Coana is a company developing security for open-source software applications. It offers software composition analysis tools that filter out irrelevant alerts. They identify direct and indirect dependency vulnerabilities, pinpoint exact locations in the code affected by reachable vulnerabilities, and identify package updates to remove vulnerabilities.