Black Duck Logo

Black Duck

0
Commercial
Visit Website

Black Duck is an application security platform focused on software supply chain security and software composition analysis (SCA). The platform helps organizations identify and manage risks in their software by providing comprehensive Software Bill of Materials (SBOM) management capabilities. Black Duck enables teams to scan applications for open source components, detect vulnerabilities, and ensure license compliance throughout the software development lifecycle. The solution integrates into CI/CD pipelines to automate security testing without impeding development velocity. Key capabilities include: - Software composition analysis to identify open source components and their associated risks - Vulnerability detection and management across the application portfolio - License compliance monitoring to prevent intellectual property issues - SBOM generation and management to meet regulatory requirements - Integration with DevSecOps workflows and CI/CD pipelines - Risk prioritization based on organizational policies The platform is designed to support various roles within an organization, from developers who need to secure code as they write it to security teams who need to manage risk at scale. Black Duck helps organizations address security concerns related to AI-generated code and maintain compliance with industry standards.

FEATURES

ALTERNATIVES

InQL is a Burp Suite extension for advanced GraphQL testing and vulnerability detection

Checkmarx One SAST is a static application security testing tool that combines speed and security to improve developer experience.

Automated web application testing tool

Automated framework for monitoring and tampering system API calls of native macOS, iOS, and Android apps.

OWASP Damn Vulnerable Web Sockets (DVWS) is a vulnerable web application for client-server communication with numerous vulnerabilities.

EvoMaster is an open-source tool that automatically generates system-level test cases for web APIs using AI-driven techniques.

Aikido is an all-in-one security platform that combines multiple security scanning and management functions for cloud-native applications and infrastructure.

Tool to inform about potential risks in project dependencies list.