Black Duck Software Composition Analysis (SCA) Brochure
Black Duck is a comprehensive solution for managing security, license compliance, and code quality risks. It specifically addresses risks from the use of open source in applications, containers, and other software artifacts or libraries. Moreover, Forrester has named Black Duck a leader in software composition analysis (SCA), recognising its unmatched visibility into third-party dependencies. This visibility, in turn, enables organisations to manage risks introduced by their software supply chain effectively.
Most commercial application code originates from third parties, written by entities outside the control or visibility of the distributing company. Black Duck offers a combination of dependency discovery techniques to provide teams with complete visibility into application composition. These techniques include dependency analysis, binary analysis, snippet analysis, CodePrint analysis, container scanning, and C/C++ scanning. By utilising these methods, teams can effectively assess and manage risks associated with open-source components.
Additionally, Black Duck conducts evaluations for any associated risks for every identified dependency. It then guides prioritisation and remediation efforts, ensuring that the most critical vulnerabilities are addressed first. Furthermore, Black Duck Security Advisories (BDSAs), powered by the Black Duck KnowledgeBase, provide timely and actionable alerts on existing and newly disclosed open-source vulnerabilities. Black Duck also surfaces the exact licenses used by application dependencies, thus helping organisations comply with licensing requirements and avoid potential legal issues.
To enable teams to be more proactive in preventing security risks, Black Duck provides metrics that can be used to evaluate the health, history, community support, origin, and reputation of an open-source project. This comprehensive evaluation helps organisations make informed decisions about which open-source components to use. Additionally, Black Duck performs post-build analysis of software artifacts to detect the presence of malware, including suspicious files, potentially unwanted applications, protestware, and suspicious file structures. Teams have the capability to export SBOMs, facilitating better management and tracking of open-source components.
Download the Black Duck brochure here



