Try our new research platform with insights from 80,000+ expert users

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Black Duck SCA auto analyzes components and highlights developer impacts from an intellectual property perspective.
The vulnerability scanning feature of Black Duck SCA is highly valuable and easy to use.
Black Duck SCA offers a vast knowledge base and effective management system for identifying licensing and potential breach issues.
Black Duck SCA seamlessly integrates with Docker to scan binary files for open vulnerabilities, providing immediate results and updates.
Black Duck SCA excels in software composition analysis for effective security risk management and accurate dependency identification.

CONS

Black Duck SCA lacks integration with IntelliJ IDEA and needs more native integration with Coverity.
It is limited by the size of the software it can handle and the initial setup is complex.
Black Duck SCA is a cloud-only solution, which may require companies to upload code to its cloud system, causing reluctance.
The pricing is higher compared to other competitor products, and the cost is too high given the infrequent use.
The documentation is scattered, and improvements are needed in pricing models and documentation.
 

Black Duck SCA Pros review quotes

TO
Consulting Partner, Cyber Security Delivery - Africa at DeltaGRiC Consulting
May 28, 2019
It highlights what the developers have done, and it shows the impact from an intellectual property point of view.
ZR
Chief Technology Officer (CTO) at FOSSAWARE
Jan 15, 2020
I like the fact that the product auto analyzes components.
SS
Project Lead at a tech vendor with 10,001+ employees
Jun 7, 2020
The stability is okay.
Learn what your peers think about Black Duck SCA. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
879,768 professionals have used our research since 2012.
reviewer1421445 - PeerSpot reviewer
Former SVP at a manufacturing company with 5,001-10,000 employees
Sep 27, 2020
The solution works well on Mac products.
it_user1435263 - PeerSpot reviewer
Lead Product Enginner at Harman International Industries, Incorporated
Dec 7, 2020
The most valuable feature is the vulnerability scanning, and that it's easy to use.
reviewer1472997 - PeerSpot reviewer
CTO at a computer software company with 11-50 employees
Dec 15, 2020
The knowledge base and the management system are the most valuable features of Black Duck Hub. It has a very helpful management environment. They offer an editor where we can check the discovered license, which is retrieved from their knowledge base. They have a huge knowledge base build over the years. It gives you some possibilities, such as this license with possibility A could cause a vulnerability issue or a potential breach.
reviewer1642500 - PeerSpot reviewer
Engineer at a manufacturing company with 10,001+ employees
Aug 6, 2021
The installation is very easy.
JR
Head: Open Source Program Office at a financial services firm with 10,001+ employees
Aug 26, 2021
Black Duck is pretty extensive in terms of the scan reserves and the vulnerability exposures. From that perspective, I'm happy with it.
SS
Project Lead at a tech vendor with 10,001+ employees
May 3, 2022
It is able to drill down to the source level.
Tarun-Sharma - PeerSpot reviewer
Cloud Solution Architect at IBM
Jun 8, 2022
The most valuable feature of Black Duck is the seamless integration to scan our Docker binary files, it provides us all open vulnerabilities, and it ensures a reference point from where it finds the vulnerability is up to date. For example, if there is any new vulnerability found, they are immediately available in the Black Duck. There is no delay in finding the vulnerabilities, they are called out in our code immediately.
 

Black Duck SCA Cons review quotes

TO
Consulting Partner, Cyber Security Delivery - Africa at DeltaGRiC Consulting
May 28, 2019
I would like to see more integration with other solutions, such as IntelliJ IDEA.
ZR
Chief Technology Officer (CTO) at FOSSAWARE
Jan 15, 2020
The scanner client is limited by the size of software it can handle.
SS
Project Lead at a tech vendor with 10,001+ employees
Jun 7, 2020
It needs to be more user-friendly for developers and in general, to ensure compliance.
Learn what your peers think about Black Duck SCA. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
879,768 professionals have used our research since 2012.
reviewer1421445 - PeerSpot reviewer
Former SVP at a manufacturing company with 5,001-10,000 employees
Sep 27, 2020
We're not too sure about the extension of the firewall. It never shows up in the Hub.
it_user1435263 - PeerSpot reviewer
Lead Product Enginner at Harman International Industries, Incorporated
Dec 7, 2020
The initial setup could be simplified. It was somewhat complex.
reviewer1472997 - PeerSpot reviewer
CTO at a computer software company with 11-50 employees
Dec 15, 2020
It is a cloud-only solution. In many cases, companies like to evaluate the software, but they're very reluctant to give you the software. It would be great if they could offer an on-prem component that could be used to scan the code and then upload the discovery results to the cloud and get all the information from there, but there is no such possibility. You have to upload the code to the Black Duck cloud system. Of course, they have a strong legal department, and they offer some configuration, but it is never enough. You have to give the code, which is a drawback. In modern designs like Snyk or FOSSA, you don't need to give the code. It requires more native integration with Coverity because they go together technically. You need both Coverity and Black Duck Hub. It would be really helpful for companies working in this space to get a combined offer from the same company. They should provide an option to buy Coverity for an additional fee. Coverity combined with Black Duck Hub will provide a one-step analysis to get everything you need and a unified report. It would be really great to be able to connect Black Duck Hub with Coverity unified reports.
reviewer1642500 - PeerSpot reviewer
Engineer at a manufacturing company with 10,001+ employees
Aug 6, 2021
Due to the fact that, with our software developer life cycle, we don't need to scan our source code every day or every week. For that reason, we find the cost is too high. We might only actually use it five to ten times a year, which makes it expensive.
JR
Head: Open Source Program Office at a financial services firm with 10,001+ employees
Aug 26, 2021
We have been having some issues with the latest releases where we are not able to scan our applications with the help of Black Duck.
SS
Project Lead at a tech vendor with 10,001+ employees
May 3, 2022
They are giving a lot of APIs and Python scripts for certain functionalities, but instead of using APIs and Python scripts, they should provide these functionalities through the UI. Users should be able to customize and add more fields through the UI. Users should be able to add more fields and generate reports. Currently, they are not giving flexibility in the UI. They're providing a script that simply generates an Excel file or CSV file. There is no flexibility.
Tarun-Sharma - PeerSpot reviewer
Cloud Solution Architect at IBM
Jun 8, 2022
Black Duck can improve the time it takes for a scan. Most of the time it's not ideal when integrated with the live DevSecOps pipeline. We have to create a separate job to scan the library because it takes a couple of hours to scan all those libraries. The scanning could be faster.