Black Duck® SCA is a Black Duck® scan engine that performs software composition analysis (SCA).
Black Duck helps teams manage the security, quality, and license compliance risks that come from the use of open source and third-party code in applications and containers. These are issues that neither static analysis nor dynamic analysis can effectively detect.
When it scans a software project, Black Duck identifies open source components, and then reports on the risks that these might pose. Component scanning helps organizations manage their use of open source binaries by identifying and cataloging open source components in order to provide metadata such as license, vulnerability, and open source software (OSS) project health for those components.