01Introduction
Most of the code in a modern application was written by someone else. Open source packages, and the packages they pull in, make up the majority of what ships, and every one of them can carry a known vulnerability or a license problem.
02What is SCA?
Software composition analysis (SCA) inventories the third-party components in an application, matches them against vulnerability databases and license data, and recommends upgrades.
SCA is the scanner category behind software supply chain security and the usual source of an SBOM. The newest generation adds reachability analysis to separate exploitable findings from theoretical ones.
03How SCA works
SCA resolves what you actually ship, then checks it.
- 1.
Resolve the graph
Read manifests and lockfiles such as package-lock.json, go.sum, poetry.lock or Gradle files, including transitive dependencies.
- 2.
Match advisories
Compare each package version with CVE, GitHub Security Advisory and ecosystem databases.
- 3.
Check licenses
Flag copyleft or unknown licenses that conflict with how the software is distributed.
- 4.
Recommend fixes
Suggest the smallest safe upgrade, ideally as a pull request.
04Threats and risks
Dependency risk is broad, but most of it is noise.
CVE floods
Hundreds of advisories per repository, most in code paths the app never calls.
Transitive exposure
The vulnerable package is four levels deep, pulled in by something nobody chose directly.
Malicious packages
Typosquats and compromised maintainers ship malware with no CVE at all.
Breaking upgrades
The fix is a major version bump, so the ticket sits in the backlog.
05How Parameter helps
Parameter Supply Chain is SCA that answers whether a finding is real.
Reachability, not a CVE dump
Agents trace call graphs and data flow to check whether your code can reach the vulnerable function. 92% of advisories are filtered out as unreachable.
Every ecosystem
npm, PyPI, Go modules, Maven and Gradle, and more, across direct and transitive dependencies.
Fixes as pull requests
Safe upgrades arrive as reviewed pull requests. See auto remediation.

