Dependency review starts with the package files you provide.
SCA is a project assessment surface for authorized source, manifests, and lockfiles. Its outcomes remain in the Workbench inventory rather than becoming a detached component report.
Bring the project source and dependency metadata together.
Add the authorized source to the project, then select the enabled assessment coverage. SCA operates on the package metadata that arrives with that source; it does not inspect an unapproved package registry or external environment.

Triage the affected component in the project inventory.
Use Workbench findings to review the component context and make a remediation decision before export. The page does not fabricate a CVE, reachability result, or customer dependency graph.

Three steps from approved scope to a reviewable result.
- 1
Add the authorized source with its package metadata.
- 2
Run selected project coverage in Workbench.
- 3
Review the component context before remediation or export.