OpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.
Integrate OpenSCA-cli into your GitHub Action to assess the supply chain risks associated with your application.