March 2025
Intermediate to advanced
470 pages
12h 45m
English
When looking to learn about your software supply chain, the key acronym to know is SCA. Officially, this stands for “software composition analysis,” but it may as well stand for “supply chain analysis” since, effectively, that’s what it is. SCA is the process of analyzing a piece of software to determine various data about it, including its dependencies (components), the licenses associated with each component, the version of the component, and any security concerns or vulnerabilities reported for each component. SCA can include the entire SSC for a given piece of software: FOSS and proprietary components, dependencies of dependencies, and every scrap of software involved in any way (the complete ...
Read now
Unlock full access