Log4Shell Log4j logs

AppSec and Software Community Respond to Log4j

The application security and the open source software communities rose to the challenge of the Java Log4j vulnerability, patching software, sharing information and providing mitigations and tools. We aren’t out of the ...
Security Boulevard
Optimizing software composition analysis for developer workflows with Black Duck Rapid Scan

Optimizing software composition analysis for developer workflows with Black Duck Rapid Scan

Black Duck Rapid Scan enables developers to check for security or policy violations without disrupting development process. The post Optimizing software composition analysis for developer workflows with Black Duck Rapid Scan appeared ...
Get earlier, actionable vulnerability insights from Black Duck Security Advisories

Get earlier, actionable vulnerability insights from Black Duck Security Advisories

Identifying security vulnerabilities is only half the battle. To remediate and prioritize them, you need Black Duck Security Advisories. The post Get earlier, actionable vulnerability insights from Black Duck Security Advisories appeared ...
Discovery capabilities: A core differentiator for Black Duck SCA

Discovery capabilities: A core differentiator for Black Duck SCA

Stay on top of open source vulnerabilities and license obligations with discovery capabilities from Black Duck. The post Discovery capabilities: A core differentiator for Black Duck SCA appeared first on Software Integrity ...
How to manage open source risks using Black Duck SCA

How to manage open source risks using Black Duck SCA

Open source risk goes beyond application security. Legal, operational, and supply chain implications demand a capable solution like Black Duck SCA. The post How to manage open source risks using Black Duck ...
Things to consider when choosing a software composition analysis tool

Things to consider when choosing a software composition analysis tool

The rise of open source software is not without risks for today’s applications. Use a software composition analysis tool to mitigate these risks. The post Things to consider when choosing a software ...
Making SCA part of your AST Strategy

Making SCA part of your AST Strategy

Open source software is now used in nearly every organization, which makes it critical to know your code. Learn how an SCA tool can help you. The post Making SCA part of ...
Black Duck continues to expand vulnerability prioritization methods

Black Duck continues to expand vulnerability prioritization methods

Today’s release of Black Duck adds vulnerability impact analysis, which indicates whether your application executes vulnerable code. Let’s look at how this addition further augments your prioritization efforts. The post Black Duck ...
An introduction to installing Black Duck

An introduction to installing Black Duck

Get started with the Dockerized Black Duck installation. This post outlines workplace specifications, tools, and steps for installing Black Duck. The post An introduction to installing Black Duck appeared first on Software ...
The advanced license compliance functionality you didn’t know your SCA tool needed

The advanced license compliance functionality you didn’t know your SCA tool needed

Open source license noncompliance can have severe implications. Here are four advanced license compliance features that help protect your proprietary code. The post The advanced license compliance functionality you didn’t know your ...