There are many tools that map dependencies, licenses and vulnerabilities. Examples include scanners in development platforms, package managers and specialized compliance tools.
The tool is just a tool. The organization still has to make choices and arrange follow-up.