Home / Services / Cloud Security / SCA
Cloud Security / Dependency & SBOM managementUnderstand the risks in your OSS
through your SBOM.
SCA (Software Composition Analysis) identifies the OSS and libraries your applications use and manages vulnerability, end-of-life (EOL), license and supply chain risks. It builds SBOMs from container images, serverless functions, virtual machines and source code repositories, and re-checks them each time a new vulnerability is published. The scanner runs inside your cloud.
Challenges
Sound familiar?
You don't know what's in use
When a critical vulnerability is published, just identifying which systems use the affected library takes time.
No way to prioritize
So many vulnerabilities are detected that you can't decide which to address first.
SBOMs are being requested
Business partners and regulations increasingly require you to disclose your software composition.
Features
SCA key features
01SBOMs from a wide range of sources
Builds CycloneDX SBOMs from container images, serverless functions, virtual machines and GitHub / GitLab repositories.
02Agentless VM scanning
EC2, Azure VM and Compute Engine are scanned from disk snapshots. No agent needs to be installed on servers.
03Multiple vulnerability databases
Checks against NVD, GitHub Advisory and OSV, plus Japan's JVN iPedia. Data is updated daily and SBOMs are re-evaluated automatically.
04Prioritized by exploitability
Ranks what to address first using CISA KEV (known exploited vulnerabilities), ransomware exploitation and EPSS exploit prediction scores.
05End of life and licenses
Detects languages, runtimes and operating systems that have reached end of support, and classifies OSS licenses by risk level. Also useful for legal review.
06Supply chain risk
Looks at the risk in the dependencies themselves, with health assessment via OpenSSF Scorecard, malicious package detection and maintainer change detection.
07Built into the development workflow
Returns check results and comments on GitHub pull requests and sends statuses to GitLab. CI can block builds based on severity.
08AI explanations and reports
AI suggests explanations for each vulnerability, response priorities and approaches to end-of-life issues. You can also create reports for executives, teams and auditors.
Coverage
From build to production,
identify every component you use
Vulnerable components can slip in anywhere: source code repositories, registry images, or running servers and functions. SCA scans each stage from development to production in the way that fits it, and brings the results together in one SBOM inventory.
Container registries
Automatically scans images in Amazon ECR, Azure Container Registry and Google Artifact Registry on every push. Also rescans periodically.
Serverless functions
Ingests packages from AWS Lambda (functions and layers), Azure Functions and Cloud Functions and identifies their dependencies.
Virtual machines
Reads disk snapshots of EC2, Azure VM and Compute Engine and detects installed packages.
Source code repositories
Reads dependencies from lock files in GitHub and GitLab repositories and checks them on every push and pull request.
Please note: The scanner runs inside your cloud (deployed with CloudFormation on AWS, ARM templates on Azure and Terraform on Google Cloud), and never sends image or disk contents outside. SBOMs and findings are managed in the CyberForces console.
Shift left
Stop vulnerable components
before they are merged
Catching an issue at the pull request stage takes far less effort to fix than finding it in production. SCA returns results to the GitHub and GitLab screens developers already use.
Pull request checks
Install the GitHub App to scan on every push and pull request and return check results and a summary comment.
Results sent to GitLab
Connect a GitLab project to scan on every push and send results as commit statuses.
Block in CI
Integrate with GitHub Actions to fail builds when vulnerabilities at or above a specified severity, such as critical, high or medium, are found.
AI assistant
From a pile of findings,
AI shows the next move
SCA's AI takes CVSS, EPSS, KEV, fixed versions and where a component is used into account, and organizes findings so people can make decisions easily. The AI runs on your Amazon Bedrock.
Per-vulnerability explanations
Summarizes what you need to decide on a response, such as what the vulnerability means and whether updating to a fixed version resolves it.
Response priorities
From many findings, lists what to tackle first, with reasons, based on exposure and exploitation status.
End-of-life response
For runtimes and operating systems that have reached end of support, suggests migration targets and how to proceed.
Specifications
Scope and delivery
| Targets |
|
|---|---|
| Vulnerability data |
|
| Where it runs |
|
| Output |
|
| Notifications |
|
| Pricing |
|
Please note: Reachability analysis (determining whether vulnerable functions are actually called) is planned for a future release. AI explanations require Amazon Bedrock to be set up in your account.
Getting started
Getting started
Connect your cloud
Deploy the scanner into your cloud with a template.
Connect repositories
Install the GitHub App or connect GitLab as needed.
Continuous checking
Automatically re-checks when images are pushed and when new vulnerabilities are published.
Respond by priority
Fix what needs attention first, based on KEV, EPSS and AI explanations.
FAQ
FAQ
Are image contents sent outside?
The scanner runs inside your cloud, so image and disk contents are never sent to CyberForces. What the console manages is SBOMs and findings.
How is this different from SAST?
SAST finds vulnerabilities in source code you write yourself; SCA finds known vulnerabilities in the OSS and libraries you use. Combining both gives broad coverage of your application's weaknesses.
Works well with
SCA — details and demo requests
Our team will explain deployment options and pricing for your environment.