SOFTWARE COMPOSITION ANALYSIS

SourceSeer SCA

Open-Source Composition Analysis

Identify open-source components and dependencies, assess vulnerability and license risks, and generate SBOMs

COMPOSITION INTELLIGENCEIllustrative workflow
Illustrative workflow: a software project unfolds into components and direct and transitive dependencies. Risk is traced along a dependency path, then recorded with component, dependency and license evidence. Package names and results are illustrative, not live scan results.
Open-source project versions
390M+
Open-source component versions
497M+
Open-source components
26M+
Open-source licenses
3,100+
Open-source vulnerabilities
1.16M+

PRODUCT OVERVIEW

From component discovery to ongoing risk management

SourceSeer SCA combines multiple detection technologies with its own analysis engine and open-source knowledge base to identify open-source software assets and assess vulnerabilities and license compliance risks

Continuous vulnerability monitoring, alerts and remediation guidance help enterprises manage open-source risk over time

CORE CAPABILITIES

Core capabilities

04 GROUPS / 08 CAPABILITIES
01

Open-source component identification

Identify open-source components, versions and dependencies through dependency analysis, file signatures and code snippet fingerprints, and generate SBOMs

02

In-house code analysis

Use file signatures and code snippet fingerprints to trace code origins and assess the proportion of in-house code across files and code volume

01 / COMPOSITION
SOURCE PROJECTapplicationsrc / manifest
network-kit2.4.0
data-parser1.8.2
core-utils3.1.0
Transitive dependency
runtime-lib1.2.0
Direct dependencies
File & code fingerprints
Open-source originsIn-house code analysis
Conceptual illustration · Not actual scan resultsProduct screenshot

USE CASES

Use cases

01 — 06
01

Supplier and delivery compliance

Assess suppliers and review software deliveries against component, vulnerability and license requirements, supported by SBOMs and license and copyright notices

02

Open-source release reviews

Review component origins, software composition, license obligations and security risks before an open-source release to guide remediation

03

Software provenance and Xinchuang assessment

Use source-code provenance, software similarity analysis and open-source evaluation to support technology independence, control and compliance assessments in Xinchuang projects

04

Development security governance

Assess risk using deployment context and vulnerability reachability, and support the integration of security checks and governance requirements into development workflows

05

Software asset and risk management

Maintain a software asset inventory, track vulnerability and compliance risks, and support supplier risk assessment and ongoing software supply chain management

06

Security readiness reviews

Review risks in critical software using vulnerability intelligence and impact analysis to support security readiness and remediation planning for critical periods

See SourceSeer SCA in action

See how to identify open-source components, check for vulnerabilities and license risks, and generate an SBOM.

Request a Demo