PAPER / ARXIV:2609.18391
Li, C.; Xue, Z.; Li, C.
RESUMO
Software supply-chain security requires accurate identification of third-party components and understanding of how they evolve from development to execution. Existing software composition analysis (SCA) approaches examine manifests, build environments, release artifacts, containers, or runtime states, but typically produce only stage-specific views of composition. As dependencies are resolved, removed, repackaged, transformed and across lifecycle stages, a single snapshot cannot capture both where a component originates and where it ultimately ends up. Combining snapshots from multiple stages still leaves their cross-stage relationships unresolved. We present SCA-Agent, an agent-based approach to lifecycle-aware SCA that reconstructs evidence-backed traces across Code, Build, Release, Deploy, and Runtime. SCA-Agent adaptively explores project-specific paths, gathers evidence, and correlates observations across stages to recover component identities, versions, introduction paths, propagation relationships, and final lifecycle states. We evaluate SCA-Agent on 105 real-world projects from the Java, JavaScript, Python ecosystems. SCA-Agent achieves the highest component detection F1 across all lifecycle stages. For vulnerability exposure assessment, it reaches F1 score 96.69%, exceeding the best traditional SCA tool by 18.76 percentage points. These results demonstrate that SCA-Agent supports traceable component provenance and more accurate risk assessment.
NO MESMO MAPA