--- id: P-REINFORCE-AUTO-A04F7E category: "10_Wiki/๐Ÿ’ก Topics/Programming & Language" confidence_score: 0.90 tags: [auto-reinforced] last_reinforced: 2026-04-20 github_commit: "[P-Reinforce] Continuous Worker - SCA (์†Œํ”„ํŠธ์›จ์–ด ๊ตฌ์„ฑ ๋ถ„์„)" --- # [[SCA (แ„‰แ…ฉแ„‘แ…ณแ„แ…ณแ„‹แ…ฐแ„‹แ…ฅ แ„€แ…ฎแ„‰แ…ฅแ†ผ แ„‡แ…ฎแ†ซแ„‰แ…ฅแ†จ)|SCA (์†Œํ”„ํŠธ์›จ์–ด ๊ตฌ์„ฑ ๋ถ„์„)]] ## ๐Ÿ“Œ ํ•œ ์ค„ ํ†ต์ฐฐ (The Karpathy Summary) > SCA(Software Composition Analysis)๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ํฌํ•จ๋œ ์ œ3์ž(Third-party) ์ฝ”๋“œ ๋ฐ ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์˜ ์˜์กด์„ฑ(Dependencies)์„ ๋ถ„์„ํ•˜๋Š” ๋ณด์•ˆ ํ…Œ์ŠคํŒ… ๊ธฐ๋ฒ•์ž…๋‹ˆ๋‹ค [1, 2]. ์ฃผ๋กœ ์™ธ๋ถ€ ์ปดํฌ๋„ŒํŠธ์— ์ด๋ฏธ ๋ณด๊ณ ๋œ ๋ณด์•ˆ ์ทจ์•ฝ์ (CVE ๋“ฑ)๊ณผ ๋ผ์ด์„ ์Šค ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ด€๋ จ ๋ฆฌ์Šคํฌ๋ฅผ ์‹๋ณ„ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค [1]. ์˜ค๋Š˜๋‚  ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœ์—์„œ ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์‚ฌ์šฉ ๋น„์ค‘์ด ๋งค์šฐ ๋†’๊ธฐ ๋•Œ๋ฌธ์— ์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋ง ๋ณด์•ˆ์„ ๊ด€๋ฆฌํ•˜๋Š” ๋ฐ ์žˆ์–ด ๊ทธ ์ค‘์š”์„ฑ์ด ์ปค์ง€๊ณ  ์žˆ์œผ๋ฉฐ [1, 2], ์ž์ฒด ์ฝ”๋“œ๋ฅผ ๊ฒ€์‚ฌํ•˜๋Š” SAST์™€ ํ•จ๊ป˜ ์ƒํ˜ธ ๋ณด์™„์ ์œผ๋กœ ํ™œ์šฉ๋ฉ๋‹ˆ๋‹ค [3]. ## ๐Ÿ“– ๊ตฌ์กฐํ™”๋œ ์ง€์‹ (Synthesized Content) - **๋ถ„์„ ๋Œ€์ƒ ๋ฐ ์ฃผ์š” ๋ชฉ์ **: SCA๋Š” ๊ฐœ๋ฐœ์ž๊ฐ€ ์ง์ ‘ ์ž‘์„ฑํ•œ ์ปค์Šคํ…€ ์ฝ”๋“œ์˜ ๋…ผ๋ฆฌ์  ๊ฒฐํ•จ์„ ์ฐพ๋Š” SAST์™€ ๋‹ฌ๋ฆฌ, ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ํฌํ•จ๋œ ์˜คํ”ˆ์†Œ์Šค ๋ฐ ์ œ3์ž ์˜์กด์„ฑ ์ปดํฌ๋„ŒํŠธ ๋ถ„์„์— ํŠนํ™”๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค [1, 2]. ๊ตฌ์„ฑ ์š”์†Œ์˜ ๋ผ์ด์„ ์Šค ์„ธ๋ถ€ ์ •๋ณด, ๋ฒ„์ „ ์ด๋ ฅ, ๊ธฐ์กด ์ทจ์•ฝ์  ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค(CVE ๋“ฑ)์— ๋“ฑ๋ก๋œ ์ทจ์•ฝ์ ์„ ํŒŒ์•…ํ•˜์—ฌ ๋ผ์ด์„ ์Šค ๊ทœ์ • ์ค€์ˆ˜ ๋ฐ ๋ฆฌ์Šคํฌ ๊ด€๋ฆฌ๋ฅผ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค [1, 2]. - **์˜์กด์„ฑ(Dependency) ๊ฐ€์‹œ์„ฑ ํ™•๋ณด**: ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ฝ”๋“œ์— ์ง์ ‘ ์„ ์–ธ๋œ ์˜์กด์„ฑ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ๊ทธ ์ด๋ฉด์— ์—ฐ๊ฒฐ๋œ ์ „์ด์  ์˜์กด์„ฑ(transitive dependencies)๊นŒ์ง€ ์ถ”์ ํ•ฉ๋‹ˆ๋‹ค [1]. ๋งŽ์€ ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์— ์˜์กดํ•˜์—ฌ ๊ฐœ๋ฐœ์ด ์ด๋ฃจ์–ด์ง€๋Š” ํ˜„๋Œ€์  ํ™˜๊ฒฝ์—์„œ, ์ด๋Ÿฌํ•œ ๊ณต๊ธ‰๋ง(Supply-chain) ์œ„ํ—˜ ๊ด€๋ฆฌ์˜ ํ•ต์‹ฌ ๋„๊ตฌ๋กœ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค [1, 2]. - **๋„๋‹ฌ ๊ฐ€๋Šฅ์„ฑ(Reachability) ๋ถ„์„์˜ ์ง„ํ™”**: ์ตœ์‹  SCA ๋„๊ตฌ๋“ค(์˜ˆ: Endor Labs)์€ ๋‹จ์ˆœํžˆ ์ทจ์•ฝํ•œ ์˜คํ”ˆ์†Œ์Šค ํŒจํ‚ค์ง€๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ๋Š”์ง€๋ฅผ ํ™•์ธํ•˜๋Š” ๊ฒƒ์„ ๋„˜์–ด, ํ•ด๋‹น ์„œ๋“œํŒŒํ‹ฐ ์ฝ”๋“œ ๋‚ด์˜ ์ทจ์•ฝํ•œ ํ•จ์ˆ˜๊ฐ€ ์‹ค์ œ ํผ์ŠคํŠธํŒŒํ‹ฐ(First-party) ์ฝ”๋“œ์˜ ์‹คํ–‰ ๊ฒฝ๋กœ๋ฅผ ํ†ตํ•ด ํ˜ธ์ถœ๋˜๋Š”์ง€ ๋ถ„์„ํ•˜๋Š” '๋„๋‹ฌ ๊ฐ€๋Šฅ์„ฑ ๊ธฐ๋ฐ˜ SCA(Reachability-based SCA)'๋กœ ์ง„ํ™”ํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค [4, 5]. ์ด๋Š” ๋งฅ๋ฝ์„ ๊ณ ๋ คํ•œ ํ•„ํ„ฐ๋ง์„ ํ†ตํ•ด ์•Œ๋ฆผ ํ”ผ๋กœ๋„๋ฅผ ์ค„์ด๊ณ , ์ž์ฒด ์ฝ”๋“œ์™€ ์˜์กด์„ฑ ๋ฆฌ์Šคํฌ์˜ ์šฐ์„ ์ˆœ์œ„๋ฅผ ํšจ๊ณผ์ ์œผ๋กœ ์ง€์ •ํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋•์Šต๋‹ˆ๋‹ค [4, 6]. - **๋ณด์•ˆ ๋„๊ตฌ ๊ฐ„์˜ ๊ฒฐํ•ฉ (SAST + SCA)**: SAST๋Š” ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์ฝ”๋“œ๊ฐ€ ๋ถ„์„ ๋ฒ”์œ„์— ํฌํ•จ๋˜์ง€ ์•Š์œผ๋ฉด ํ•ด๋‹น ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์˜ ์ทจ์•ฝ์ ์„ ๋†“์น  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค [1]. ๋”ฐ๋ผ์„œ ์ปค์Šคํ…€ ์ฝ”๋“œ๋ฅผ ๋ณดํ˜ธํ•˜๋Š” SAST์™€ ์„œ๋“œํŒŒํ‹ฐ ์ปดํฌ๋„ŒํŠธ ์ทจ์•ฝ์ ์„ ๋ณดํ˜ธํ•˜๋Š” SCA๋ฅผ ๋™์‹œ์— ์‚ฌ์šฉํ•˜์—ฌ ์ „์ฒด ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ ๋ฒ”์œ„๋ฅผ ํฌ๊ด„์ ์œผ๋กœ ๋ฐฉ์–ดํ•˜๋Š” ๊ฒƒ์ด ๊ถŒ์žฅ๋ฉ๋‹ˆ๋‹ค [1-3]. ## โš ๏ธ ๋ชจ์ˆœ ๋ฐ ์—…๋ฐ์ดํŠธ (Contradictions & RL Update) - **๊ณผ๊ฑฐ ๋ฐ์ดํ„ฐ์™€์˜ ์ถฉ๋Œ:** ์ž๋™ํ™” ์—”์ง„์— ์˜ํ•ด ๋งคํ•‘๋œ ์ง€์‹์œผ๋กœ, ์ถ”ํ›„ ์ •๋ฐ€ ๊ฒ€์ฆ ํ•„์š”. - **์ •์ฑ… ๋ณ€ํ™”:** Programming & Language ๋ถ„์•ผ์˜ ์ž๋™ ์ž์‚ฐํ™” ์ˆ˜ํ–‰. ## ๐Ÿ”— ์ง€์‹ ์—ฐ๊ฒฐ (Graph) - **Related Topics:** [[SAST (แ„Œแ…ฅแ†ผแ„Œแ…ฅแ†จ แ„‹แ…ขแ„‘แ…ณแ†ฏแ„…แ…ตแ„แ…ฆแ„‹แ…ตแ„‰แ…งแ†ซ แ„‡แ…ฉแ„‹แ…กแ†ซ แ„แ…ฆแ„‰แ…ณแ„แ…ตแ†ผ)|SAST (์ •์  ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ ํ…Œ์ŠคํŒ…)]], [[แ„‰แ…ฅแ„‘แ…ณแ†ฏแ„…แ…กแ„‹แ…ต แ„Žแ…ฆแ„‹แ…ตแ†ซ แ„‡แ…ฉแ„‹แ…กแ†ซ (Supply Chain Security)|์„œํ”Œ๋ผ์ด ์ฒด์ธ ๋ณด์•ˆ (Supply Chain Security)]], [[แ„‹แ…ฉแ„‘แ…ณแ†ซแ„‰แ…ฉแ„‰แ…ณ แ„แ…ฅแ†ทแ„‘แ…ฉแ„‚แ…ฅแ†ซแ„แ…ณ (Open Source Components)|์˜คํ”ˆ์†Œ์Šค ์ปดํฌ๋„ŒํŠธ (Open Source Components)]], [[แ„ƒแ…ฉแ„ƒแ…กแ†ฏ แ„€แ…กแ„‚แ…ณแ†ผแ„‰แ…ฅแ†ผ แ„‡แ…ฎแ†ซแ„‰แ…ฅแ†จ (Reachability Analysis)|๋„๋‹ฌ ๊ฐ€๋Šฅ์„ฑ ๋ถ„์„ (Reachability Analysis)]] - **Projects/Contexts:** [[แ„ƒแ…ฆแ„‡แ…ณแ„‰แ…ฆแ†จแ„‹แ…ฉแ†ธแ„‰แ…ณ (DevSecOps) แ„’แ…ชแ†ซแ„€แ…งแ†ผแ„‹แ…ฆแ„‰แ…ฅแ„‹แ…ด แ„Œแ…ตแ„‰แ…ฉแ†จแ„Œแ…ฅแ†จแ„‹แ…ตแ†ซ แ„‡แ…ฉแ„‹แ…กแ†ซ แ„€แ…ฅแ†ทแ„‰แ…ก|๋ฐ๋ธŒ์„น์˜ต์Šค (DevSecOps) ํ™˜๊ฒฝ์—์„œ์˜ ์ง€์†์ ์ธ ๋ณด์•ˆ ๊ฒ€์‚ฌ]], [[Snyk, Checkmarx, Endor Labs แ„ƒแ…ณแ†ผ แ„Œแ…ฉแ†ผแ„’แ…กแ†ธ แ„‹แ…ขแ„‘แ…ณแ†ฏแ„…แ…ตแ„แ…ฆแ„‹แ…ตแ„‰แ…งแ†ซ แ„‡แ…ฉแ„‹แ…กแ†ซ แ„‘แ…ณแ†ฏแ„…แ…ขแ†บแ„‘แ…ฉแ†ท|Snyk, Checkmarx, Endor Labs ๋“ฑ ์ข…ํ•ฉ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ ํ”Œ๋žซํผ]] - **Contradictions/Notes:** ์—ฌ๋Ÿฌ ์†Œ์Šค์—์„œ SCA์™€ SAST๋Š” ์„œ๋กœ ๋Œ€์ฒดํ•˜๊ฑฐ๋‚˜ ๊ฒฝ์Ÿํ•˜๋Š” ๊ด€๊ณ„๊ฐ€ ์•„๋‹ˆ๋ผ๋Š” ์ ์„ ๋ถ„๋ช…ํžˆ ํ•ฉ๋‹ˆ๋‹ค. SAST๋Š” ์ž์ฒด ์ž‘์„ฑ ์ฝ”๋“œ์˜ ๋…ผ๋ฆฌ ๊ฒฐํ•จ์„, SCA๋Š” ์„œ๋“œํŒŒํ‹ฐ ์ฝ”๋“œ์˜ ๋ฒ„์ „ ์ด๋ ฅ ๋ฐ ๋ผ์ด์„ ์Šค ๋ฌธ์ œ๋ฅผ ์žก์•„๋‚ด๊ธฐ ๋•Œ๋ฌธ์— ๊ฐ ๋„๊ตฌ์˜ ์•ฝ์ ์„ ๋ณด์™„ํ•˜๋ ค๋ฉด ์ด ๋‘˜์„ ๊ฒฐํ•ฉํ•˜์—ฌ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ๋ชจ๋ฒ” ์‚ฌ๋ก€๋กœ ๊ฐ•์กฐ๋ฉ๋‹ˆ๋‹ค [1, 2]. --- *Last updated: 2026-04-18* - Raw Source: 00_Raw/2026-04-20/SCA (์†Œํ”„ํŠธ์›จ์–ด ๊ตฌ์„ฑ ๋ถ„์„).md ---