FortiDevSec for SCA Scans

Software Composition Analysis

FortiDevSec scans external open source components and third party libraries

app software

Identify all open-source components in application software

dependency check

Dependency checking of integrated software

vulnerable package

Ensure vulnerable versions are not used in apps

license policy

Check for license policies and organizational mandate

verified applications

Verify apps live on secure infrastructure components

infinity loop

Help DevOps secure apps without slowing them down

target scan

SCA scan runs on every build

blue flag

Flag OSS components used