Category
What you installed, not what you wrote. An SBOM names the package. SCA names the vulnerable one you already have. Open a shortlist for the buy you are making.
More categories
Questions about Supply Chain
No. One names the tree. The other names the CVE on a package you already have.
No. SAST reads your code. This pillar reads what you installed.
The plan you apply is Platform.