Black Duck SCA is a software composition analysis solution that identifies and manages security, quality, and license compliance risks associated with open source and third-party code in applications and containers. The platform uses multiple scan technologies to detect open source dependencies in source code, files, artifacts, containers, and firmware through various discovery techniques including direct and transitive dependencies from package managers, post-build artifacts analysis, binary scanning for modified binaries, and code snippet matching to original open source projects. The solution detects vulnerabilities through Black Duck Security Advisories that extend beyond the National Vulnerability Database with research from the Cybersecurity Research Center. It manages licenses through a knowledge base containing over 2,750 unique open source licenses with full license text and encoded attributes. Black Duck SCA generates Software Bills of Materials with SPDX 3.0 support and integrates with development tools including IDEs, package managers, CI/CD systems, and issue trackers across the software development lifecycle.