Lune

ISSTA2026Top-tier venue

ProgSCA: Software Composition Analysis via Program-Level Modeling

Peihong Li, Cheng Li, Yuchen Gu, Yanzhe Hu, Liheng Chen, Zeyu Gao, Hao Wang, Chao Zhang

2026Year

Abstract

Software composition analysis (SCA) aims to identify third-party dependencies in programs, which plays a critical role in ensuring software supply chain security. Existing approaches largely follow a rule-based paradigm: they first compute function-level similarities, then aggregate these results using handcrafted heuristics to determine which third-party libraries (TPLs) the target program depends on. However, such rules require substantial manual effort and expert knowledge to design, tune, and maintain. To address this, we present ProgSCA, an SCA framework based on a two-stage strategy and program-level rather than function-level modeling. ProgSCA formulates SCA as a retrieval problem, first employing lightweight methods to quickly filter out irrelevant libraries from numerous candidate TPLs, then using a model trained at the program level to directly predict dependency between programs. Comprehensive evaluations show that ProgSCA achieves state-of-the-art performance in SCA tasks, improving F1 scores over existing methods by 174% and 100% in two mainstream scenarios, respectively. Moreover, ProgSCA maintains a consistent advantage across different datasets and different candidate pool scales, and also proves effective in the downstream task of function similarity matching, further demonstrating the practical value of our approach.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 4501b68a-d133-4b6c-bb01-e4168f1797be

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines