SCA
Software Composition Analysis
Software Composition Analysis identifies open-source and third-party components in a codebase and checks them against vulnerability databases. SCA tools track dependency trees, flag outdated libraries, verify license compliance, and alert teams when new CVEs affect their software supply chain.
Como é usado em cibersegurança
Security engineers integrate SCA into CI/CD pipelines to block builds that include vulnerable dependencies. GRC analysts review SCA reports to confirm third-party component risk stays within acceptable thresholds. Security architects select and standardize SCA tools across development teams to ensure consistent supply chain visibility.
Termo relacionado no glossário: sca
As definições são explicações originais escritas para fins de desenvolvimento profissional. Para definições técnicas autoritativas, consulte NIST, ISO ou o órgão de normalização correspondente.