Black duck software composition analysis works amazing on Mac, It has a good security and excellent features that protects and examines our source code from compliance issues. Review collected by and hosted on G2.com.
Black duck should add features like packet analysis and binary analysis for better performance. Review collected by and hosted on G2.com.
my position within the organization as DevSecOps and developer can be quite complicated without the use of services or tools such as those provided by the whitehat sentinel team, we have used it for more than 4 years and the development support is always elementary, the The issue of security is something serious and it is something that must be studied permanently, they help you to have what you need Review collected by and hosted on G2.com.
This is very complex since for the niche that they offer service, in my opinion, if they meet the expectations, so I could say that I do not find a specific point to suggest any improvement at the moment. Review collected by and hosted on G2.com.
Security Experts analyse potential vulnerabilities.
Minimal false positives.
Alerts for newly discovered vulnerabilities.tracking all records previous as well as present. Review collected by and hosted on G2.com.
The vendor provides scanning, identification, engineering support and risked based reporting of security vulnerabilities. It is little bit slow other wise it is very good. Review collected by and hosted on G2.com.
One of the top solution providers to help manage security vulnerabilities, code quality, code smells, bugs and compliance risk associated with third-party open source code in an effective way. It supports wide range of languages some of which include Java, Cobol, Javascript, C#, C and C++. This software is the benchmark solution to elevate the continuous inspection element in CI/CD model Review collected by and hosted on G2.com.
The cost is relatively higher than the other solutions in the market which makes it a difficult choice for organisations Review collected by and hosted on G2.com.
It has impressive features for both legal & security 3rd party software compliance. UI is easy to understand. It helps us to analyze the code in a timely and accurate manner. Review collected by and hosted on G2.com.
According to me it has all the features required. It is fast and easy to use. Review collected by and hosted on G2.com.
Blackduck is part of Devonshire which provides us automatic scanning. Black duck is not just for devops but also Secops. Blackduck has the most extensive open source KB in the industry Review collected by and hosted on G2.com.
I am expecting better governance of teams. I have various teams using the capacity and I need to know which team is using how much. Black duck can come up with tenancy. Review collected by and hosted on G2.com.
Black duck is certainly an industry leader in open source scanning primarily due to the fact that it is simpler to use and hence eliminate majority open source vulnerabilities and bugs and licensing issues. Should there be any enhancement request Blackduck is fairly adaptive and responsive towards implementing the same. Review collected by and hosted on G2.com.
The reporting could be enhanced as it does not provide the output the way one would expect it to be owing to which, it adds additional overhead to present the result in a better way Review collected by and hosted on G2.com.
Quick inventory scan, Security and License risk management, integration for automatic scanning. Review collected by and hosted on G2.com.
It is slow, outdated design and is to expensive. Review collected by and hosted on G2.com.
Black duck serves as a good platform to identify third party software risk factors. It can be easily integrated as of part of CI/CD tools to scan security, license risk etc. It shows the exact break up of all the risky components of the binaries. Review collected by and hosted on G2.com.
It's very strict in compliance check so during upgradation of third party software it is diffcult to ignore some of the risks. But that shows how efficient Black duck software is. Also, using open source software creates license risks. Review collected by and hosted on G2.com.
Custom policies, IDE integration during the development life cycle.Jira tickets are being created for the issues Review collected by and hosted on G2.com.
Dont have any suggestion here which i have not liked so far. Review collected by and hosted on G2.com.