Definition
Software composition analysis (SCA) identifies the open-source components an application uses, usually from lockfiles or manifests, and matches them against databases of known vulnerabilities (CVEs and advisories) and license terms.
How SCA tools work
- Build an inventory from manifests, lockfiles, container layers or binaries (often exported as an SBOM).
- Match each package and version against advisory databases such as the GitHub Advisory Database, OSV and the NVD.
- Report vulnerable versions, the fixed version and license issues, often with automatic upgrade pull requests.
Common tools include npm audit, GitHub Dependabot, OSV-Scanner, Trivy, Snyk Open Source, Mend, Sonatype and Black Duck.
The malware gap
SCA is a lookup: it only flags what someone has already reported. A malicious version published an hour ago, a fresh typosquat or a hijacked release has no advisory yet, so SCA reports it as clean. That window is exactly when supply-chain attacks do their damage.
Closing it requires looking at the code: install scripts, network calls, credential access and obfuscation. Togoder Security complements SCA by having an AI reviewer read every source file of every package in a lockfile and publishing the results as public reports.
Frequently asked questions
Is npm audit a software composition analysis tool?
Yes, a basic one: it checks your dependency tree against the GitHub Advisory Database. It does not inspect source code, so it cannot find unreported malware.
What is the difference between SCA and SAST?
SAST analyzes your own source code for bugs. SCA inventories third-party components and checks them against known vulnerabilities. Neither, by default, reads third-party source looking for malicious behavior.