Save to My Lists
Claimed
Claimed

Black Duck Reviews & Product Details

Neri Rafael C.
NC
Developer TI
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
Business partner of the seller or seller's competitor, not included in G2 scores.
What do you like best about Black Duck?

my position within the organization as DevSecOps and developer can be quite complicated without the use of services or tools such as those provided by the whitehat sentinel team, we have used it for more than 4 years and the development support is always elementary, the The issue of security is something serious and it is something that must be studied permanently, they help you to have what you need Review collected by and hosted on G2.com.

What do you dislike about Black Duck?

This is very complex since for the niche that they offer service, in my opinion, if they meet the expectations, so I could say that I do not find a specific point to suggest any improvement at the moment. Review collected by and hosted on G2.com.

What problems is Black Duck solving and how is that benefiting you?

security at all times is very important in each application development that involves data from clients and administrative personnel, this is something that must always be taken into account and this team does everything to shield our people. Review collected by and hosted on G2.com.

Black Duck Overview

What is Black Duck?

Organizations worldwide use Black Duck’s industry-leading products to secure and manage open source software, eliminating the pain related to security vulnerabilities, compliance and operational risk. Black Duck is headquartered in Burlington, MA, and has offices in San Jose, CA, Vancouver, London, Frankfurt, Hong Kong, Tokyo, Seoul and Beijing. For more information, visit www.blackducksoftware.com

Black Duck Details
Languages Supported
German, English, Finnish, French, Irish, Hindi, Japanese, Korean, Dutch, Norwegian, Swedish, Chinese (Simplified)
Show LessShow More
Product Description

Black Duck by Synopsys provides a comprehensive software composition analysis (SCA) solution for managing security, quality, and license compliance risk that comes from the use of open source and third-party code in applications and containers. Black Duck gives you unmatched visibility into third-party code, enabling you to control it across your software supply chain and throughout the application life cycle.

How do you position yourself against your competitors?

Black Duck’s KnowledgeBase™ is the world’s most complete, current and accurate repository and database of open source software, associated licenses and other critical information, including known security vulnerabilities. It contains open source code from thousands of internet sites, from general-purpose repositories (e.g., github.com, SourceForge.net, Savannah.gnu.org) to vertically and functionally-oriented repositories (e.g., Java.net, bioperl.org, horde.org), to single-project sites (e.g., Asterisk.org). Combined with a sophisticated matching algorithm, this comprehensive coverage of open source enables the industry’s most precise and thorough code scans, identifications and analysis.


Seller Details
Seller
Synopsys
Year Founded
1986
HQ Location
Mountain View, CA
Twitter
@synopsys
22,911 Twitter followers
LinkedIn® Page
www.linkedin.com
19,499 employees on LinkedIn®
Ownership
NASDAQ:SNPS
Total Revenue (USD mm)
$3,685
Description

Synopsys helps customers innovate from Silicon to Software, so they can deliver Smart, Secure Everything


JE
Overview Provided by:

Recent Black Duck Reviews

OR
omkar r.Mid-Market (51-1000 emp.)
4.5 out of 5
"Whitehat sentinel"
Security Experts analyse potential vulnerabilities. Minimal false positives. Alerts for newly discovered vulnerabilities.tracking all records pre...
Neri Rafael C.
NC
Neri Rafael C.Small-Business (50 or fewer emp.)
5.0 out of 5
"good service and excellent support"
my position within the organization as DevSecOps and developer can be quite complicated without the use of services or tools such as those provided...
Pratik H.
PH
Pratik H.Mid-Market (51-1000 emp.)
4.0 out of 5
"Legal and Operational risks management tool."
It has impressive features for both legal & security 3rd party software compliance. UI is easy to understand. It helps us to analyze the code in a ...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
1 person requested security information

Black Duck Media

Black Duck Demo - Screen+Shot+2017-03-03+at+11.27.57+AM.png
Screen+Shot+2017-03-03+at+11.27.57+AM.png
Black Duck Demo - Screen+Shot+2017-03-03+at+11.26.59+AM.png
Screen+Shot+2017-03-03+at+11.26.59+AM.png
Black Duck Demo - Screen+Shot+2017-03-07+at+3.50.54+PM.png
Screen+Shot+2017-03-07+at+3.50.54+PM.png
Black Duck Demo - Screen+Shot+2017-03-07+at+3.57.26+PM.png
Screen+Shot+2017-03-07+at+3.57.26+PM.png
Answer a few questions to help the Black Duck community
Have you used Black Duck before?
Yes

25 out of 26 Total Reviews for Black Duck

4.0 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
25 out of 26 Total Reviews for Black Duck
4.0 out of 5
25 out of 26 Total Reviews for Black Duck
4.0 out of 5

Overall Review Sentiment for Black DuckQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
OR
Consultant
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Black Duck?

Security Experts analyse potential vulnerabilities.

Minimal false positives.

Alerts for newly discovered vulnerabilities.tracking all records previous as well as present. Review collected by and hosted on G2.com.

What do you dislike about Black Duck?

The vendor provides scanning, identification, engineering support and risked based reporting of security vulnerabilities. It is little bit slow other wise it is very good. Review collected by and hosted on G2.com.

What problems is Black Duck solving and how is that benefiting you?

The vendor provides scanning, identification, engineering support and risked based reporting of security vulnerabilities.it support to better quality of software. Review collected by and hosted on G2.com.

Shreyans M.
SM
Scrum Master
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Black Duck?

One of the top solution providers to help manage security vulnerabilities, code quality, code smells, bugs and compliance risk associated with third-party open source code in an effective way. It supports wide range of languages some of which include Java, Cobol, Javascript, C#, C and C++. This software is the benchmark solution to elevate the continuous inspection element in CI/CD model Review collected by and hosted on G2.com.

What do you dislike about Black Duck?

The cost is relatively higher than the other solutions in the market which makes it a difficult choice for organisations Review collected by and hosted on G2.com.

What problems is Black Duck solving and how is that benefiting you?

Having used this software for a few years I have been able to cut down on a substantial amount of rework by detecting and analysing vulnerabilities before leveraging any open source code. With the timely upgradation of this software it becomes easy to stay updated in terms of the handling newer type of vulnerabilities introduced in the market Review collected by and hosted on G2.com.

Pratik H.
PH
IT Project Coordinator
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
(Original )Information
What do you like best about Black Duck?

It has impressive features for both legal & security 3rd party software compliance. UI is easy to understand. It helps us to analyze the code in a timely and accurate manner. Review collected by and hosted on G2.com.

What do you dislike about Black Duck?

According to me it has all the features required. It is fast and easy to use. Review collected by and hosted on G2.com.

What problems is Black Duck solving and how is that benefiting you?

The support team is always available to resolve the problem if any. Rest it helps us to know what's in your code and analyze your code in a timely and accurate manner. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
II
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Black Duck?

Blackduck is part of Devonshire which provides us automatic scanning. Black duck is not just for devops but also Secops. Blackduck has the most extensive open source KB in the industry Review collected by and hosted on G2.com.

What do you dislike about Black Duck?

I am expecting better governance of teams. I have various teams using the capacity and I need to know which team is using how much. Black duck can come up with tenancy. Review collected by and hosted on G2.com.

Recommendations to others considering Black Duck:

Well suited:. Easily come out of pain to manage open source components. No worries, Black duck is to the rescue, it takes care of your pen source components in terms of license and security. Also SecOps eases with the super Black duck

Less suited: can't really come up with a scenario, where it can be less suited. Until you stop using open source components in your code, quite impossible Review collected by and hosted on G2.com.

What problems is Black Duck solving and how is that benefiting you?

Black duck being rich in its knowledge base about the vulnerabilities and license issues of open source components, quickly compares the identified inventory to the Black duck knowledge base and lists all the vulnerabilities and license issues in the code Review collected by and hosted on G2.com.

SAILEE J.
SJ
Scrum Master [Associate]
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Black Duck?

Black duck is certainly an industry leader in open source scanning primarily due to the fact that it is simpler to use and hence eliminate majority open source vulnerabilities and bugs and licensing issues. Should there be any enhancement request Blackduck is fairly adaptive and responsive towards implementing the same. Review collected by and hosted on G2.com.

What do you dislike about Black Duck?

The reporting could be enhanced as it does not provide the output the way one would expect it to be owing to which, it adds additional overhead to present the result in a better way Review collected by and hosted on G2.com.

What problems is Black Duck solving and how is that benefiting you?

It is very quick and responsive I remember including us small sized code from a random source and Blackduck immediately identified it Review collected by and hosted on G2.com.

Ali s.
AS
Customer Service Representative
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Black Duck?

Black duck software composition analysis works amazing on Mac, It has a good security and excellent features that protects and examines our source code from compliance issues. Review collected by and hosted on G2.com.

What do you dislike about Black Duck?

Black duck should add features like packet analysis and binary analysis for better performance. Review collected by and hosted on G2.com.

What problems is Black Duck solving and how is that benefiting you?

We use black duck to audit our source code to protect from liscence and open source compliance. It is easy to use, stable, and well recognized in the industry. Review collected by and hosted on G2.com.

Shayna  A.
SA
Academic Specialist
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Black Duck?

Quick inventory scan, Security and License risk management, integration for automatic scanning. Review collected by and hosted on G2.com.

What do you dislike about Black Duck?

It is slow, outdated design and is to expensive. Review collected by and hosted on G2.com.

What problems is Black Duck solving and how is that benefiting you?

Black Duck being well established about the vulnerabilities and license issues of open source components, quickly compares the identified inventory to the Black Duck knowledge base and lists all the vulnerabilities and license issues in the code. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Black Duck?

Black duck serves as a good platform to identify third party software risk factors. It can be easily integrated as of part of CI/CD tools to scan security, license risk etc. It shows the exact break up of all the risky components of the binaries. Review collected by and hosted on G2.com.

What do you dislike about Black Duck?

It's very strict in compliance check so during upgradation of third party software it is diffcult to ignore some of the risks. But that shows how efficient Black duck software is. Also, using open source software creates license risks. Review collected by and hosted on G2.com.

What problems is Black Duck solving and how is that benefiting you?

Using Black duck for binary scans as a part of DevOps activity to ensure the security and operation risk complaince that has helped to manage the risks and triage vulnerabilies in the softwares. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
UC
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Black Duck?

Custom policies, IDE integration during the development life cycle.Jira tickets are being created for the issues Review collected by and hosted on G2.com.

What do you dislike about Black Duck?

Dont have any suggestion here which i have not liked so far. Review collected by and hosted on G2.com.

Recommendations to others considering Black Duck:

It was part of the ci/Cd pipeline to detect and create the jirra issues for corresponding vulnerabilities Review collected by and hosted on G2.com.

What problems is Black Duck solving and how is that benefiting you?

It was part of the ci/Cd pipeline to detect and create the Jira issues for corresponding vulnerabilities Review collected by and hosted on G2.com.

Verified User in Utilities
AU
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about Black Duck?

The report is crisp and easy for deciding actionable Review collected by and hosted on G2.com.

What do you dislike about Black Duck?

documentation could be better for implementation Review collected by and hosted on G2.com.

What problems is Black Duck solving and how is that benefiting you?

Able to find out the vulnerabilities and keep my systems secure & compliant Review collected by and hosted on G2.com.