# Why not just SCA? | Chainsaw

> SCA tools report on exposure. Chainsaw is a control point that prevents non-compliant packages from being consumed in the first place.

Source: https://chain305.com/vs-sca/

---

Why not just SCA?

# SCA reports. Chainsaw refuses. Run both.

SCA tells you what's already inside your build. Chainsaw refuses the request on the install path, before bytes land.

[How the install path works →](https://chain305.com/product/how-it-works/)

Decision timing

## Where each tool acts on one install

Chainsaw decides before the package enters a build. SCA reports after it is in use.

1.  01 · Developer or CI
    
    `npm install`

3.  02 · Chainsaw decides
    
    -   CVE, license, version
    -   up to 25 supply-chain signals
    
    on supported ecosystems
    

5.   Refused
    
    never reaches a build
    
     Allowed
    
    in the build. SCA reports on it from here, after install
    

[The attack-pattern signals SCA misses →](https://chain305.com/product/policy/)

Feature matrix

## Reporting vs. install-time control

Capability

SCA tool Snyk · Sonatype · Mend

Chainsaw Install-time policy proxy

Dependency inventory / SBOM

 Yes

 Partial

CVE reporting & alerts

 Yes

 Partial

Refuses a package before it reaches a build

 No

 Yes

License policy at install time Refuse GPL in production, for example.

 Partial

 Yes

Monitor-only mode before enforcing

 No

 Yes

Policy response to a new CVE Stop new installs without waiting on upgrade PRs.

 No

 Yes

Post-install reporting

 Yes

 Partial

Refuses supply-chain attacks beyond CVE Install-script exfiltration, maintainer takeover, worm bursts.

 No

 Yes

Checksum fail-closed on upstream fetch

 No

 Yes

Want to see it in practice?

## Compare your current SCA coverage to install-time control

Start a free org in monitor mode. See what Chainsaw would have refused this week.

[Run alongside your SCA](https://chain305.com/chainsaw/signup) [Compare coverage →](https://chain305.com/product/policy/)

---

## Long form

The full text behind this page, including detail the page itself leaves out.

Why not just SCA?

### SCA reports. Chainsaw refuses. Run both.

SCA tells you what's already inside your build. That's reporting, not control.

Chainsaw sits on the [install path](https://chain305.com/product/how-it-works/) and refuses the request before bytes land — on CVE, license, version, and the [attack-pattern signals SCA misses](https://chain305.com/product/policy/): install-script exfiltration, maintainer takeover, worm bursts, dependency confusion. Run both.

##### Decision timing

SCA tools

After dependencies are already in use.

Chainsaw

Before the package enters a build.

##### What the control point does

SCA tools

Reports on exposure across repos, pipelines, and environments.

Chainsaw

Refuses non-compliant installs on the install path.

##### How teams adopt it

SCA tools

No phased enforcement. Flip from off to alerts only.

Chainsaw

Monitor impact in a safe mode before enforcing. Flip rule by rule.

##### Response to a newly disclosed CVE

SCA tools

Scan runs, ticket filed, developers open PRs to upgrade.

Chainsaw

Policy edit refuses the affected version at install. No code changes needed to stop new spread.

##### Coverage of supply-chain attack patterns

SCA tools

Focused on known CVEs and licenses. Install-script exfiltration, maintainer takeover, and worm bursts typically slip past.

Chainsaw

Up to 25 supply-chain signals beyond CVE on supported ecosystems: install scripts, publisher changes, version anomalies, hidden Unicode, publish velocity, and more.

##### Real-world attacks caught at install

SCA tools

Generally none — these slip past CVE-based feeds: Shai-Hulud, PhantomRaven, GlassWorm, Axios v1.14.1, event-stream, ua-parser-js.

Chainsaw

Each maps to a named signal family on the policy page — publish-velocity bursts, install-script exfiltration, hidden Unicode, maintainer-account takeover.

##### Scope of control

SCA tools

Dependency-level visibility. Governance lives in the ticket queue.

Chainsaw

Policy at the install surface: vulnerabilities, licenses, versions, provenance, and attack signals.

##### Can an install route around the policy?

SCA tools

There's no install-path gate to route around — the scan reports either way.

Chainsaw

The proxy is the gate, and CI, endpoint, and network controls close the ways around it. Enforcement closure, with an audit trail that shows the gap is shut.

Feature matrix

#### Reporting vs. install-time control

Capability

SCA tool Snyk · Sonatype · Mend

Chainsaw Install-time policy proxy

Dependency inventory / SBOM Know what's in your apps.

 Yes

 Partial

CVE reporting & alerts

 Yes

 Partial

Refuses a package before it reaches a build

 No

 Yes

License policy at install time Refuse GPL in production, for example.

 Partial

 Yes

Monitor-only mode before enforcing

 No

 Yes

Policy response to a new CVE Stop new installs without waiting on upgrade PRs.

 No

 Yes

Post-install reporting

 Yes

 Partial

Refuses supply-chain attacks beyond CVE Install-script exfiltration, maintainer takeover, worm bursts, dependency confusion.

 No

 Yes

Checksum fail-closed on upstream fetch

 No

 Yes

Works alongside your existing SCA

—

 Yes

Want to see it in practice?

#### Compare your current SCA coverage to install-time control

Start with a free org. Turn on monitor mode. See what Chainsaw would have refused this week before changing anything.

[Run alongside your SCA](https://chain305.com/chainsaw/signup) [Compare coverage →](https://chain305.com/product/policy/)
