Parameter

What is SCA?

Software composition analysis

What SCA is, how it finds vulnerable and risky open source dependencies, and why reachability decides which findings matter.

01Introduction

Most of the code in a modern application was written by someone else. Open source packages, and the packages they pull in, make up the majority of what ships, and every one of them can carry a known vulnerability or a license problem.

02What is SCA?

Software composition analysis (SCA) inventories the third-party components in an application, matches them against vulnerability databases and license data, and recommends upgrades.

SCA is the scanner category behind software supply chain security and the usual source of an SBOM. The newest generation adds reachability analysis to separate exploitable findings from theoretical ones.

03How SCA works

SCA resolves what you actually ship, then checks it.

  1. 1.

    Resolve the graph

    Read manifests and lockfiles such as package-lock.json, go.sum, poetry.lock or Gradle files, including transitive dependencies.

  2. 2.

    Match advisories

    Compare each package version with CVE, GitHub Security Advisory and ecosystem databases.

  3. 3.

    Check licenses

    Flag copyleft or unknown licenses that conflict with how the software is distributed.

  4. 4.

    Recommend fixes

    Suggest the smallest safe upgrade, ideally as a pull request.

04Threats and risks

Dependency risk is broad, but most of it is noise.

  • CVE floods

    Hundreds of advisories per repository, most in code paths the app never calls.

  • Transitive exposure

    The vulnerable package is four levels deep, pulled in by something nobody chose directly.

  • Malicious packages

    Typosquats and compromised maintainers ship malware with no CVE at all.

  • Breaking upgrades

    The fix is a major version bump, so the ticket sits in the backlog.

05How Parameter helps

Parameter Supply Chain is SCA that answers whether a finding is real.

  • Reachability, not a CVE dump

    Agents trace call graphs and data flow to check whether your code can reach the vulnerable function. 92% of advisories are filtered out as unreachable.

  • Every ecosystem

    npm, PyPI, Go modules, Maven and Gradle, and more, across direct and transitive dependencies.

  • Fixes as pull requests

    Safe upgrades arrive as reviewed pull requests. See auto remediation.

[ Supply Chain ]

See how Parameter Supply Chain fits your SCA program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.