Security analysis
SCA with SBOM
Inventory dependencies, identify component risk and retain SBOM evidence.
Software Composition Analysis inventories project dependencies and associates eligible vulnerability data with the generated Software Bill of Materials. The result summarizes files scanned, dependencies scanned, total vulnerabilities and elapsed time.
Review component identity, version and dependency path before upgrading or accepting risk. Regenerate SCA and SBOM evidence after dependency or lockfile changes; an earlier SBOM does not describe the new revision.
What the product adds to source analysis
Section titled “What the product adds to source analysis”An application includes more than the code its team wrote. Libraries and transitive dependencies can introduce exposure even when the first-party implementation has no detected issue. SCA provides the component inventory and vulnerability context needed to investigate that part of the application.
Use the dependency path to understand why a component is present, then check the version and available finding information. An upgrade may require changes to a direct dependency or lockfile rather than only the flagged transitive package. Validate the updated application before accepting the remediation.
SBOM evidence and formats
Section titled “SBOM evidence and formats”The published offering supports SPDX and CycloneDX analysis and reports. These formats describe software materials and relationships for different security, provenance and governance uses. Use the report and download controls available for the selected scan rather than assuming every export is enabled.
Retain the artifact with its project and revision when it supports a release or investigation. A component inventory describes what was assessed; it is not a guarantee that all components are vulnerability-free.
Related product views
Section titled “Related product views”ASPM relates dependency risk to the project’s commit progression. Package Analysis assesses eligible packaged inputs, and Cortex Cloud can include eligible SBOM and dependency evidence in a managed release workflow.
See the public SCA and SBOM introduction and component-analysis overview for the product background.

