DevGuard is an open-source developer security platform for hardening the software supply chain. It monitors deployed software for newly disclosed vulnerabilities and can create issues when new CVEs affect software. Risk scoring and exploit probability analysis help prioritize findings, while VEX assessment sharing supports false-positive reduction. DevGuard connects with GitHub and GitLab repositories, CI pipelines, and issue trackers, and can ingest SBOM, VEX, and SARIF inputs from compatible tools. Its scanner CLI supports software composition analysis, static application security testing, and signing attestations. A dependency firewall checks npm, Go, PyPI, and container image requests against a malicious-package database and blocks known-bad releases. The project also supports SBOM management, artifact signing, provenance attestations, and release policy gates. Its source is distributed under AGPL-3.0-or-later. The free self-hosted Open Source plan is for public projects with an OSI-approved license; non-commercial FLOSS projects can get SaaS free. Business SaaS costs 449.10 EUR per month on a one-year contract paid yearly.
Who it is for
DevGuard is aimed at developers, DevOps engineers, and security-conscious teams managing software supply-chain risks. The free self-hosted plan is specifically for public projects with an OSI-approved license.
What is good
- Monitors deployed software for new vulnerabilities.
- Ingests SBOM, VEX, and SARIF inputs.
- Dependency firewall blocks known-bad releases.
- Supports provenance attestations and release policy gates.
What to know first
- Free self-hosted plan is restricted to qualifying public projects.
- Business SaaS requires a one-year contract paid yearly.
- Enterprise pricing requires a custom quote.
Verdict
DevGuard combines vulnerability monitoring, dependency checks, and supply-chain security workflows. The free plan has a public-project restriction, while Business SaaS is priced at 449.10 EUR per month on an annual contract.
DevGuard plans and pricing
All plansCompared on software supply chain security software
- Free plan
- Yes
- Source & repo security
- Yes
- Dependency analysis
- Yes
- SBOM management
- Yes
- Build provenance
- Yes
- Artifact signing
- Yes
- Provenance attestations
- Yes
- Release policy gates
- Yes



