Contrast SCA identifies open-source components through run-time analysis, file system scanning, and dependency analysis. The product analyzes applications' open-source and third-party libraries at build-time and runtime to detect vulnerabilities, license issues, and exploitable paths. It performs runtime analysis to identify specific libraries exercised by the application down to their class, file, or module level. The product identifies CVE vulnerabilities for each library that applications use, including descriptions of each CVE vulnerability and the number of applications using that library. It automatically creates and maintains an organization-wide inventory of open-source and commercial off-the-shelf library code mapped to applications, servers, and environments. The product provides license data tied to open-source components to support intellectual property tracking and operational risk assessment. It flags dependency risk and contextualizes how vulnerable dependencies are introduced, highlighting potential supply chain attack vectors like dependency confusion. The product supports over 30 languages and frameworks for static code scanning. It delivers real-time feedback into third-party software risk by embedding Software Composition Analysis and monitoring controls into applications throughout their life cycle. The product enables application security teams to respond to emerging threats by continuously monitoring for new vulnerabilities in deployed libraries and providing automated alerts.