Veracode Software Composition Analysis (SCA) identifies and manages vulnerabilities in third-party and open-source components used within applications. It provides an inventory of third-party components, detects known vulnerabilities, and offers remediation guidance to mitigate risks. The solution supports both upload-based scans and agent-based scans, integrating into the development lifecycle for early vulnerability detection. It offers detailed reporting in formats such as CSV and PDF, and provides features like dependency mapping, automated pull requests, and developer training to enhance secure coding practices.