Software composition analysis (SCA) identifies risks that come from the use of open source and third-party code in applications and containers.

The issues found by an SCA scan are not issues that can be identified by either static analysis or dynamic analysis.

When it scans a software project, software composition analysis identifies open source components and then reports on the risks that these might pose. Component scanning helps organizations manage their use of open source binaries by identifying and cataloging open source components in order to provide metadata such as license, vulnerability, and open source software (OSS) project health for those components.