Hub Detect offers package management level analysis combined with signature scanning.
Detect Configuration
Hub Detect
Available from GitHub for Linux by running:
bash <(curl -s https://blackducksoftware.github.io/hub-detect/hub-detect.sh)
Available from GitHub for Windows by running:
powershell "[Net.ServicePointManager]::SecurityProtocol = 'tls12'; irm https://blackducksoftware.github.io/hub-detect/hub-detect.ps1?$(Get-Random) | iex; detect"
All documentation is located on our public Black Duck Confluence