Why Software Composition Analysis (SCA) Demands Precision

Why Software Composition Analysis (SCA) Demands Precision

July 24, 2019
By Katie McCaskey

4 minute read time

As leaders in software composition analysis (SCA), we know its role throughout today's software supply chain.

SCA was born out of necessity. How else could innovators discover, identify, and track open source software (OSS) components within their applications? SCA may be best known for tracking capabilities, such as adherence to license requirements (e.g., "you can use this code, just buy me a beer"). Others value it for identifying security vulnerabilities inherent in open source projects ( "Red alert! Red alert!"). Yet, the technology can do far more than that.

Our product suite helps developers and security professionals at every stage of software development. Our tools locate, manage, and protect the best quality open source software components.

Of these capabilities, which is most critical?

To find out, we commissioned 451 Research, a global research firm, to evaluate the case for SCA. The report, Software Composition Analysis: Getting to the Signal Through the Noise, written by Scott Crawford, Research Director, is revealing.

Superior Precision Necessary for Secure Software Production

The report identifies precision as the most important element an SCA tool must master. By 451's measure, Sonatype excels in this domain. Precision ensures secure software development from concept through delivery.

Consider:

Below are three precision-related characteristics found in Sonatype's elite SCA management tools.

Superior Coverage Beyond Public Datasets

Sonatype Intelligence uses proprietary natural language processes. This provides in-depth vulnerability data beyond public databases, such as the NVD.

This means:

Data Precision "As Deployed" Extremely Valuable

Scanning manifest files ("as declared") does not identify true risk. That’s because an "as declared" scan does not analyze embedded dependencies. This introduces the potential for intended and unintended changes in production.

Sonatype Nexus Repository scans post-build artifacts, including binaries ("as deployed"). Our Advanced Binary Fingerprinting (ABF), reveals the truth about third-party risk with in-depth visibility.

Scanning "as deployed":

Integrated Toolset and End-to-End Approach

Sonatype Platform breaks down siloed security tools. This reduces risk and potential costs, with seamless policy governance across the entire software life cycle.

This end-to-end approach offers:

Read the entire 451 Pathfinder Report here.

Written by Katie McCaskey

Katie is an experienced technology writer and entrepreneur. At Sonatype, she's focused on creating and finding great content.