---
title: Software Composition Analysis (SCA) Configuration
description: >-
  Reference documentation for Datadog Software Composition Analysis (SCA)
  configuration, including path, ecosystem, and package exclusion.
breadcrumbs: >-
  Docs > Datadog Security > Code Security > Software Composition Analysis >
  Software Composition Analysis (SCA) Configuration
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Software Composition Analysis (SCA) Configuration

{% callout %}
# Important note for users on the following Datadog sites: app.ddog-gov.com, us2.ddog-gov.com

{% alert level="danger" %}
This product is not supported for your selected [Datadog site](https://docs.datadoghq.com/getting_started/site.md). ({% placeholder "user-datadog-site-name" /%}).
{% /alert %}

{% /callout %}

Datadog Software Composition Analysis (SCA) detects open source libraries and their vulnerabilities in your code. You can exclude specific paths, ecosystems, or packages from Static SCA analysis. Configure these settings under the `sca` key in the Code Security configuration, either in Datadog or in a `code-security.datadog.yaml` file.

The `sca` key was introduced in `schema-version: v1.1` and supports the following fields. Each field has its own minimum `schema-version`, so use the highest version required by the fields you configure:

| **Property**        | **Type** | **Description**                                                                                                                             | **Default** | **Minimum `schema-version`** |
| ------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------- | ----------- | ---------------------------- |
| `ignore-paths`      | Array    | File paths or glob patterns to exclude from Static SCA analysis.                                                                            | None        | `v1.1`                       |
| `ignore-ecosystems` | Array    | Ecosystems, such as `npm`, `Go`, `PyPI`, to exclude from Static SCA analysis.                                                               | None        | `v1.7`                       |
| `ignore-packages`   | Array    | Packages to exclude from Static SCA analysis, regardless of version. Each entry uses the `<ecosystem>:<name>` format, such as `npm:lodash`. | None        | `v1.7`                       |

Example:

```yaml
schema-version: v1.7
sca:
  ignore-paths:
    - "vendor/"
    - "**/node_modules/**"
    - "third_party/"
  ignore-ecosystems:
    - "npm"
  ignore-packages:
    - "Go:golang.org/x/text"
```

{% alert level="warning" %}
Ecosystem and package names in `ignore-ecosystems` and `ignore-packages` are matched case-sensitively. For example, `go:golang.org/x/text` does not match the `Go` ecosystem, and `npm:Lodash` does not match the `lodash` package.
{% /alert %}

If you run the SCA scanner directly from the CLI, the equivalent `--exclude`, `--exclude-ecosystem`, and `--exclude-package` flags are unioned with the exclusions configured above.

For more information on configuration locations, precedence, and merging, see [Code Security Configuration Reference](https://docs.datadoghq.com/security/code_security/guides/configuration.md).

## Further Reading{% #further-reading %}

Additional helpful documentation, links, and articles:

- [Software Composition Analysis](https://docs.datadoghq.com/security/code_security/software_composition_analysis.md)
- [Code Security Configuration Reference](https://docs.datadoghq.com/security/code_security/guides/configuration.md)
