Organizations use Black Duck for compliance, internal audits, license management, and security, scanning software to identify vulnerabilities, non-compliant code, and dependencies in open-source projects.
Product | Market Share (%) |
---|---|
Black Duck | 17.8% |
Snyk | 13.7% |
JFrog Xray | 10.3% |
Other | 58.2% |
Type | Title | Date | |
---|---|---|---|
Category | Software Composition Analysis (SCA) | Aug 29, 2025 | Download |
Product | Reviews, tips, and advice from real users | Aug 29, 2025 | Download |
Comparison | Black Duck vs Snyk | Aug 29, 2025 | Download |
Comparison | Black Duck vs Veracode | Aug 29, 2025 | Download |
Comparison | Black Duck vs Sonatype Lifecycle | Aug 29, 2025 | Download |
Title | Rating | Mindshare | Recommending | |
---|---|---|---|---|
GitLab | 4.2 | 4.1% | 97% | 85 interviewsAdd to research |
Snyk | 4.0 | 13.7% | 100% | 48 interviewsAdd to research |
Black Duck is primarily used for software composition analysis, identifying software components and assessing security and compliance risks. Organizations use it for vulnerability assessment and license compliance in development. It helps with open-source security management, ensures compliance in DevSecOps pipelines, and facilitates audits during the M&A process. Users focus on examining code for compliance, scanning for vulnerabilities, and detecting non-compliance in third-party applications, enhancing software visibility and security management.
Company Size | Count |
---|---|
Small Business | 6 |
Large Enterprise | 13 |
Company Size | Count |
---|---|
Small Business | 443 |
Midsize Enterprise | 274 |
Large Enterprise | 1689 |
Black Duck integrates into CI/CD pipelines and DevSecOps processes, helping multiple industries detect and handle risks associated with open-source usage. Users leverage it for source and binary analysis to ensure security and compliance before software release. Automatic component analysis, effective vulnerability scanning, and a comprehensive knowledge base are some of its valuable features. Despite needing improvements in scanning speed, UI, and documentation, Black Duck remains crucial for ensuring open-source security and compliance.
What are Black Duck's most important features?
What benefits or ROI should users look for in reviews?
Black Duck is implemented by industries ranging from finance to healthcare, addressing security and compliance in open-source usage. Financial institutions employ it to manage license risks and ensure audit readiness. Healthcare organizations use it to comply with stringent data protection regulations, ensuring patient data security and privacy. Tech companies integrate Black Duck within CI/CD pipelines to maintain the security and compliance of software products before release. Its deployment varies, tailored to meet the specific risk management and compliance needs dictated by each sector's regulatory environment.
Black Duck was previously known as Blackduck Hub, Black Duck Protex, Black Duck Security Checker.
Samsung, Siemens, ScienceLogic, BryterCX, Dynatrace
Author info | Rating | Review Summary |
---|---|---|
IP Head at a tech services company with 10,001+ employees | 3.5 | I find Black Duck to be robust and accurate, particularly in identifying dependencies and licenses, but it needs improvement in security vulnerability identification. It's pricier and complex to set up, impacting direct ROI assessment in some cases. |
Director at a healthcare company with 10,001+ employees | 3.0 | I recommend Black Duck for its ability to identify software components and manage security, operational, and license risks effectively. While it excels in risk management, improvements are needed in addressing false positives, reporting, and container scanning. |
Director at a healthcare company with 10,001+ employees | 4.0 | I use Black Duck primarily for software composition analysis. Its composition analysis and automated code scanning features are valuable for managing security risks and audit readiness. However, the absence of SBOM management is a notable drawback for me. |
DevOps Engineer at a manufacturing company with 1,001-5,000 employees | 3.5 | As a DevOps engineer, I integrate Black Duck in our CI/CD pipeline for product vulnerability scans. The UI is valuable for easy integration, but improvements are needed in pricing, documentation, and scalability. Debugging can be challenging without adequate documentation. |
Senior Manager at Happiest Minds Technologies | 3.5 | We use Black Duck for open-source security management in DevOps and DevSecOps, appreciating its integration capabilities and community resources. It effectively secures 400 to 500 applications, although more open APIs would enhance its functionality further. |
Solutions Architect at a tech services company with 10,001+ employees | 4.0 | I use Synopsys Black Duck for security-focused project scans, identifying vulnerabilities through source code and binary analysis. It provides precise fixes and dependency insights, but sometimes lacks consistency, particularly in differentiating between direct and transitive vulnerabilities. |
Project Manager at a manufacturing company with 11-50 employees | 4.5 | I use Black Duck to detect vulnerabilities in open-source software, valuing its effective binary file scanning. However, its reporting capabilities need improvement for clarity and comprehensiveness. Compared to competitors, it's superior in deployment, scalability, and its comprehensive vulnerability database. |
Group IT Vendor Management Director at Twoday | 4.5 | I use Black Duck to detect non-compliance in third-party applications. Its valuable features include policy and license management at a group level. Despite its power, documentation needs improvement. I evaluated other solutions like FOSSA but chose Black Duck for its customization. |