Impressed with the Blackduck offerings to scan and manage OpenSource software, their service, and the response time . Very detailed information on licensing and vulnerability for the open source software . UI and the usability of the tool and its plugins...
Still too many incorrect identifications. There is no support for a workflow to manage mitigations of vulnerabilities in a particular component in one version of a project, then apply those comments and actions to future versions, or to the same component...
Cost-effective for startups. I always put off scanning my open-source libraries because the cost was too high to bear. SOOS takes that off the table.
The pipeline Reports structure must be available to check the Instant results from the developer's end. SOOS frequently changes its policies, and price structure, and puts many conditions.
Impressed with the Blackduck offerings to scan and manage OpenSource software, their service, and the response time . Very detailed information on licensing and vulnerability for the open source software . UI and the usability of the tool and its plugins...
Cost-effective for startups. I always put off scanning my open-source libraries because the cost was too high to bear. SOOS takes that off the table.
Still too many incorrect identifications. There is no support for a workflow to manage mitigations of vulnerabilities in a particular component in one version of a project, then apply those comments and actions to future versions, or to the same component...
The pipeline Reports structure must be available to check the Instant results from the developer's end. SOOS frequently changes its policies, and price structure, and puts many conditions.