output that looks reputable. I could have just made my own in excel a lot faster.

Pros:

Fast, quick reviews of your code. They do a good job of putting all the relevant reports and dashboards in front of you quickly. Once you manually fix everything, it can look really good.

Cons:

The false positives are awful. I had to spend hours and hours manually fixing everything it mis-identified - dozens of libraries and thousands of source files. If you use a library not in its database... too bad. You can make a support request and wait for them to enter it for you, whenever they get around to it. The search is pretty awful. There is some kind of syntax to using it but when I asked our account rep, she couldn't give me any documentation on it. You will frequently see results like "openssl-v0_9_8" in your search, but if you type "openssl" it will vanish and not come up. Don't ever both trying to search for a version, it doesn't work. This results in a lot of time scrolling through very large lists. Naming schemes are random and follow no established pattern. For a good half of all libraries, they have not assigned a license. Guess who gets to go google search them all? You, the user! Isn't the point of this tool to help me identify the licensing? UI navigation is challenging. Back button will take you to a different place than you were almost every time. You'll love the dashboard... because you have to go back to it roughly every 5 minutes and start over. No great system for notes/todos/reminders. When you have to fix 60 libraries, it's hard to remember what you want to do with each one.

Udi
System Architect & FOSS Evaluator in Israel
Used the Software for: Not provided
Reviewer Source

FOSS lifecycle management with Whitesource

5.0 9 years ago

Comments: Using Whitesource to manage the process of analysing FOSS for a large product with hundreds of opensource dependencies.
Makes life much easier and helps you cover all dependencies much more accurately.
Some processes are still a bit course (though improved dramatically over the past 18 months)
Refresh performance might be a bit slow when there are very large dependency lists.
Best product out there for FOSS lifecycle management

John McIntire
Used the Software for: Not provided
Reviewer Source
Source: GetApp

Easy to use. Saves tons of time.

5.0 12 years ago

Comments: We used to document it all manually. Now its done easily and effectively. Not to mention that we missed many things, so with this we were able to fix some small issues before they become big issues....

Pros:

easy inexpensive very comprehensive no more hassle

shaul
SW director in Israel
Used the Software for: Not provided
Reviewer Source

work with it for a long time still place to improve.

4.0 9 years ago

Comments: It aggregates my licenses in one centralized place. The software helps me to generate the reports for many requests that I have inside my organization. It also helps me to identify the changes between versions and compare them.

Alice Akins
Used the Software for: Not provided
Reviewer Source
Source: GetApp

License Management in the cloud

5.0 12 years ago

Comments: I use the free cloud based service of White Source and it is pretty well done. Things get done quickly and easy and the software helps me to track open source licences. There is nothing to complain about it!