OpenSCA-cli
An open-source software composition analysis tool that lists dependencies, vulnerabilities and licences in a project.
Compare OpenSCA-cli with another product
Read the OpenSCA-cli documentation
View the OpenSCA-cli source code
2 more ways to get OpenSCA-cli
Chocolatey
choco install opensca-cliHomebrew
brew install opensca-cli
Alternatives
See all alternativesAbout OpenSCA-cli
OpenSCA-cli scans a project's third-party components and the components they depend on, then reports the dependency list, known vulnerabilities and licence information. It can produce SBOM output in standard formats and supports a range of mainstream languages.
It runs as a command-line tool and can also be used through IDE plugins, CI pipeline scripts and code repository integrations. Both online and offline use are supported. It suits developers and security researchers who want a free SCA scanner for supply-chain and licence compliance checks.
Strengths
- Reports vulnerabilities and licences for dependencies
- Generates SBOMs in standard formats
- Works offline as well as online
- Fits into CLI, IDE and CI workflows
Limitations
- Website and much documentation are in Chinese
Details
- Pricing
- FreeFree and open source under the Apache 2.0 licence.
- License
- Apache-2.0
- Developer
- Xmirror Security
- Platforms
- Windows, Command line
- How it runs
- Downloadable app
- Works offline
- Yes
- Best suited for
- Developers checking dependency vulnerabilities and licence compliance
- Categories
- Security tools, Developer tools
- Last verified
- Added
- Sources