Black Duck Primary Use Case

Saravanan_Radhakrishnan - PeerSpot reviewer
Senior Manager at Happiest Minds Technologies

We use the solution for open-source security management. The product connects the entire customer entity into DevOps and DevSecOps. Solutions like Black Duck and Code Dx enable application testing and onboarding of different applications from entities for security. All the users in different entities have access to the product. They run it by themselves and come to us with their findings. Our security team helps them take action.

View full review »
Aaron  P - PeerSpot reviewer
DevOps Engineer at a manufacturing company with 1,001-5,000 employees

As a DevOps engineer, I am supposed to integrate Black Duck in my CI/CD integration and deployment pipeline. The product teams in my company do a vulnerability scan of our products before we make them available in the market. From the product team's perspective, they check the vulnerability according to the scanning process done from pipelines. My company has a YAML script with which we add the stage, and from there, it gets integrated.

View full review »
Alina-Eugenia Negulescu - PeerSpot reviewer
Group IT Vendor Management Director at Twoday

We use the solution to detect non-compliance in third-party applications.

View full review »
Buyer's Guide
Black Duck
April 2024
Learn what your peers think about Black Duck. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.
ZR
Senior Quality Manager at a financial services firm with 11-50 employees

Our company uses the solution to check open source software that is embedded in our products. 

View full review »
Tarun-Sharma - PeerSpot reviewer
Cloud Solution Architect at IBM

We use Black Duck mainly for the DevSecOps pipeline. For the microservices-based application, we have to deploy Black Duck into the Kubernetes environment. 

I have worked for multiple clients across the world, such as the US and Europe in the banking, retail, and energy sectors.

View full review »
SK
Project Lead at a manufacturing company with 10,001+ employees

We use Black Duck to examine our source code for compliance issues.

View full review »
TO
Consulting Partner, Cyber Security Delivery - Africa at DeltaGRiC Consulting

We have been using this solution for between two and three years.

We frequently use this solution for software composition analysis. We also use it for vulnerability assessment and operational risk assessment. This is usually for customers who want to do one-off assessments, trying to check open source components they are using in their build. 

View full review »
JR
Head: Open Source Program Office at a financial services firm with 10,001+ employees

I am not working with Black Duck. I manage a team that works with Black Duck.

View full review »
CV
CTO at a computer software company with 11-50 employees

We use Black Duck Hub to discover commercial and open-source licenses and the licensed software used by a company. Whenever a company enters the M&A process, a preliminary step called due diligence is done. A part of it is the technical discovery that includes finding out what software the company is using and whether the software is linked with any open-source software or commercial product for which you have to pay a license.

Our main use case is to discover the license and find out if there is an obligation for the paid license. We also check the exposure of the software to open-source libraries. Open source is great, and it is a preferred solution for many companies. Around 90% of the software is now open source, but it is also exposed to vulnerabilities. So, through the dependencies that we were discovering, we were also working on the security exposure of the software product. For this purpose, we use Black Duck Hub.

View full review »
ZR
Chief Technology Officer (CTO) at FOSSAWARE

I'm a technology leader and an open source compliant and risk expert. I lead two domains, both are open source compliant. We use Black Duck in order to make internal audits on software during development, for license compliance, open source compliance, and open source vulnerability. We have an open source audit team, which has some administration rights on the tool and can make changes to the reports based on feedback from business units. Remaining users have permission via tokens to view reports. We would have around 300 users. Up to 20 users can access the system at any one time. The product is used on a daily basis. 

View full review »
VM
Senior Technical Architect at IGT Solutions

We use the solution to scan Java code. 

View full review »
SK
Former SVP at a manufacturing company with 5,001-10,000 employees

We're primarily using the solution for compliance. It's part of an audit process.

View full review »
RS
Lead Product Enginner at Harman International Industries, Incorporated

We are using this solution for software analysis and vulnerability scanning.

View full review »
Buyer's Guide
Black Duck
April 2024
Learn what your peers think about Black Duck. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
767,847 professionals have used our research since 2012.