Try our new research platform with insights from 80,000+ expert users

What is Black Duck?

Featured Black Duck reviews

Black Duck mindshare

As of August 2025, the mindshare of Black Duck in the Software Composition Analysis (SCA) category stands at 17.8%, down from 22.5% compared to the previous year, according to calculations based on PeerSpot user engagement data.
Software Composition Analysis (SCA) Market Share Distribution
ProductMarket Share (%)
Black Duck17.8%
Snyk13.7%
JFrog Xray10.3%
Other58.2%
Software Composition Analysis (SCA)

PeerResearch reports based on Black Duck reviews

TypeTitleDate
CategorySoftware Composition Analysis (SCA)Aug 29, 2025Download
ProductReviews, tips, and advice from real usersAug 29, 2025Download
ComparisonBlack Duck vs SnykAug 29, 2025Download
ComparisonBlack Duck vs VeracodeAug 29, 2025Download
ComparisonBlack Duck vs Sonatype LifecycleAug 29, 2025Download
Suggested products
TitleRatingMindshareRecommending
GitLab4.24.1%97%85 interviewsAdd to research
Snyk4.013.7%100%48 interviewsAdd to research
 
 
Key learnings from peers

Valuable Features

Room for Improvement

ROI

Pricing

Popular Use Cases

Service and Support

Deployment

Scalability

Stability

Review data by company size

By reviewers
Company SizeCount
Small Business6
Large Enterprise13
By reviewers
By visitors reading reviews
Company SizeCount
Small Business443
Midsize Enterprise274
Large Enterprise1689
By visitors reading reviews

Top industries

By visitors reading reviews
Financial Services Firm
18%
Manufacturing Company
15%
Computer Software Company
13%
Insurance Company
5%
Healthcare Company
4%
Retailer
4%
Educational Organization
3%
Real Estate/Law Firm
3%
University
3%
Comms Service Provider
3%
Energy/Utilities Company
3%
Government
3%
Media Company
2%
Construction Company
2%
Consumer Goods Company
2%
Transportation Company
2%
Non Profit
2%
Performing Arts
2%
Outsourcing Company
1%
Legal Firm
1%
Recreational Facilities/Services Company
1%
Hospitality Company
1%
Marketing Services Firm
1%
Wholesaler/Distributor
1%
Logistics Company
1%
Pharma/Biotech Company
1%
Aerospace/Defense Firm
1%

Compare Black Duck with alternative products

Learn more about Black Duck

Black Duck customers

Related questions

 
Black Duck Reviews Summary
Author infoRatingReview Summary
IP Head at a tech services company with 10,001+ employees3.5I find Black Duck to be robust and accurate, particularly in identifying dependencies and licenses, but it needs improvement in security vulnerability identification. It's pricier and complex to set up, impacting direct ROI assessment in some cases.
Director at a healthcare company with 10,001+ employees3.0I recommend Black Duck for its ability to identify software components and manage security, operational, and license risks effectively. While it excels in risk management, improvements are needed in addressing false positives, reporting, and container scanning.
Director at a healthcare company with 10,001+ employees4.0I use Black Duck primarily for software composition analysis. Its composition analysis and automated code scanning features are valuable for managing security risks and audit readiness. However, the absence of SBOM management is a notable drawback for me.
DevOps Engineer at a manufacturing company with 1,001-5,000 employees3.5As a DevOps engineer, I integrate Black Duck in our CI/CD pipeline for product vulnerability scans. The UI is valuable for easy integration, but improvements are needed in pricing, documentation, and scalability. Debugging can be challenging without adequate documentation.
Senior Manager at Happiest Minds Technologies3.5We use Black Duck for open-source security management in DevOps and DevSecOps, appreciating its integration capabilities and community resources. It effectively secures 400 to 500 applications, although more open APIs would enhance its functionality further.
Solutions Architect at a tech services company with 10,001+ employees4.0I use Synopsys Black Duck for security-focused project scans, identifying vulnerabilities through source code and binary analysis. It provides precise fixes and dependency insights, but sometimes lacks consistency, particularly in differentiating between direct and transitive vulnerabilities.
Project Manager at a manufacturing company with 11-50 employees4.5I use Black Duck to detect vulnerabilities in open-source software, valuing its effective binary file scanning. However, its reporting capabilities need improvement for clarity and comprehensiveness. Compared to competitors, it's superior in deployment, scalability, and its comprehensive vulnerability database.
Group IT Vendor Management Director at Twoday4.5I use Black Duck to detect non-compliance in third-party applications. Its valuable features include policy and license management at a group level. Despite its power, documentation needs improvement. I evaluated other solutions like FOSSA but chose Black Duck for its customization.