Software Composition Analysis (SCA): Know Your Dependency Risk | Nurbak

SOFTWARE COMPOSITION ANALYSIS

Software composition analysis that cuts the noise

Most of your code is other people's code. Nurbak's software composition analysis finds the vulnerable and risky dependencies you pulled in, and, crucially, tells you which ones you actually reach, so you fix what matters. Free scan to start.

Create account and connect GitHub

We never store your code. We only write when you ask for a fix PR.

Maps your real dependency tree

Direct and transitive packages, so a vulnerability three levels deep doesn't hide from you.

Reachability, not just presence

A CVE in a package you never call isn't your emergency. It flags what your code actually reaches first.

Catches risky packages, not just CVEs

Abandoned, typo-squatted or suspicious dependencies, supply-chain risk a CVE list alone misses.

Private and self-owned model

Runs on our own model on ephemeral infra; your code never reaches a third-party AI and isn't stored.

How the SCA scan works

1

Create your account and connect GitHub.

2

We resolve your direct and transitive dependencies.

3

The model checks each for known and likely risk.

4

You get findings ranked by reachability and impact.

5

Re-scan after upgrades to confirm the risk is gone.

Software composition analysis FAQ

What is software composition analysis?

SCA analyzes the open-source and third-party components in your code to find known vulnerabilities and licensing or supply-chain risk. Nurbak adds reachability so you fix the dependencies your code actually uses first.

How is it different from a plain dependency scanner?

A plain scanner lists every CVE in every package, including ones you never call. Nurbak reasons about which dependencies your code actually reaches, so the list is short and actionable.

Is it free?

Yes. The free scan works on any repository: you see your security score and the 3 most important findings in full, plus 1 fix Pull Request on us. Paid plans unlock the full report and continuous monitoring.

Is my code shared with a third party?

No. Analysis runs on our own model on ephemeral infrastructure; your code is deleted after the scan and never reaches OpenAI or Anthropic.

Related articles

Security

What Is an SBOM? Software Bill of Materials Explained

An SBOM is the ingredient list of your software: every library, version and supplier in a machine-readable file. Here is what goes inside one, why regulators now ask for it, CycloneDX vs SPDX, how to generate one with Syft, cdxgen or GitHub, and how to actually use it.

Security

SAST vs SCA: Your Code vs Your Dependencies, and Why You Need Both

SAST analyzes the code your team writes. SCA analyzes the open-source code you import. Here is a practical comparison of software composition analysis vs SAST: what each finds, where they overlap, why reachability and lockfiles matter, license risk and how to run both on every pull request.

Run software composition analysis free

See which of your dependencies are actually putting you at risk in minutes.

Scan my repo