Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

This page's audience real numbers from our own analytics — open to see them
–Visitors
–Page views
–Clicks to vendors
–Time on page
–Reading now
Clicks to vendors, by tool
  • –
Top countries
  • –
Devices
  • –

– · counted by iTechGuides's own first-party analytics, bots removed, every figure rounded down · how we count

GUAC

Free#14 of 24 in Software Supply Chain Security Software

GUAC: A capable graph-based analyzer for SBOMs, dependencies, attestations, and supply-chain exposure. Ranked #14 of 24 in Software Supply Chain Security Software by our editors (6.1/10); pricing: Open source; best for teams needing a supply-chain relationship graph.

6.1/10Editor score
GUAC6.1 Visit GUAC

At a glance

  • Editor score
    6.1 / 10
  • Pricing
    Open source
  • Best for
    Teams needing a supply-chain relationship graph
  • Paid from
    None
  • Dependency analysis
    Yes
  • Facts checked
    20 Sep 2026
GUAC screenshot
  • Where it wins

    • Maps packages, artifacts, sources, vulnerabilities, SBOMs, and attestations
    • Queries transitive dependencies and supply-chain vulnerabilities
    • Offers visualizer, GraphQL, REST, CLI, and persistent PostgreSQL support
  • Where it doesn't

    • Requires self-managed deployment rather than hosted commercial SaaS
    • Artifact signing is not a core GUAC capability
    • Release policy gates are not a core GUAC capability

Our verdict on GUAC

GUAC, or Graph for Understanding Artifact Composition, aggregates software security metadata into a graph of relationships across packages, artifacts, sources, vulnerabilities, SBOMs, and attestations. It is designed for security and engineering teams that need to investigate transitive dependencies, understand supply-chain exposure, support audit and policy analysis, or identify missing metadata. The project is open source and supports web, API, and self-hosted deployments.

Its main strength is breadth within relationship and metadata analysis. GUAC ingests SBOMs and other supply-chain documents, collects metadata from multiple sources, and models SLSA and in-toto attestations. Teams can explore nodes and relationships through the GUAC visualizer, or connect analysis to workflows through GraphQL, REST, and CLI interfaces. Integrations include GitHub, Amazon S3, Google Cloud Storage, Azure Blob Storage, OCI images, and NATS. Persistent PostgreSQL backend support adds a foundation for retaining graph data across analysis activities.

GUAC is a strong fit when the priority is building a shared view of software supply-chain relationships for policy, audit, risk-management, and developer-assistance work. Its open-source, self-managed model can suit teams that want control over deployment and data handling. It is less suitable for organizations seeking a hosted SaaS product centered on artifact signing or release policy gates. Those requirements call for an alternative whose core capabilities directly cover signing verification and gated release workflows.

GUAC pricing

Plans Open sourceFree Free to use — no paid tier required for the core job.
See plans on guac.sh

GUAC fact sheet

Free planNot verified
Paid fromNone
Source & repo securityYes
Dependency analysisYes
SBOM managementYes
Build provenanceYes
Artifact signingNot verified
Provenance attestationsYes
Release policy gatesNot verified
DeploymentCloud, Self-hosted, Browser extension
PlatformsWeb
SupportCommunity, Docs
Built forSmall business, Mid-market, Enterprise (editorial estimate)
Integrations6 integrations: GitHub, Amazon S3, Google Cloud Storage, Azure Blob Storage, OCI images, NATS
PricingOpen source
Websiteguac.sh
Facts checked20 Sep 2026

GUAC integrations

GUAC lists 6 integrations on its own site.

  • GitHub
  • Amazon S3
  • Google Cloud Storage
  • Azure Blob Storage
  • OCI images
  • NATS

Alternatives to GUAC

See all GUAC alternatives →

Used GUAC? Be the first to review it

The editor score above is our own research. What this page doesn't have yet is a reader's view — what you used GUAC for, what worked and what didn't. No stars are seeded and no review is paid for; an editor reads every one before it appears.

Write a reviewTwo minutes · verified accounts only · read by an editor before it appears

Reviews come only from verified accounts. Sign in or create an account first — your e-mail is never shown.

Your rating

0 characters · at least 80, up to 3,000

Posted from your verified account. Reviews appear after an editor reads them, usually within two working days.

Featured on iTechGuides

Featured on iTechGuides — GUAC 6.1/10

GUAC is listed in our Software Supply Chain Security Software directory. Add the badge to your site — it links back to this page.

<a href="https://www.itechguides.com/products/guac/"><img src="https://www.itechguides.com/best/badge/guac.svg" alt="Featured on iTechGuides" width="230" height="46"></a>

Guides on software supply chain security software

Reviewed by iTechGuides Editors · Editorial team · Updated Sep 2026

Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. How we rank.

Last updated · How we research and update