Fix SCA vulnerabilities
Last updated: Sep 30, 2026
Software Composition Analysis (SCA) reports frequently flag vulnerabilities in transitive dependencies. These issues are hard to fix. You do not control the version of a transitive dependency. A direct or intermediate dependency controls it.
The sections below give remediation guides for these ecosystems: JavaScript (npm and pnpm), Python (uv), Kotlin (Gradle), and Rust (Cargo).
Other tools can report more findings for the same codebase. Most of them count one finding for each workspace or manifest file. Fluid Attacks counts one finding for each unique CVE, thus each finding is one task: one finding, one action.
Check your fix before you push
After you apply a fix, run the SCA scanner on your working copy. Make sure that the finding is gone before a pipeline tells you.
docker run --rm -v "$PWD":/my-dir fluidattacks/sca:latest sca scan /my-dirIf you run the scanner after each change,
add an alias to your shell startup file.
Use ~/.zshrc for zsh, ~/.bashrc for bash,
or a different ~/.aliases file that the two files source.
alias sca-scan='docker run --rm -v "$PWD":/my-dir fluidattacks/sca:latest sca scan /my-dir'Open a new shell, or run source ~/.zshrc.
Then one word scans the repository in your current directory:
sca-scanAdd --strict to the sca scan call
to get a non-zero exit code when the scanner finds a vulnerability.
Use this option in a pre-push hook.
A group token is not necessary for a local scan. Authentication only attributes the run to your group in the Fluid Attacks platform. It does not block the scan.
Custom remediation guides
Learn to use the generative artificial intelligence integrated with the Fluid Attacks VS Code extension to receive specific vulnerability remediation guidance.
In JavaScript
Learn the recommended strategies to remediate SCA vulnerabilities found in transitive npm and pnpm dependencies, from updating packages to using dependency overrides.