{"id":651,"date":"2026-08-13T06:25:26","date_gmt":"2026-08-13T06:25:26","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=651"},"modified":"2026-08-13T06:25:26","modified_gmt":"2026-08-13T06:25:26","slug":"sca","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/sca\/","title":{"rendered":"SCA Explained: Safer Open-Source Dependencies"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: SCA\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">SCA identifies the open-source libraries your application depends on and checks each one against known vulnerabilities and licence obligations.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Code security<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Software composition analysis builds an inventory of every third-party component in your codebase, including the ones you never chose directly, and reports which have published vulnerabilities and which carry licence terms you may not want. Most of a modern application is imported code, so most of its known vulnerabilities arrive this way.<\/p>\n<\/div>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#transitive\">The dependencies you did not choose<\/a><\/li>\n    <li><a href=\"#reports\">What SCA reports<\/a><\/li>\n    <li><a href=\"#priority\">Prioritising what to upgrade<\/a><\/li>\n    <li><a href=\"#osto\">How Osto runs code security<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"transitive\">The dependencies you did not choose<\/h2>\n\n<p>You add a handful of libraries. Each of those pulls in its own, and so on. The result is a tree where the code you selected is a small fraction of the code you ship, and where most vulnerabilities sit several levels down.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 310\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Dependency tree: your application depends on three direct libraries, which pull in eleven transitive ones, with a known CVE two levels down.\">\n  <rect x=\"300\" y=\"26\" width=\"160\" height=\"42\" rx=\"12\" fill=\"#1c267a\"\/>\n  <text x=\"380\" y=\"52\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#ffffff\">Your application<\/text>\n\n  <line x1=\"380\" y1=\"68\" x2=\"180\" y2=\"102\" stroke=\"#c3c9f0\" stroke-width=\"1.8\"\/>\n  <line x1=\"380\" y1=\"68\" x2=\"380\" y2=\"102\" stroke=\"#c3c9f0\" stroke-width=\"1.8\"\/>\n  <line x1=\"380\" y1=\"68\" x2=\"580\" y2=\"102\" stroke=\"#c3c9f0\" stroke-width=\"1.8\"\/>\n\n  <text x=\"66\" y=\"128\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#25547a\">You chose<\/text>\n  <text x=\"66\" y=\"143\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#25547a\">these 3<\/text>\n\n  <rect x=\"110\" y=\"104\" width=\"140\" height=\"38\" rx=\"10\" fill=\"#c2d9ec\"\/>\n  <text x=\"180\" y=\"121\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#25547a\">web-framework<\/text>\n  <text x=\"180\" y=\"135\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">direct dependency<\/text>\n  <rect x=\"310\" y=\"104\" width=\"140\" height=\"38\" rx=\"10\" fill=\"#c2d9ec\"\/>\n  <text x=\"380\" y=\"121\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#25547a\">auth-library<\/text>\n  <text x=\"380\" y=\"135\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">direct dependency<\/text>\n  <rect x=\"510\" y=\"104\" width=\"140\" height=\"38\" rx=\"10\" fill=\"#c2d9ec\"\/>\n  <text x=\"580\" y=\"121\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" font-weight=\"700\" fill=\"#25547a\">pdf-generator<\/text>\n  <text x=\"580\" y=\"135\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">direct dependency<\/text>\n\n  <g stroke=\"#dfe3f5\" stroke-width=\"1.5\">\n    <line x1=\"180\" y1=\"142\" x2=\"120\" y2=\"176\"\/><line x1=\"180\" y1=\"142\" x2=\"180\" y2=\"176\"\/><line x1=\"180\" y1=\"142\" x2=\"240\" y2=\"176\"\/>\n    <line x1=\"380\" y1=\"142\" x2=\"320\" y2=\"176\"\/><line x1=\"380\" y1=\"142\" x2=\"380\" y2=\"176\"\/><line x1=\"380\" y1=\"142\" x2=\"440\" y2=\"176\"\/>\n    <line x1=\"580\" y1=\"142\" x2=\"520\" y2=\"176\"\/><line x1=\"580\" y1=\"142\" x2=\"580\" y2=\"176\"\/><line x1=\"580\" y1=\"142\" x2=\"640\" y2=\"176\"\/>\n  <\/g>\n\n  <text x=\"66\" y=\"196\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#0f1538\">They pulled<\/text>\n  <text x=\"66\" y=\"211\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#0f1538\">in these 11<\/text>\n\n  <rect x=\"76\" y=\"178\" width=\"88\" height=\"30\" rx=\"8\" fill=\"#e9ecfa\"\/>\n  <text x=\"120\" y=\"197\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#4a52a8\">http-parser<\/text>\n  <rect x=\"176\" y=\"178\" width=\"88\" height=\"30\" rx=\"8\" fill=\"#e9ecfa\"\/>\n  <text x=\"220\" y=\"197\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#4a52a8\">logger<\/text>\n  <rect x=\"276\" y=\"178\" width=\"88\" height=\"30\" rx=\"8\" fill=\"#e9ecfa\"\/>\n  <text x=\"320\" y=\"197\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#4a52a8\">token-utils<\/text>\n  <rect x=\"376\" y=\"178\" width=\"88\" height=\"30\" rx=\"8\" fill=\"#f2cdb2\" stroke=\"#a2603a\" stroke-width=\"1.6\"\/>\n  <text x=\"420\" y=\"197\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" font-weight=\"700\" fill=\"#7e4426\">crypto-core<\/text>\n  <rect x=\"476\" y=\"178\" width=\"88\" height=\"30\" rx=\"8\" fill=\"#e9ecfa\"\/>\n  <text x=\"520\" y=\"197\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#4a52a8\">image-codec<\/text>\n  <rect x=\"576\" y=\"178\" width=\"88\" height=\"30\" rx=\"8\" fill=\"#e9ecfa\"\/>\n  <text x=\"620\" y=\"197\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#4a52a8\">font-loader<\/text>\n\n  <rect x=\"126\" y=\"218\" width=\"88\" height=\"30\" rx=\"8\" fill=\"#e9ecfa\"\/>\n  <text x=\"170\" y=\"237\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#4a52a8\">stream-buf<\/text>\n  <rect x=\"226\" y=\"218\" width=\"88\" height=\"30\" rx=\"8\" fill=\"#e9ecfa\"\/>\n  <text x=\"270\" y=\"237\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#4a52a8\">yaml-reader<\/text>\n  <rect x=\"326\" y=\"218\" width=\"88\" height=\"30\" rx=\"8\" fill=\"#e9ecfa\"\/>\n  <text x=\"370\" y=\"237\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#4a52a8\">base64<\/text>\n  <rect x=\"426\" y=\"218\" width=\"88\" height=\"30\" rx=\"8\" fill=\"#e9ecfa\"\/>\n  <text x=\"470\" y=\"237\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#4a52a8\">date-utils<\/text>\n  <rect x=\"526\" y=\"218\" width=\"88\" height=\"30\" rx=\"8\" fill=\"#e9ecfa\"\/>\n  <text x=\"570\" y=\"237\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#4a52a8\">compress<\/text>\n\n  <rect x=\"150\" y=\"266\" width=\"16\" height=\"16\" rx=\"5\" fill=\"#f2cdb2\" stroke=\"#a2603a\" stroke-width=\"1.6\"\/>\n  <text x=\"176\" y=\"279\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Known CVE, two levels below your own code. You never chose it, and you still have to fix it.<\/text>\n  <text x=\"380\" y=\"302\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Component names shown are illustrative.<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>A vulnerability two levels down is still yours to fix, and the upgrade path usually runs through the direct dependency above it.<\/figcaption>\n<\/figure>\n\n<h2 id=\"reports\" class=\"c-sage\">What SCA reports<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Output<\/th><th>Why it matters<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Component inventory<\/strong><\/td><td>Every library and version actually present, direct and transitive<\/td><\/tr>\n    <tr><td><strong>Known vulnerabilities<\/strong><\/td><td>Matches against CVE and advisory databases, with severity<\/td><\/tr>\n    <tr><td><strong>Licence obligations<\/strong><\/td><td>Copyleft terms that can affect how you distribute your product<\/td><\/tr>\n    <tr><td><strong>Upgrade path<\/strong><\/td><td>The version that resolves the issue, and which direct dependency to bump<\/td><\/tr>\n    <tr><td><strong>Component age<\/strong><\/td><td>Unmaintained packages, which are a risk even with no CVE today<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"priority\" class=\"c-apri\">Prioritising what to upgrade<\/h2>\n\n<p>An SCA report on a mature codebase will list more findings than any team can act on at once. Severity alone is a weak filter, for the same reason it is weak elsewhere: it describes the vulnerability, not your exposure.<\/p>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Is it reachable?<\/p>\n    <p>A vulnerable function your code never calls is far less urgent than one on a request path.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Is it being exploited?<\/p>\n    <p>Presence in the known exploited catalogue moves a finding straight to the top.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Is a fix available?<\/p>\n    <p>A finding with no patched version needs a different response: replace, isolate, or compensate.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto runs code security<\/h2>\n\n<p>Osto&#8217;s code security module covers SCA alongside <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">SAST<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">SBOM<\/a> generation and open-source licence compliance, so dependency findings, code findings and the component inventory come from one place. Because the platform also runs the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a> and vulnerability testing, a dependency finding can be assessed against whether the affected path is exposed in production rather than in isolation.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Know what is actually in your build<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto covers SCA alongside SAST, SBOM generation and open-source licence compliance, with findings read against production exposure.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Direct and transitive coverage &middot; Licence checks &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What does SCA stand for?<\/summary>\n  <p>Software composition analysis. It identifies the third-party and open-source components in a codebase and checks them against known vulnerability databases and licence terms.<\/p>\n<\/details>\n\n<details>\n  <summary>What is a transitive dependency?<\/summary>\n  <p>A library pulled in by another library rather than chosen by you. Most dependencies in a modern application are transitive, and a large share of dependency vulnerabilities sit among them.<\/p>\n<\/details>\n\n<details>\n  <summary>How is SCA different from SAST?<\/summary>\n  <p>SAST analyses code your team wrote. SCA analyses code you imported. They find different classes of problem and neither substitutes for the other.<\/p>\n<\/details>\n\n<details>\n  <summary>Why does SCA report licences?<\/summary>\n  <p>Open-source components carry terms. Some copyleft licences impose obligations on how you distribute software that includes them. Enterprise buyers and investors increasingly ask for a licence position during <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-readiness-checklist\/\">due diligence<\/a>.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">SAST<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">SBOM<\/a> &middot; CVE &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability Management<\/a> &middot; Supply Chain Security &middot; DAST<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>SCA identifies the open-source libraries your application depends on and checks each one against known vulnerabilities and licence obligations. Glossary\u2026<\/p>\n","protected":false},"author":8,"featured_media":652,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[234,235],"class_list":["post-651","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-sca","tag-software-composition-analysis"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/651","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=651"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/651\/revisions"}],"predecessor-version":[{"id":653,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/651\/revisions\/653"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/652"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=651"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=651"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=651"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}