Software composition analysis

Software composition analysis (SCA) reviews dependencies from the authorized project source and its package metadata in Eresus Workbench.

Inputs

Provide the project source with the dependency manifests and lockfiles used by that project. SCA is not a request for Eresus Guard to enumerate an unapproved package registry, production host, or third-party environment.

What a reviewer gets

SCA outcomes enter the same project inventory used for other assessment findings. Review the affected component and its project context before exporting a result or assigning remediation.

The exact dependency formats and advisory coverage depend on the selected source and enabled product version. This documentation does not claim universal registry coverage, an SBOM for every source tree, or reachability proof for every advisory.

Evidence and decision boundary

A component name or advisory identifier is an input to review, not a remediation decision by itself. Validate the package context and the owning application before treating an SCA result as exploitable impact.

Availability

SCA is included from the Professional package. SBOM export is available under the package matrix. See Plans for entitlement details.

Need a workflow that is not documented here? Email contact@eresussec.com.