Software Composition Analysis (SCA)

Get earlier, actionable vulnerability insights from Black Duck Security Advisories
Identifying security vulnerabilities is only half the battle. To remediate and prioritize them, you need Black Duck Security Advisories. The post Get earlier, actionable vulnerability insights from Black Duck Security Advisories appeared ...

Discovery capabilities: A core differentiator for Black Duck SCA
Stay on top of open source vulnerabilities and license obligations with discovery capabilities from Black Duck. The post Discovery capabilities: A core differentiator for Black Duck SCA appeared first on Software Integrity ...

How to manage open source risks using Black Duck SCA
Open source risk goes beyond application security. Legal, operational, and supply chain implications demand a capable solution like Black Duck SCA. The post How to manage open source risks using Black Duck ...

Things to consider when choosing a software composition analysis tool
The rise of open source software is not without risks for today’s applications. Use a software composition analysis tool to mitigate these risks. The post Things to consider when choosing a software ...

Making SCA part of your AST Strategy
Open source software is now used in nearly every organization, which makes it critical to know your code. Learn how an SCA tool can help you. The post Making SCA part of ...

Black Duck continues to expand vulnerability prioritization methods
Today’s release of Black Duck adds vulnerability impact analysis, which indicates whether your application executes vulnerable code. Let’s look at how this addition further augments your prioritization efforts. The post Black Duck ...

An introduction to installing Black Duck
Get started with the Dockerized Black Duck installation. This post outlines workplace specifications, tools, and steps for installing Black Duck. The post An introduction to installing Black Duck appeared first on Software ...

The advanced license compliance functionality you didn’t know your SCA tool needed
Open source license noncompliance can have severe implications. Here are four advanced license compliance features that help protect your proprietary code. The post The advanced license compliance functionality you didn’t know your ...

Why developers need a supplemental source to NVD vulnerability data
The NVD is a good source for open source vulnerability data. But with an average 27-day reporting delay, it shouldn’t be your only source of information. The post Why developers need a ...
![[Webinars] Vulnerability reports, application security for DevOps and CI/CD](https://2kjpox12cnap3zv36440iue7-wpengine.netdna-ssl.com/wp-content/plugins/pt-content-views-pro/public/assets/images/lazy_image.png)
[Webinars] Vulnerability reports, application security for DevOps and CI/CD
Learn how vulnerability reports can help you fix critical vulnerabilities effectively, and the essentials of application security for DevOps and CI/CD. The post [Webinars] Vulnerability reports, application security for DevOps and CI/CD ...