DevGuard
- Android app
- Not listed
- Free plan
- Yes
- Paid plans from
- €449.10/mo
- Runs on
- api, Linux, Mac, self-hosted, Web, Windows

Summary
DevGuard is an open-source developer security platform for hardening the software supply chain. It monitors deployed software for newly disclosed vulnerabilities and can create issues when new CVEs affect a project. Risk scoring and exploit probability analysis help prioritize findings, while VEX assessment sharing can reduce false positives. The platform connects with GitHub and GitLab repositories, CI pipelines and issue trackers, and it can ingest SBOM, VEX and SARIF inputs from compatible scanners or tools. Its scanner CLI supports software composition analysis, static application security testing and signing attestations. A dependency firewall checks npm, Go, PyPI and container image requests against a malicious-package database, blocking known-bad releases. DevGuard also supports SBOM management, artifact signing, provenance attestations and release policy gates. The source code is distributed under AGPL-3.0-or-later. The free self-hosted Open Source plan is restricted to public projects with an OSI-approved license; non-commercial FLOSS projects can get SaaS free. Business SaaS is €449.10 per month on a one-year contract paid yearly and includes 10 users, managed hosting in Germany and support.
Who it is for
DevGuard is aimed at developers, DevOps engineers and security-conscious teams managing software supply-chain risks. The free self-hosted plan is for qualifying public projects; Business SaaS adds managed hosting and support.
What is good
- Monitors deployed software for newly disclosed vulnerabilities.
- Prioritizes risks using scoring and exploit probability analysis.
- Ingests SBOM, VEX and SARIF inputs.
- Dependency firewall blocks known-bad releases.
- Supports provenance attestations and artifact signing.
What to know first
- Free self-hosted plan is limited to qualifying public projects.
- Business SaaS costs €449.10 per month on an annual contract.
- Business SaaS includes 10 users.
- Business SaaS support is limited to four monthly hours and 8×5 email.
Everything Xiaomi review
DevGuard: the full review
DevGuard combines vulnerability monitoring, dependency checks and supply-chain security workflows. Review the public-project condition for its free plan and the user, support and contract terms for Business SaaS.
DevGuard is an open-source software supply-chain security platform for developers, DevOps engineers and security-conscious teams. It suits teams that want to connect vulnerability response with dependency and release controls. Its strongest case is the breadth of that workflow; its free plan’s public-project condition and Business SaaS’s annual contract are meaningful constraints.
Overview
DevGuard connects repositories, CI pipelines and issue trackers, and can ingest SBOM, VEX and SARIF data from compatible scanners and tools. That makes it a practical coordination layer for teams that already generate security data, rather than a reason to discard their existing tools. The project is distributed under AGPL-3.0-or-later.
The platform monitors deployed software for newly disclosed vulnerabilities and can automatically create issues when a CVE affects it. Risk scoring and exploit-probability analysis help teams prioritize response, while sharing VEX assessments can help distinguish applicable risks from false positives. This combination is most useful where teams need to move from identifying exposure to assigning and tracking remediation.
Key features
Dependency and release security
The devguard-scanner CLI supports software composition analysis, static application security testing and signing attestations. DevGuard also supports SBOM management, build provenance, artifact signing, provenance attestations and release policy gates. Together, these capabilities address both what goes into software and how releases are documented and controlled.
Dependency firewall
The firewall checks npm, Go, PyPI and container image requests against a malicious-package database and blocks known-bad releases. That is a useful preventive control for teams working with those ecosystems, though its stated coverage does not extend to every package ecosystem.
Standards and compliance
Support for SBOM, VEX and SARIF inputs gives teams a standards-based way to bring scanner results into the platform. DevGuard also says it helps meet software development requirements associated with ISO/IEC 27001 and PCI-DSS; teams should view that as support for compliance work, not a substitute for their broader compliance program.
Pricing
| Plan | Price and terms | Best fit |
|---|---|---|
| Open Source | 0.00 EUR per free, billed Lifetime. Self-hosted, all features and community support. For public projects with an OSI-approved license; non-commercial FLOSS projects can get SaaS free. | Eligible open-source projects able to operate a self-hosted deployment. |
| Business SaaS | 449.10 EUR per month, billed 1 year contract, paid yearly. Includes 10 users, 4 hours monthly support, managed hosting in Germany, a 1-hour setup workshop and 8×5 email support. | Teams seeking managed hosting and defined support, and prepared to commit annually. |
| Enterprise | Custom pricing; custom quote. Unlimited users, projects and assets, custom SLA, phone and chat support, and on-premises or cloud deployment. | Organizations needing scale, tailored service terms or deployment choice. |
The 14-day trial gives prospective buyers a limited window to assess the paid offering. The free tier is generous in features but not a general-purpose free plan: private commercial projects do not meet its stated public-project condition. Business adds managed operations and support, but its annual contract and yearly payment are a substantial step up from self-hosting.
Platforms
DevGuard supports API, Linux, macOS, self-hosted, web and Windows. Self-hosting is central to the free Open Source plan, while Business SaaS provides fully managed hosting in Germany.
Who it's for
Development and DevOps teams that want vulnerability monitoring, dependency checks and supply-chain controls in one workflow should put DevGuard on their shortlist. It is especially relevant to teams already producing SBOM, VEX or SARIF data and to eligible public open-source projects seeking a self-hosted option. A private commercial team wanting a no-cost hosted service should look elsewhere; Business is better suited to organizations that can justify a yearly commitment for hosting and support.
Pros and cons
- Broad supply-chain coverage: analysis, provenance, signing and release gates sit alongside vulnerability monitoring, reducing the need to treat these as disconnected workflows.
- Useful risk triage: exploit-probability analysis and VEX sharing help teams prioritize findings and address false positives.
- Meaningful free option for eligible projects: the Open Source plan includes all features at no cost, but requires public projects with an OSI-approved license and self-hosting.
- Business has a firm commitment: 10 users and monthly support hours are included, but the €449.10 monthly rate is tied to a one-year contract paid yearly.
- Firewall coverage is bounded: checks cover npm, Go, PyPI and container image requests, not every ecosystem.
Alternatives
Compare software supply-chain security software if you want to consider the category beyond DevGuard.
- Chainloop is worth considering for teams that prefer a self-hosted community edition at no cost; that edition has no UI or curated policy library.
- SafeDep Platform may suit teams that want free, open-source tools such as Vet, PMG, xBom and Gryph usable without a SafeDep account.
- ActiveState Platform offers a free organization plan for public projects, so it is another option for teams whose work is public.
- Kosli is an alternative with custom annual contracts based on recorded data and retention, with volume discounts and usage costs capped during the contract.
- OX Security may fit buyers seeking a quoted OX Code package spanning SAST, SCA, secrets and PII, SBOM, IaC, CI/CD, container scanning, IDE and CLI.
- Sigstore is a free option for developers and software providers considering a no-cost alternative.
- Kusari is another freemium option and may appeal to teams interested in its GUAC contributions.
- Determinate Systems is another freemium alternative.
Verdict
DevGuard is a strong fit for open-source maintainers and development-security teams that need vulnerability response alongside dependency and release controls. The breadth of its security workflow is the main reason to choose it; the public-project restriction on the free plan and annual Business commitment are the main reasons to look elsewhere.
DevGuard plans and pricing
All plansCompared on software supply chain security software
- Free plan
- Yesdevguard.org
- Source & repo security
- Yesdevguard.org
- Dependency analysis
- Yesdevguard.org
- SBOM management
- Yesdevguard.org
- Build provenance
- Yesdevguard.org
- Artifact signing
- Yesdevguard.org
- Provenance attestations
- Yesdevguard.org
- Release policy gates
- Yesdevguard.org
Facts
- Purpose
- DevGuard is an open-source developer security platform for hardening the software supply chain.devguard.org · 30 Sept 2026
- Vulnerability management
- It monitors deployed software for newly disclosed vulnerabilities and can automatically create issues when new CVEs affect software.devguard.org · 30 Sept 2026
- Risk and VEX
- It prioritizes risk using scoring and exploit probability analysis, and supports VEX assessment sharing to reduce false positives.devguard.org · 30 Sept 2026
- Integrations
- The homepage says DevGuard connects with GitLab and GitHub repositories, CI pipelines, and issue trackers.devguard.org · 30 Sept 2026
- Open standards
- DevGuard can ingest inputs from scanners or tools that support SBOM, VEX, and SARIF.devguard.org · 30 Sept 2026
- CLI
- The devguard-scanner CLI supports software composition analysis, static application security testing, and signing attestations.devguard.org · 30 Sept 2026
- Dependency firewall
- The dependency firewall checks npm, Go, PyPI, and container image requests against a malicious package database and blocks known-bad releases.devguard.org · 30 Sept 2026
- Supported users
- The documentation describes DevGuard as built for developers, DevOps engineers, and security-conscious teams.docs.devguard.org · 30 Sept 2026
- Security and compliance
- The documentation says DevGuard helps meet software development requirements for standards such as ISO/IEC 27001 and PCI-DSS.docs.devguard.org · 30 Sept 2026
- Support
- The open-source plan includes community support; Business SaaS includes monthly support hours and 8×5 email support.devguard.org · 30 Sept 2026
- Notable plan limit
- The free Open Source plan is for public projects with an OSI-approved license; non-commercial FLOSS projects can get SaaS free.devguard.org · 30 Sept 2026
- License
- The project documentation says DevGuard source code is distributed under AGPL-3.0-or-later.docs.devguard.org · 30 Sept 2026
- Maker
- The site footer identifies L3montree GmbH and the DevGuard Contributors; the project timeline lists its first line of code in June 2023.devguard.org · 30 Sept 2026
Company
- Founded
- 2023devguard.org · 23 Sept 2026
Best DevGuard alternatives
See all 20Where it ranks on Everything Xiaomi
Is DevGuard yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- devguard.org· checked 30 Sept 2026
- devguard.org/dependency-proxy· checked 30 Sept 2026
- docs.devguard.org· checked 30 Sept 2026
- devguard.org/about· checked 30 Sept 2026



