CodeArts Governance
CodeArts Governance
- Service Overview
- Getting Started
- User Guide
- Best Practices
-
FAQs
-
Binary Software Composition Analysis (SCA)
- What Objects Can Be Scanned?
- What Are the Precautions of Binary SCA?
- How Does Binary SCA Work and What Risks Can be Identified?
- How Do I Handle Open-Source Software Vulnerabilities?
- How Do I Handle Secure Complier Option Vulnerabilities?
- How Do I Handle Security Configuration Issues?
- How Do I Handle Information Leakage Risks?
- Why Is the Component Version Not Identified or Incorrectly Identified?
- Why Can't I Buy a CodeArts Governance Package?
- How Do I View the Path of a File that Has Vulnerabilities?
- What Can I Do If a Binary SCA Task Fails?
- How Do I Check User Group Permissions and Grant Permissions?
- What Should I Do If a Role Permission Error (Roles with READONLY_USER) Is Reported?
-
Binary Software Composition Analysis (SCA)
- General Reference
On this page
Show all
Help Center/
CodeArts Governance/
FAQs/
Binary Software Composition Analysis (SCA)/
How Does Binary SCA Work and What Risks Can be Identified?
Copied.
How Does Binary SCA Work and What Risks Can be Identified?
CodeArts Governance decompresses and scans your software packages and firmware. It performs component feature analysis based on the bill of materials (BOM) to identify possible rule violations. The following lists the vulnerabilities that can be identified.
- Open source software's known vulnerabilities and license compliance risks.
- Security configuration risks in hard-coded credentials, sensitive files (keys, certificate, and debugging tools), OS authentication, and access control.
- Disclosure risks of IP addresses, hard-coded keys, passwords, and Git/SVN repositories.
- Compiler security option risks in binary program compilation.
Figure 1 Risk items
Parent topic: Binary Software Composition Analysis (SCA)
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
The system is busy. Please try again later.
For any further questions, feel free to contact us through the chatbot.
Chatbot