Blackduck is part of Devonshire which provides us automatic scanning. Black duck is not just for devops but also Secops. Blackduck has the most extensive open source KB in the industry
Missed key open source licensing issues and locked us into a 2-year contract. Expensive with no benefit since we ended up needing to check all the open source code we had personally. If we hadn't we could have faced significant licensing issues. Not a...
Easy and straightforward to use. From the easy plugins, to the excellent dashboard, the feature set helps us every day without taking a lot of time. This is very important as we could need to change our code at any time.
Seems to over-include packages, creating false positives for things that aren't in our BOM. Need to understand how to configure the system to get a more accurate result. Also, would like a CSV export of vulnerability data to make it possible to create...
Blackduck is part of Devonshire which provides us automatic scanning. Black duck is not just for devops but also Secops. Blackduck has the most extensive open source KB in the industry
Easy and straightforward to use. From the easy plugins, to the excellent dashboard, the feature set helps us every day without taking a lot of time. This is very important as we could need to change our code at any time.
Missed key open source licensing issues and locked us into a 2-year contract. Expensive with no benefit since we ended up needing to check all the open source code we had personally. If we hadn't we could have faced significant licensing issues. Not a...
Seems to over-include packages, creating false positives for things that aren't in our BOM. Need to understand how to configure the system to get a more accurate result. Also, would like a CSV export of vulnerability data to make it possible to create...