--- id: P-REINFORCE-AUTO-WIKI-SEC-004 category: Dev confidence_score: 0.95 tags: [security, sca, open-source, dependency-management, license-compliance, p-reinforce] last_reinforced: 2026-05-01 --- # [[Software Composition Analysis (SCA)|Software Composition Analysis (SCA]] ## ๐Ÿ“Œ ํ•œ ์ค„ ํ†ต์ฐฐ (The Karpathy Summary) > "์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ๊ตฌ์„ฑํ•˜๋Š” ์™ธ๋ถ€ ์˜คํ”ˆ์†Œ์Šค ์ปดํฌ๋„ŒํŠธ์™€ ์„œ๋“œํŒŒํ‹ฐ ์˜์กด์„ฑ์„ ์Šค์บ”ํ•˜์—ฌ, ์•Œ๋ ค์ง„ ๋ณด์•ˆ ์ทจ์•ฝ์ (CVE)๊ณผ ๋ฒ•์  ๋ผ์ด์„ ์Šค ๋ฆฌ์Šคํฌ๋ฅผ ์‚ฌ์ „์— ์ฐจ๋‹จํ•˜๋Š” '๊ณต๊ธ‰๋ง ๋ณด์•ˆ(Supply Chain Security)'์˜ ํ•ต์‹ฌ ์—”์ง„." ## ๐Ÿ“– ๊ตฌ์กฐํ™”๋œ ์ง€์‹ (Synthesized Content) SCA๋Š” ํ”„๋กœ์ ํŠธ์˜ ์™ธ๋ถ€ ์˜์กด์„ฑ์„ ๊ด€๋ฆฌํ•˜๊ณ  ๋ณด์•ˆ ๋ฌด๊ฒฐ์„ฑ์„ ๊ฒ€์ฆํ•ฉ๋‹ˆ๋‹ค. 1. **์˜์กด์„ฑ ๋ฐ ์ทจ์•ฝ์  ์Šค์บ”**: * NPM, Maven, PyPI ๋“ฑ ํ”„๋กœ์ ํŠธ์— ํฌํ•จ๋œ ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ์Šค์บ”ํ•˜์—ฌ CVE(์•Œ๋ ค์ง„ ์ทจ์•ฝ์ ) ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์™€ ๋Œ€์กฐํ•ฉ๋‹ˆ๋‹ค. * ์ทจ์•ฝํ•œ ๋ฒ„์ „์˜ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๊ฐ€ ์‚ฌ์šฉ๋  ๊ฒฝ์šฐ ๊ฒฝ๊ณ ๋ฅผ ๋ณด๋‚ด๊ณ  ์•ˆ์ „ํ•œ ๋ฒ„์ „์œผ๋กœ์˜ ์—…๋ฐ์ดํŠธ๋ฅผ ์ œ์•ˆํ•ฉ๋‹ˆ๋‹ค. 2. **๋ผ์ด์„ ์Šค ๋ฐ ์ง€์  ์žฌ์‚ฐ๊ถŒ ๋ณดํ˜ธ**: * ์˜คํ”ˆ์†Œ์Šค ๋ผ์ด์„ ์Šค(์˜ˆ: AGPL vs MIT) ์ถฉ๋Œ์„ ๊ฐ์ง€ํ•˜์—ฌ ๋ฒ•์  ๋ฆฌ์Šคํฌ๋ฅผ ๋ฐฉ์–ดํ•ฉ๋‹ˆ๋‹ค. * ํŠนํžˆ AI ์ƒ์„ฑ ์ฝ”๋“œ๊ฐ€ ๋ผ์ด์„ ์Šค ๋ณดํ˜ธ ์ฝ”๋“œ๋ฅผ ๋ฌด๋‹จ ๋ณต์ œํ•˜์—ฌ ๋ณ‘ํ•ฉํ•˜๋Š” ์ƒํ™ฉ์„ ์‹๋ณ„ํ•˜๋Š” ๋ฐ ์œ ์šฉํ•ฉ๋‹ˆ๋‹ค. 3. **CI/CD ํ’ˆ์งˆ ๊ฒŒ์ดํŠธ**: * ์ฝ”๋“œ ๋ฆฌ๋ทฐ ์ด์ „ ๋‹จ๊ณ„์—์„œ ์ทจ์•ฝํ•œ ํŒจํ‚ค์ง€๋ฅผ ์ž๋™์œผ๋กœ ์ฐจ๋‹จํ•˜์—ฌ, ์ธ๊ฐ„ ๋ฆฌ๋ทฐ์–ด์˜ ๊ฒ€ํ†  ๋ถ€๋‹ด์„ ๋Œ€ํญ ๋‚ฎ์ถฅ๋‹ˆ๋‹ค. ## โš ๏ธ ๋ชจ์ˆœ ๋ฐ ์—…๋ฐ์ดํŠธ (Contradictions & RL Update) - **๋‚ด๋ถ€ ๋กœ์ง ๊ฒ€์ฆ์˜ ๋ถ€์žฌ**: SCA๋Š” '์•Œ๋ ค์ง„ ์œ„ํ˜‘'์„ ์ฐพ๋Š” ๋„๊ตฌ์ž…๋‹ˆ๋‹ค. ๊ฐœ๋ฐœ์ž๊ฐ€ ์ง์ ‘ ์ž‘์„ฑํ•œ ์†Œ์Šค ์ฝ”๋“œ ๋‚ด๋ถ€์˜ ๊ณ ์œ ํ•œ ๋กœ์ง ์˜ค๋ฅ˜๋‚˜ ์ œ๋กœ๋ฐ์ด ์ทจ์•ฝ์ ์€ ํƒ์ง€ํ•  ์ˆ˜ ์—†์œผ๋ฏ€๋กœ SAST์™€์˜ ๋ณ‘ํ–‰์ด ํ•„์ˆ˜์ ์ž…๋‹ˆ๋‹ค. - **๋„๋‹ฌ ๊ฐ€๋Šฅ์„ฑ(Reachability)์˜ ๋ฌธ์ œ**: ๋ฐฉ๋Œ€ํ•œ ์ทจ์•ฝ์  ๋ชฉ๋ก ์ค‘ ์‹ค์ œ ๋น„์ฆˆ๋‹ˆ์Šค ๋กœ์ง์—์„œ ํ˜ธ์ถœ๋˜์–ด ํƒ€๊ฒฉ์„ ์ค„ ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์ ์„ ์šฐ์„ ์ˆœ์œ„ํ™”ํ•˜๋Š” ์ •์ฑ…์ด ์šด์˜ ํšจ์œจ์„ฑ์„ ๊ฒฐ์ •์ง“๋Š” ํ•ต์‹ฌ ์—…๋ฐ์ดํŠธ๊ฐ€ ๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค. ## ๐Ÿ”— ์ง€์‹ ์—ฐ๊ฒฐ (Graph) - [[SAST (Static Application Security Testing)|SAST (Static Application Security Testing]]: ๋‚ด๋ถ€ ์†Œ์Šค ๋ถ„์„๊ณผ์˜ ์ƒํ˜ธ ๋ณด์™„. - CVE (Common Vulnerabilities and Exposures: ์ทจ์•ฝ์  ํ‘œ์ค€ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์™€์˜ ์—ฐ๊ฒฐ. - Shift-Left Security: ๋ณด์•ˆ ๊ด€๋ฆฌ์˜ ์กฐ๊ธฐ ๋„์ž…. - Dependabot: ์ž๋™ํ™”๋œ ํŒจํ‚ค์ง€ ์—…๋ฐ์ดํŠธ ์›Œํฌํ”Œ๋กœ์šฐ. - AI-Generated Code Security: AI ์ƒ์„ฑ ์ฝ”๋“œ์˜ ๋ณด์•ˆ ๋ฐ ์ €์ž‘๊ถŒ ๊ฒ€์ฆ. ---