---
id: sca
requestedLanguage: en
descriptionLanguage: en
---

# Software Composition Analysis

- Type: component analysis practice
- Group: Security
- Placement: Security
- [Source](<https://github.com/OWASP/DevSecOpsGuideline/blob/master/current-version/2-Process/2-3-Build/2-3-2-Software-Composition-Analysis/2-3-2-1-Software-Composition-Analysis.md>)

[HTML](https://dpm.cnonim.name/practices/sca/)

Inventory third-party components and analyze their known vulnerabilities and licensing constraints.

## Relationships

- assesses components from: [Dependency Management](/practices/dependencies/en.md) (verification)
- analyzes components and complements: [Static Application Security Testing](/practices/sast/en.md) (combination)

[Show on the map](https://dpm.cnonim.name/#practice=sca&lang=en)
