Black Duck is an application security platform focused on software supply chain security and software composition analysis (SCA). The platform helps organizations identify and manage risks in their software by providing comprehensive Software Bill of Materials (SBOM) management capabilities. Black Duck enables teams to scan applications for open source components, detect vulnerabilities, and ensure license compliance throughout the software development lifecycle. The solution integrates into CI/CD pipelines to automate security testing without impeding development velocity. Key capabilities include: - Software composition analysis to identify open source components and their associated risks - Vulnerability detection and management across the application portfolio - License compliance monitoring to prevent intellectual property issues - SBOM generation and management to meet regulatory requirements - Integration with DevSecOps workflows and CI/CD pipelines - Risk prioritization based on organizational policies The platform is designed to support various roles within an organization, from developers who need to secure code as they write it to security teams who need to manage risk at scale. Black Duck helps organizations address security concerns related to AI-generated code and maintain compliance with industry standards.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Application monitoring and security platform that provides runtime visibility, threat detection, and automated response capabilities for application-layer security
Dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers.
A learning and training project demonstrating common configuration errors in cloud environments.
StaCoAn is a cross-platform tool for static code analysis on mobile applications, emphasizing the identification of security vulnerabilities.
A free online tool to scan for DOM-based XSS vulnerabilities in HTML, JavaScript, and CSS files.
A tool that uses Apache mod_rewrite to redirect invalid URIs to a specified URL
An IDE-integrated AI security solution that detects, remediates, and educates about code vulnerabilities in real-time as developers write code.
An API security solution that provides continuous discovery, classification, and protection of APIs across environments while integrating with existing security infrastructure to prevent attacks and business logic abuse.
ZeroThreat is a cloud-based DAST platform that provides automated penetration testing and vulnerability detection for web applications and APIs with AI-driven remediation guidance.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.