Content deleted Content added
m Add word |
|||
Line 1:
{{Use dmy dates|date=February 2023}}
{{Short description|Software Composition Analysis}}
It is a common
{{Cite journal
|last1=Nierstrasz|first1=Oscar
Line 54 ⟶ 55:
* OSS Version Control: risks of changes introduced by new versions
* Security: risks of vulnerabilities in components - [[Common Vulnerabilities and Exposures|Common Vulnerabilities & Exposures]] (or CVEs)
* License: risks of [[Intellectual property
* Development: risks of compatibility between existing codebase and [[open-source software]]
* Support: risk of poor documentation and [[Obsolescence|Obsolete software components]]
Line 83 ⟶ 84:
==Overview==
'''Software Composition Analysis''' (SCA) is a practice in the fields of
{{Cite journal
|last1=Prana|first1=Gede Artha Azriadi
Line 150 ⟶ 151:
== Usage ==
As SCA impacts different functions in organizations, different teams may use the data depending on the organization's corporation size and structure. The IT department will often use SCA for implementing and operationalizing the technology with common stakeholders including the
Depending on the SCA product capabilities, it can be implemented directly within a developer's [[Integrated_development_environment|Integrated Development Environment]] (IDE) who uses and integrates OSS components, or it can be implemented as a dedicated step in the [[software quality control]] process.<ref>
Line 185 ⟶ 186:
}}</ref>
SCA products, and particularly their capacity to generate an SBOM is required in some countries such as the
Another common use case for SCA is for Technology [[Due diligence
{{Cite journal
|last1=Serafini|first1=Daniele
Line 266 ⟶ 267:
}}</ref>
* Limiting vulnerability data to reporting only on vulnerabilities officially reported in the NVD (which can be months after the vulnerability was originally discovered)<ref> {{Cite web|url=https://owasp.org/www-community/Component_Analysis|title=Component Analysis|website=owasp.org}}</ref>
* Lack of automated guidance on actions to take based on SCA reports and data
{{Cite journal
|last1=Foo|first1=Darius
|