Please use this identifier to cite or link to this item: https://hdl.handle.net/10356/148846
Title: SCA vs. SCA : a comparison of SCA tools in the market
Authors: Lee, Guan Qing
Keywords: Engineering::Computer science and engineering::Software::Software engineering
Issue Date: 2021
Publisher: Nanyang Technological University
Source: Lee, G. Q. (2021). SCA vs. SCA : a comparison of SCA tools in the market. Final Year Project (FYP), Nanyang Technological University, Singapore. https://hdl.handle.net/10356/148846
Project: PSCSE19-0038
Abstract: In just 2018, there are 16,555 new vulnerabilities discovered from the open-source community, and the total number of vulnerabilities introduced by the use of open-source components had also exceeded 100,000. In the same year, tech giants like Google, Facebook, and Amazon have exposed at least 1 case of a cybersecurity incident. Therefore, SCA (Software Composition Analysis) has become a popular solution for an organization to manage its open-source components’ inventory. Inspired by [1-3], this project focuses on the feature and results comparison of the commercial SCA tools. A command-line tool called Karby is also built to provide a more straightforward way to receive scan results from different SCA tools. This report reveals the limitations of popular commercial and free-to-use SCA tools in terms of features, language coverage, use cases, et cetera.
URI: https://hdl.handle.net/10356/148846
Schools: School of Computer Science and Engineering 
Fulltext Permission: restricted
Fulltext Availability: With Fulltext
Appears in Collections:SCSE Student Reports (FYP/IA/PA/PI)

Files in This Item:
File Description SizeFormat 
FYP_Leeguanqing_U1720332B.pdf
  Restricted Access
1.66 MBAdobe PDFView/Open

Page view(s)

268
Updated on Mar 21, 2025

Download(s)

8
Updated on Mar 21, 2025

Google ScholarTM

Check

Items in DR-NTU are protected by copyright, with all rights reserved, unless otherwise indicated.