🗂️ Navigation

Black Duck by Synopsys

Manage your open source risk.

Visit Website →

Overview

Black Duck by Synopsys is a comprehensive software composition analysis (SCA) solution that helps organizations identify and manage risks associated with open source software. It scans applications and containers to provide a complete inventory of open source components, known vulnerabilities, and license compliance issues.

✨ Key Features

  • Open source discovery
  • Vulnerability detection
  • License compliance management
  • Software Bill of Materials (SBOM)
  • Policy management

🎯 Key Differentiators

  • Large, comprehensive open source knowledge base
  • Multiple scanning methods including binary analysis

Unique Value: Provides unmatched visibility and control over open source risk across the software supply chain.

🎯 Use Cases (3)

Securing applications by managing open source vulnerabilities Ensuring compliance with open source licenses Creating and managing SBOMs

✅ Best For

  • Integrating into CI/CD pipelines for vulnerability scans.
  • Identifying vulnerabilities through source code and binary analysis.

💡 Check With Vendor

Verify these considerations match your specific requirements:

  • Small organizations due to cost.
  • Management of commercial, on-premise software.

🏆 Alternatives

Snyk Mend (WhiteSource) FOSSA

Offers more comprehensive scanning, including binary analysis, which can find risks that source-only scanners might miss.

💻 Platforms

Web API CLI

✅ Offline Mode Available

🔌 Integrations

Jenkins Jira Azure DevOps GitHub Artifactory

🛟 Support Options

  • ✓ Email Support
  • ✓ Phone Support
  • ✓ Dedicated Support (Varies tier)

🔒 Compliance & Security

✓ SOC 2 ✓ GDPR ✓ ISO 27001 ✓ SSO ✓ ISO 27001 ✓ SOC 2

💰 Pricing

Contact for pricing

✓ 14-day free trial

Visit Black Duck by Synopsys Website →