Home / Services / Cloud Security / SCA

Cloud Security / Dependency & SBOM management

Understand the risks in your OSS
through your SBOM.

SCA (Software Composition Analysis) identifies the OSS and libraries your applications use and manages vulnerability, end-of-life (EOL), license and supply chain risks. It builds SBOMs from container images, serverless functions, virtual machines and source code repositories, and re-checks them each time a new vulnerability is published. The scanner runs inside your cloud.

Challenges

Sound familiar?

You don't know what's in use

When a critical vulnerability is published, just identifying which systems use the affected library takes time.

No way to prioritize

So many vulnerabilities are detected that you can't decide which to address first.

SBOMs are being requested

Business partners and regulations increasingly require you to disclose your software composition.

Features

SCA key features

01SBOMs from a wide range of sources

Builds CycloneDX SBOMs from container images, serverless functions, virtual machines and GitHub / GitLab repositories.

02Agentless VM scanning

EC2, Azure VM and Compute Engine are scanned from disk snapshots. No agent needs to be installed on servers.

03Multiple vulnerability databases

Checks against NVD, GitHub Advisory and OSV, plus Japan's JVN iPedia. Data is updated daily and SBOMs are re-evaluated automatically.

04Prioritized by exploitability

Ranks what to address first using CISA KEV (known exploited vulnerabilities), ransomware exploitation and EPSS exploit prediction scores.

05End of life and licenses

Detects languages, runtimes and operating systems that have reached end of support, and classifies OSS licenses by risk level. Also useful for legal review.

06Supply chain risk

Looks at the risk in the dependencies themselves, with health assessment via OpenSSF Scorecard, malicious package detection and maintainer change detection.

07Built into the development workflow

Returns check results and comments on GitHub pull requests and sends statuses to GitLab. CI can block builds based on severity.

08AI explanations and reports

AI suggests explanations for each vulnerability, response priorities and approaches to end-of-life issues. You can also create reports for executives, teams and auditors.

Coverage

From build to production,
identify every component you use

Vulnerable components can slip in anywhere: source code repositories, registry images, or running servers and functions. SCA scans each stage from development to production in the way that fits it, and brings the results together in one SBOM inventory.

CONTAINER

Container registries

Automatically scans images in Amazon ECR, Azure Container Registry and Google Artifact Registry on every push. Also rescans periodically.

SERVERLESS

Serverless functions

Ingests packages from AWS Lambda (functions and layers), Azure Functions and Cloud Functions and identifies their dependencies.

VM

Virtual machines

Reads disk snapshots of EC2, Azure VM and Compute Engine and detects installed packages.

REPOSITORY

Source code repositories

Reads dependencies from lock files in GitHub and GitLab repositories and checks them on every push and pull request.

Please note: The scanner runs inside your cloud (deployed with CloudFormation on AWS, ARM templates on Azure and Terraform on Google Cloud), and never sends image or disk contents outside. SBOMs and findings are managed in the CyberForces console.

Shift left

Stop vulnerable components
before they are merged

Catching an issue at the pull request stage takes far less effort to fix than finding it in production. SCA returns results to the GitHub and GitLab screens developers already use.

GITHUB APP

Pull request checks

Install the GitHub App to scan on every push and pull request and return check results and a summary comment.

GITLAB

Results sent to GitLab

Connect a GitLab project to scan on every push and send results as commit statuses.

GITHUB ACTIONS

Block in CI

Integrate with GitHub Actions to fail builds when vulnerabilities at or above a specified severity, such as critical, high or medium, are found.

AI assistant

From a pile of findings,
AI shows the next move

SCA's AI takes CVSS, EPSS, KEV, fixed versions and where a component is used into account, and organizes findings so people can make decisions easily. The AI runs on your Amazon Bedrock.

TRIAGE

Per-vulnerability explanations

Summarizes what you need to decide on a response, such as what the vulnerability means and whether updating to a fixed version resolves it.

PRIORITIES

Response priorities

From many findings, lists what to tackle first, with reasons, based on exposure and exploitation status.

EOL

End-of-life response

For runtimes and operating systems that have reached end of support, suggests migration targets and how to proceed.

Specifications

Scope and delivery

Targets
  • Container images (ECR / ACR / Artifact Registry)
  • Serverless functions (Lambda / Azure Functions / Cloud Functions)
  • Virtual machines (EC2 / Azure VM / Compute Engine, snapshot-based)
  • Repositories (GitHub / GitLab)
Vulnerability data
  • NVD / GitHub Advisory / OSV / JVN iPedia
  • CISA KEV / EPSS
Where it runs
  • The scanner runs inside your cloud (AWS CloudFormation / Azure ARM / Terraform)
Output
  • CycloneDX SBOM
  • PDF / Markdown reports (for executives, teams and auditors)
  • REST API
Notifications
  • Email / Slack / Webhook
Pricing
  • Charged by the number of registered cloud accounts

Please note: Reachability analysis (determining whether vulnerable functions are actually called) is planned for a future release. AI explanations require Amazon Bedrock to be set up in your account.

Getting started

Getting started

  1. Connect your cloud

    Deploy the scanner into your cloud with a template.

  2. Connect repositories

    Install the GitHub App or connect GitLab as needed.

  3. Continuous checking

    Automatically re-checks when images are pushed and when new vulnerabilities are published.

  4. Respond by priority

    Fix what needs attention first, based on KEV, EPSS and AI explanations.

FAQ

FAQ

Are image contents sent outside?

The scanner runs inside your cloud, so image and disk contents are never sent to CyberForces. What the console manages is SBOMs and findings.

How is this different from SAST?

SAST finds vulnerabilities in source code you write yourself; SCA finds known vulnerabilities in the OSS and libraries you use. Combining both gives broad coverage of your application's weaknesses.

Works well with

SCA — details and demo requests

Our team will explain deployment options and pricing for your environment.