Dependency Scanning and Software Composition Analysis
Modern applications are built mostly from third-party code: open-source libraries and their transitive dependencies often make up the large majority of a codebase. Software Composition Analysis identifies these components and checks them against databases of known vulnerabilities. It matters because a flaw in a widely used library is a flaw in every application that includes it, and attackers scan aggressively for such known, unpatched dependencies.
Analogy🏏Cricket
🍳 Think of it like cooking: A recipe can look flawless on paper, but a head chef only truly judges the dish by tasting the finished plate, because heat, timing, and the actual oven reveal problems the written method never shows. Just as tasting the cooked result catches what reading the recipe cannot, DAST probes the running application and catches the misconfigurations and runtime behaviour that reading the source cannot. This reveals DAST's stance: it judges the dish as it is actually served, not the recipe as it was merely written.
🏏 Showing the Cricket analogy — a Cricket version isn’t available for this concept yet.
This lesson explains how SCA inventories dependencies, including the transitive ones you never chose directly, and matches them to advisories. It also covers the practical challenges: prioritising which vulnerabilities actually matter, handling the constant stream of advisories, and defending against supply-chain attacks. The goal is to treat your dependencies as the significant, dynamic attack surface they are, rather than a set-and-forget detail.
Analogy🏏Cricket
💰 Think of it like finance: A real audit that actually attempts a sample transaction proves beyond doubt whether a control can be bypassed, with little room for a false alarm, but it can only test the accounts and processes the auditors actually reach. Just as a hands-on audit yields high-confidence, low-false-positive results yet is bounded by what it examines, DAST yields high-confidence findings about real exploitability yet is bounded by the surface it can reach. This reveals its trade-off: what it confirms is solid, but it only confirms what it manages to touch.
🏏 Showing the Cricket analogy — a Cricket version isn’t available for this concept yet.