OpenSCA-cli logo

OpenSCA-cli

An open-source software composition analysis tool that lists dependencies, vulnerabilities and licences in a project.

Open source (Apache-2.0)By Xmirror Security

Compare OpenSCA-cli with another product

Read the OpenSCA-cli documentation

View the OpenSCA-cli source code

2 more ways to get OpenSCA-cli

Alternatives

See all alternatives

About OpenSCA-cli

OpenSCA-cli scans a project's third-party components and the components they depend on, then reports the dependency list, known vulnerabilities and licence information. It can produce SBOM output in standard formats and supports a range of mainstream languages.

It runs as a command-line tool and can also be used through IDE plugins, CI pipeline scripts and code repository integrations. Both online and offline use are supported. It suits developers and security researchers who want a free SCA scanner for supply-chain and licence compliance checks.

Strengths

  • Reports vulnerabilities and licences for dependencies
  • Generates SBOMs in standard formats
  • Works offline as well as online
  • Fits into CLI, IDE and CI workflows

Limitations

  • Website and much documentation are in Chinese

Details

Pricing
FreeFree and open source under the Apache 2.0 licence.
License
Apache-2.0
Developer
Xmirror Security
Platforms
Windows, Command line
How it runs
Downloadable app
Works offline
Yes
Best suited for
Developers checking dependency vulnerabilities and licence compliance
Last verified
Added

Report a wrong fact or a dead link on this listing