Fix SCA vulnerabilities

Last updated: Sep 30, 2026


Software Composition Analysis (SCA) reports frequently flag vulnerabilities in transitive dependencies. These issues are hard to fix. You do not control the version of a transitive dependency. A direct or intermediate dependency controls it.

The sections below give remediation guides for these ecosystems: JavaScript (npm and pnpm), Python (uv), Kotlin (Gradle), and Rust (Cargo).

Check your fix before you push

After you apply a fix, run the SCA scanner on your working copy. Make sure that the finding is gone before a pipeline tells you.

docker run --rm -v "$PWD":/my-dir fluidattacks/sca:latest sca scan /my-dir

If you run the scanner after each change, add an alias to your shell startup file. Use ~/.zshrc for zsh, ~/.bashrc for bash, or a different ~/.aliases file that the two files source.

alias sca-scan='docker run --rm -v "$PWD":/my-dir fluidattacks/sca:latest sca scan /my-dir'

Open a new shell, or run source ~/.zshrc. Then one word scans the repository in your current directory:

sca-scan

Add --strict to the sca scan call to get a non-zero exit code when the scanner finds a vulnerability. Use this option in a pre-push hook.

On this page