Skip to content

Software Composition Analysis (SCA)

Definition

A category of security tooling that scans source code, build manifests, and container images to identify open-source and third-party components, match them against vulnerability databases (CVE, OSV, GHSA), and flag licence compliance issues. SCA is the primary automated control for supply-chain dependency risk.

Full form
Software Composition Analysis
Scans
Source code, build manifests, container images
Matched against
CVE, OSV, GHSA vulnerability databases
Also flags
Licence compliance issues

Common questions

How does SCA differ from static application security testing (SAST)?+

SAST analyses the code an organisation writes itself for security flaws. SCA instead focuses on third-party and open-source components pulled into the project, identifying which known-vulnerable packages are present, a distinct risk surface that SAST does not typically cover.

Can SCA tools miss a vulnerability in an open-source dependency?+

Yes. SCA relies on matching identified components against known vulnerability databases, so a flaw that has not yet been publicly disclosed or catalogued in those databases will not be flagged until the databases are updated.

Why does SCA also check licence compliance rather than only security?+

Pulling in an open-source component under a licence incompatible with how the organisation distributes its own software creates legal exposure, so SCA tools are built to surface that risk alongside vulnerability findings during the same scan of dependencies.

Related terms

Dependency Confusion
An attack technique in which an attacker publishes a public package with the same name as an organisation's internal private package at...
NIST SP 800-161R1
The US National Institute of Standards and Technology publication 'Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations' (Revision 1, 2022)....
Software Bill of Materials (SBOM)
A structured, machine-readable inventory of the software components in a product or system. Captures component names, versions, licences, and dependency relationships. Standard...
Transitive Dependency
A software library that an application does not import directly but is pulled in automatically because a direct dependency requires it. Transitive...
Vendor Due Diligence
The pre-procurement and ongoing process of assessing a supplier's security practices before and during a commercial relationship. In supply-chain risk management, due...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.