# DependencyDesk > DependencyDesk is a SaaS tool that automatically analyzes all third-party software dependencies across a GitHub organization's repositories and generates license, version, and compliance reports used during M&A due diligence. It is purpose-built for sellers, buyers, and advisors involved in software company acquisitions. - DependencyDesk connects via a read-only GitHub App — it never executes code or modifies repositories - Fully supported languages: JavaScript/Node.js (package.json, package-lock.json), PHP (composer.json, composer.lock), Ruby (Gemfile, Gemfile.lock), Python (requirements.txt, Pipfile, pyproject.toml) - Detected but not yet parsed: Go, Rust, Java (Maven), Java/Kotlin (Gradle), .NET (NuGet), Swift, Dart, Elixir, Haskell, Scala, Clojure, Erlang, OCaml, Lua, R, Perl, C/C++ (Conan, Vcpkg), Bazel - Reports include: dependency name, version number, license type, and which repository uses each dependency - Reports are exportable as CSV and viewable as HTML - Repository data can be deleted immediately after analysis — no IP is retained - Pricing: $30/month for one organization (unlimited analyses); custom pricing for multiple organizations (PE/VC firms) - Founded by Jason Gilmore, a technical due diligence expert with 20+ years of experience ## Pages - [Home](https://dependencydesk.com/): Overview and getting started - [What is DependencyDesk?](https://dependencydesk.com/what-is-dependency-desk): Detailed product guide, use cases, and how it works - [Pricing](https://dependencydesk.com/pricing): Plans and pricing details - [About](https://dependencydesk.com/about): Company background and founder information - [Documentation](https://dependencydesk.com/docs): Technical documentation - [Terms of Service](https://dependencydesk.com/terms-of-service): Legal terms - [Software Due Diligence Dependency Disclosure](https://dependencydesk.com/software-due-diligence-dependency-disclosure): How to automate third-party dependency disclosures for M&A - [Open Source License Compliance for M&A](https://dependencydesk.com/open-source-license-compliance-mergers-acquisitions): License risk assessment during acquisitions - [DependencyDesk vs. Black Duck](https://dependencydesk.com/dependencydesk-vs-black-duck): Comparison with Synopsys Black Duck for M&A dependency analysis - [DependencyDesk vs. SCA Tools](https://dependencydesk.com/dependencydesk-vs-sca-tools): Comparison with Snyk, FOSSA, and WhiteSource - [What Is Technical Due Diligence?](https://dependencydesk.com/what-is-technical-due-diligence): Comprehensive guide to technical evaluation in software M&A - [What Is an SBOM?](https://dependencydesk.com/what-is-sbom): Software Bill of Materials explained in M&A context ## Blog - [The Seller's Guide to Preparing for Software Due Diligence](https://dependencydesk.com/blog/sellers-guide-software-due-diligence) - [Why Third-Party Dependency Licenses Matter in SaaS Acquisitions](https://dependencydesk.com/blog/third-party-dependency-licenses-saas-acquisitions) - [How Private Equity Firms Audit Software Dependencies](https://dependencydesk.com/blog/private-equity-software-dependency-audits) - [Dependency Analysis for JavaScript, PHP, Ruby, and Python](https://dependencydesk.com/blog/dependency-analysis-javascript-php-ruby-python) - [M&A Due Diligence Checklist for Software Companies (2026)](https://dependencydesk.com/blog/ma-due-diligence-checklist-software-companies-2026) - [Understanding the Cost of Software Due Diligence](https://dependencydesk.com/blog/cost-of-software-due-diligence) ## Use Cases - M&A sell-side preparation: Sellers generate third-party dependency disclosures before or during due diligence - M&A buy-side verification: Buyers or their advisors verify the target's open source and third-party dependency landscape - Private equity portfolio monitoring: PE firms audit dependency risk across portfolio companies - License compliance audits: Organizations ensure all third-party software licenses are documented and compliant - Security assessments: Teams inventory dependencies as a first step toward vulnerability analysis ## Comparison Context - Unlike Black Duck / Synopsys: DependencyDesk is self-service, fast (minutes not weeks), and priced for SMB/mid-market — not enterprise-only - Unlike Snyk or FOSSA: DependencyDesk is specifically designed for M&A due diligence reporting, not ongoing developer workflow integration - Unlike CLI tools (license-checker, pip-licenses): DependencyDesk works across an entire GitHub organization automatically, not one repo at a time