Scanning open source libraries and third-party code for security vulnerabilities To scan open source libraries and third-party code for security vulnerabilities, follow the steps in these topics. Configure an open source scan in AppScan on Cloud Configuring a scan using AppScan Go! Generating an IRX file using the command line interface (CLI) Generating an IRX file using a plugin or IDE Generating an IRX file using a Software Bill of Materials (SBOM) report