Vulnerabilities and scanning
SCA (Software Composition Analysis)
Software Composition Analysis identifies the open-source dependencies in a project, including transitive ones, and matches them against known vulnerability databases such as the NVD, the GitHub Advisory Database and OSV. It covers vulnerabilities in third-party code, including dependencies a project never imports directly. Deva's SCA checks dependency manifests against a catalog of more than 2,800 packages.