Get listed

Category

Supply Chain

What you installed, not what you wrote. An SBOM names the package. SCA names the vulnerable one you already have. Open a shortlist for the buy you are making.

More categories

Questions about Supply Chain

Does an SBOM replace SCA?

No. One names the tree. The other names the CVE on a package you already have.

Is this SAST?

No. SAST reads your code. This pillar reads what you installed.

Where does IaC sit?

The plan you apply is Platform.