Overview
CodeAnt AI’s Software Composition Analysis (SCA) feature analyzes third-party packages and dependencies for vulnerabilities, ensuring your applications are protected from supply chain risks. By scanning your package manifests and lock files, we identify security issues in open-source components and provide actionable insights to keep your dependencies secure.Key Features
- Vulnerability Database Integration: Continuously updated vulnerability detection using CVE databases and security advisories.
- Severity Filtering: Filter vulnerabilities by severity (Critical, High, Medium, Low) to prioritize remediation efforts.
- Package Health Analysis: Assess the overall health and maintenance status of your dependencies.
- Multi-Ecosystem Support: Analyze packages across npm, PyPI, Maven, RubyGems, NuGet, Go modules, Cargo, Swift, Hex, pub, and more.
- Reachability Analysis: An AI agent traces whether your code actually reaches each vulnerable function, so your team fixes what matters first.
- Exploit Intelligence: Prioritize with CVSS scores, EPSS exploit probability, and CISA Known Exploited Vulnerabilities (KEV) signals.
- Production and Transitive Insights: See which vulnerable packages ship to production and which arrive through transitive dependencies.
- License Compliance: Identify license risks and ensure compliance with your organization’s policies.
- Dependency Tree Visualization: Understand the full dependency chain and identify transitive vulnerabilities.
- Update Recommendations: Get specific version recommendations for secure package updates.
- Triage and Ticketing: Dismiss, re-prioritize, and create tickets in Jira, Linear, GitHub, or Azure DevOps directly from your results.
- Autofixing: Automatically update vulnerable packages to secure versions (Coming soon).
How It Works
- Select Repository: Choose the repository containing the package manifests you want to analyze.
- Scan Dependencies: The system automatically detects and scans package.json, requirements.txt, pom.xml, Gemfile, and other dependency files.
- Vulnerability Detection: Third-party packages are analyzed against known vulnerability databases and security advisories.
- Reachability Verification: An AI agent confirms which vulnerabilities your code can actually reach.
- Filter Results: Use filtering options to focus on critical vulnerabilities or specific package ecosystems.
- Review Impact: Examine detailed vulnerability information including CVE details, CVSS scores, and exploitation likelihood.
- Remediation Guidance: Receive specific recommendations for updating or replacing vulnerable packages.
- Autofix (Coming Soon): Automatically update vulnerable dependencies to secure versions with compatibility checks.
Supported Package Managers
- JavaScript/TypeScript: npm, yarn, pnpm
- Python: pip, pipenv, poetry, conda
- Java/Kotlin/Scala: Maven, Gradle, sbt, Ivy, Mill
- Ruby: Bundler
- .NET: NuGet, Paket
- Go: Go modules
- PHP: Composer
- Rust: Cargo
- Swift: Swift Package Manager
- Elixir: Mix
- Dart/Flutter: pub
Reachability Analysis
Not every vulnerable package puts your application at risk. CodeAnt AI’s reachability analysis uses an AI agent to trace whether your code actually calls the vulnerable function, so your team can focus on the vulnerabilities that matter.
Each verdict comes with its evidence: the vulnerable symbols your code uses, what an attacker could do, and the call path from your code to the vulnerable function. Click Verify with agent on any vulnerability to run the check on demand.
Private Repository Scanning
CodeAnt AI now supports scanning private repositories as part of SCA (Software Composition Analysis). This enhancement allows vulnerability detection and risk assessment to include private dependency libraries, providing a more complete and accurate security posture.How to Configure Private Repositories
When configuring SCA for your repository, you can include private repositories that contain dependencies used by your application.Steps to Add Private Repositories
- Navigate to SCA Configuration: Go to Settings → Analysis Configuration, select your repository, and turn on Software Composition Analysis (SCA).
- Add Private Repositories: Under Private Repository Scanning, click “Configure Private Repository” to include private repositories in your SCA scan.
-
Specify Repository Details:
- Repository: Select the repository (e.g.,
org/private-library-1) - Branch: Select the branch to scan (e.g.,
main,develop), or keep the default branch - Checkout path (optional): The directory your build expects the repository in
- Repository: Select the repository (e.g.,
- Save Configuration: Click “Add”, then save your configuration.
Benefits of Private Repository Scanning
When private repositories are configured, SCA results will aggregate vulnerabilities and metrics across all scanned repositories, including:- The primary (triggering) repository
- All configured private repositories
- Total vulnerabilities across all dependencies (public and private)
- Healthy packages from both public and private sources
- Overall risk assessment including private dependencies
- Complete dependency chain visibility
Example Use Case
Scenario: Your e-commerce application (myorg/ecommerce-app) depends on two internal private libraries:
myorg/payment-sdk- Custom payment processing librarymyorg/auth-library- Internal authentication library
- In SCA settings for
myorg/ecommerce-app, click “Add” to include private repositories - Add the following:
- Repository:
myorg/payment-sdk, Branch:main - Repository:
myorg/auth-library, Branch:develop
- Repository:
express, lodash, etc. in your main application.
With private repository scanning enabled:
- 18 vulnerabilities detected (instead of just 5 from public packages)
- 150 total packages scanned (including dependencies from your private libraries)
- Complete dependency chain showing vulnerabilities in both
payment-sdkandauth-library