SecurityDevOps/Cloud

Software Composition Analysis

Also written as SCA, Dependency Scanning

Scanning the third-party libraries an application depends on for known vulnerabilities — most code in a modern app was written by someone else.

Think of it like

Like checking every ingredient supplier's recall notices, not just inspecting your own kitchen.

Junior or senior?

Junior sounds like

Has seen the alerts.

Senior sounds like

Talks about prioritising by whether the vulnerable code path is actually reachable, rather than patching everything red.

Ask them

“How did you decide which dependency vulnerabilities to fix first?”