Dependency scanning (SCA)
Security & software supply chain
Dependency scanning (SCA)
Software composition analysis checks dependencies for known risks. Include transitive packages and review whether a finding affects the workload.
Resources
Links marked “Amazon affiliate link” open an Amazon product page. As an Amazon Associate I earn from qualifying purchases. About affiliate links
Open Source Insights (deps.dev)Reference · Google · opens in a new tabTrivy documentationDocumentation · Aqua Security · opens in a new tabOSV: open source vulnerability databaseReference · Google, OpenSSF · opens in a new tabDevOps guides (in French)Blog · Stéphane Robert · opens in a new tabOWASP Cheat Sheet SeriesReference · OWASP · opens in a new tabAlice and Bob Learn Application SecurityBook · Tanya Janca · Amazon affiliate link, opens Amazon in a new tabSecuring DevOpsBook · Julien Vehent · Amazon affiliate link, opens Amazon in a new tabDeveloping Secure Software (LFD121)Course · OpenSSF, The Linux Foundation · opens in a new tab