Configure Software Composition Analysis

Seeker integrates the composition analysis tools BDBA® and BDBA® (BDBA).

Software Composition Analysis (SCA) tools enable organizations to audit open-source software compliance, detect vulnerabilities in, and achieve governance over third-party and open source code.

You can choose which of the tools to use for SCA on a per project basis.

Prerequisites: You have configured integration with the tool(s) that you want to use.

For instructions, see Configure Black Duck and Install and Configure Black Duck Binary Analysis.

  1. In the main menu, click (Projects) and open a project that you want to configure.
  2. Click Features, and scroll down to the Others section.
  3. Toggle on the Enabled switch for Software Composition Analysis (SCA).
  4. Click Configure.
  5. From the SCA tool dropdown list, choose the tool that you want to use for the current project or project template.
  6. Click Save.
Results: If you have chosen Black Duck, you will see more detailed information for Vulnerable Component (SCA) detections in the vulnerability details page, and will be able to access the SCA results from Black Duck via a direct link from that page.