About this project
Developed and maintained by Microsoft, Component Detection (often shortened to CD) is a purpose-built package scanning tool designed to run during project build processes. Its core function is to map all open-source components used in a given codebase, producing structured, graph-based output of detected dependencies for use in software supply chain visibility and dependency management workflows. The tool supports two primary integration modes: as a standalone command-line utility for direct, ad-hoc scanning, and as an embeddable library that developers can integrate into their own applications to add native dependency detection capabilities.
Component Detection supports scanning across a broad range of package managers, language ecosystems, and platform artifacts, with varying levels of dependency graph creation support for each target. Supported scan targets include CocoaPods, Conan, Conda (Python), Docker Compose files, Dockerfiles, .NET SDK binary logs, Go modules (with full graph support for Go 1.11 and later), Gradle lockfiles, Helm charts, Ivy manifests, Linux distribution packages (Debian, Alpine, RHEL, CentOS, Fedora, Ubuntu, with scanning powered by the Syft tool), Maven projects, NPM projects (including Yarn and Pnpm workflows), NuGet packages (including Paket), Pip (Python) projects, Poetry (Python) lockfiles, Ruby gems, Rust Cargo projects, existing SPDX SBOM files, Swift packages, Uv (Python) projects, and Vcpkg manifests. Each individual detector has documented stability status (stable, experimental, or disabled by default) available in the project's public detector documentation.
For users running the tool from source, the project requires Git and the .NET 8 SDK installed on the local machine. After cloning the repository, the tool can be executed via the dotnet CLI with a scan command pointing to the target directory to analyze. Precompiled, ready-to-run binaries for Windows, macOS, and Linux are available for download from the project's official GitHub releases page, so end users do not need to build the tool from source for regular scanning use.
The project is designed to simplify contributor onboarding, supporting cloud-based development via GitHub Codespaces, and containerized development via VS Code DevContainers to eliminate local environment setup friction. Maintainers host monthly public community meetings open to all users, where recent project changes, upcoming roadmap items, open issues, and user feedback are discussed. Meeting archives and ongoing project conversations are hosted in the repository's issue tracker and Discussions tab.
By default, the tool writes telemetry data as a local JSON file to the user-configured output path, with no user data transmitted to Microsoft servers. The project operates under the Microsoft Open Source Code of Conduct, with clear guidelines for community participation.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.