SCA

Supported scan options

  • Available options
    • Scan without building, using dependency files
    • Scan even when gradle.lock is absent

Scanning with a build

1. Scan an exported SBOM

If the project can be built, generate an SBOM during the build and use its package information for the scan.

2. Scan build artifacts

You can also scan built JAR files or installed node_modules directories.

Scanning without a build

Language Dependency files
C/C++
  • conan.lock
Dart
  • pubspec.lock
Elixir
  • mix.lock
Go
  • go.mod
Haskell
  • cabal.project.freeze
  • stack.yaml.lock
Java
  • buildscript-gradle.lockfile
  • gradle.lockfile
  • gradle/verification-metadata.xml
  • pom.xml
JavaScript
  • package-lock.json
  • pnpm-lock.yaml
  • yarn.lock
.NET
  • deps.json
PHP
  • composer.lock
Python
  • Pipfile.lock
  • poetry.lock
  • requirements.txt
  • pdm.lock
  • uv.lock
R
  • renv.lock
Ruby
  • Gemfile.lock
Rust
  • Cargo.lock

Rust source reachability

Rust SCA uses crates.io packages identified in Cargo.lock together with source-code reachability signals.

  • When assessing vulnerabilities, check both use of the relevant APIs and the package version.
  • For malicious packages, check whether the project uses the package.

Image and container scanning

You can also scan Docker container images.