Software Composition Analysis (SCA) inventories the open-source components in an application — direct and transitive dependencies — and checks them against databases of known vulnerabilities (CVEs) and license obligations. Since modern applications are mostly assembled from open source, SCA covers the majority of the shipped code.

How SCA works

SCA tools read manifests and lockfiles (package.json, pom.xml, requirements.txt), resolve the full dependency graph, and match component versions against vulnerability databases. Better engines add reachability analysis — whether the vulnerable function is actually called — to cut noise.

Why SCA findings explode

  • Transitive dependencies multiply: one direct package can pull in hundreds.
  • New CVEs are published daily against components you already ship.
  • The same vulnerable package appears in dozens of repositories at once.
  • Fix availability varies — sometimes the patch is a major-version migration.

The operational question

The hard part at enterprise scale is rarely the scanner — it is knowing every repository and pipeline is actually scanned, deciding centrally which severities block builds, and proving both to an audit.

RELATED CONCEPTS