Zum Hauptinhalt springen
Glossary

SCA (Software Composition Analysis)

Updated on 1 min

SCA (Software Composition Analysis) automatically examines all third-party libraries and open-source components of an application for known vulnerabilities and licence conflicts. Tools such as Snyk, Dependabot, or OWASP Dependency-Check match deployed versions against CVE databases. Ideally you integrate SCA into your CI/CD pipeline so that vulnerable dependencies are caught before deployment. In an ISMS, SCA is a control for secure software development and supply-chain security. Together with SAST and DAST, SCA forms the third pillar of application security.

No Cookies!

This wiki collects nothing, bakes nothing and leaves nothing behind. There's nothing to consent to. Privacy doesn't get better than this.