Skip to content

Security analysis

SCA with SBOM

Inventory dependencies, identify component risk and retain SBOM evidence.

Software Composition Analysis inventories project dependencies and associates eligible vulnerability data with the generated Software Bill of Materials. The result summarizes files scanned, dependencies scanned, total vulnerabilities and elapsed time.

Review component identity, version and dependency path before upgrading or accepting risk. Regenerate SCA and SBOM evidence after dependency or lockfile changes; an earlier SBOM does not describe the new revision.

An application includes more than the code its team wrote. Libraries and transitive dependencies can introduce exposure even when the first-party implementation has no detected issue. SCA provides the component inventory and vulnerability context needed to investigate that part of the application.

Use the dependency path to understand why a component is present, then check the version and available finding information. An upgrade may require changes to a direct dependency or lockfile rather than only the flagged transitive package. Validate the updated application before accepting the remediation.

The published offering supports SPDX and CycloneDX analysis and reports. These formats describe software materials and relationships for different security, provenance and governance uses. Use the report and download controls available for the selected scan rather than assuming every export is enabled.

Retain the artifact with its project and revision when it supports a release or investigation. A component inventory describes what was assessed; it is not a guarantee that all components are vulnerability-free.

ASPM relates dependency risk to the project’s commit progression. Package Analysis assesses eligible packaged inputs, and Cortex Cloud can include eligible SBOM and dependency evidence in a managed release workflow.

See the public SCA and SBOM introduction and component-analysis overview for the product background.