Difference between revisions of "Software Composition Analysis (SCA)"
Jump to navigation
Jump to search
↑ https://github.blog/2020-09-30-code-scanning-is-now-available/
Tags: Mobile web edit, Mobile edit |
|||
(12 intermediate revisions by the same user not shown) | |||
Line 1: | Line 1: | ||
− | |||
[[wikipedia:Software Composition Analysis]] | [[wikipedia:Software Composition Analysis]] | ||
Line 21: | Line 20: | ||
* [[Fortify Static Code Analyzer]] (SCA) | * [[Fortify Static Code Analyzer]] (SCA) | ||
* [[GitLab Ultimate]]: [[GitLab Security Dashboards]] | * [[GitLab Ultimate]]: [[GitLab Security Dashboards]] | ||
+ | * [[GitHub code scanning]] (Sep 2020) <ref>https://github.blog/2020-09-30-code-scanning-is-now-available/</ref> | ||
* [[JFrog Xray]] | * [[JFrog Xray]] | ||
* [[Snyk]] (2015, UK) | * [[Snyk]] (2015, UK) | ||
* [[Sonatype]] | * [[Sonatype]] | ||
* [[Synopsys]]: [[Black Duck]] and [[Black Duck Binary Analysis]] | * [[Synopsys]]: [[Black Duck]] and [[Black Duck Binary Analysis]] | ||
− | * [[Veracode]]: [[Veracode SCA]] and [[SourceClear]] SCA | + | * [[Veracode]]: [[Veracode SCA]] (<code>[[srcclr]]</code>) and [[SourceClear]] SCA |
* [[WhiteHat Security]]: WhiteHat Sentinel SCA | * [[WhiteHat Security]]: WhiteHat Sentinel SCA | ||
* [[WhiteSource]] (2011): automatic [[remediation]] | * [[WhiteSource]] (2011): automatic [[remediation]] | ||
Line 31: | Line 31: | ||
== Related terms == | == Related terms == | ||
− | * [[Application Security Testing]] | + | * [[Application Security Testing (AST)]]: [[SAST]], [[DAST]] |
* <code>[[npm audit]]</code> | * <code>[[npm audit]]</code> | ||
+ | * <code>[[docker scan]]</code> | ||
+ | * [[Amazon Inspector]] | ||
+ | * [[Static program analysis]]: <code>[[eslint]]</code> | ||
== See also == | == See also == | ||
Line 38: | Line 41: | ||
* [[Binary repository manager]] | * [[Binary repository manager]] | ||
* {{SCA}} | * {{SCA}} | ||
− | * {{ | + | * {{AST}} |
[[Category:Security]] | [[Category:Security]] | ||
+ | [[Category:SCA]] |
Latest revision as of 19:21, 16 May 2022
wikipedia:Software Composition Analysis
Contents
Options[edit]
- License risk management
- Policy management
- Vulnerability identification
- Vulnerability management
- SDLC integration
- Container scanning
- Serverless scanning
Reports
Products[edit]
- Flexera: FlexNet Code Insight
- FOSSA: Compliance*
- Fortify Static Code Analyzer (SCA)
- GitLab Ultimate: GitLab Security Dashboards
- GitHub code scanning (Sep 2020) [1]
- JFrog Xray
- Snyk (2015, UK)
- Sonatype
- Synopsys: Black Duck and Black Duck Binary Analysis
- Veracode: Veracode SCA (
srcclr
) and SourceClear SCA - WhiteHat Security: WhiteHat Sentinel SCA
- WhiteSource (2011): automatic remediation
- SonarQube (2006-2007)
Related terms[edit]
- Application Security Testing (AST): SAST, DAST
npm audit
docker scan
- Amazon Inspector
- Static program analysis:
eslint
See also[edit]
- CA Technologies
- Binary repository manager
- Software Composition Analysis (SCA): Flexera, FOSSA, GitLab Ultimate, JFrog Xray, Snyk, Sonatype, Synopsys: Black Duck, Veracode, WhiteHat Security, WhiteSource, Bill of Materials (BOM), Semgrep, Clair
- Application Security Testing (SAST, DAST, IAST): Fortify WebInspect, GitLab Ultimate, flawfinder, Kubesec, Coverity, SonarQube, SCA, Checkmarx
Advertising: