The Synopsys Software Integrity Group is now Black Duck®. Learn More

Development and DevOps Integrations

Black Duck DevOps integrations and security plug-ins are designed to establish reliable, automated mechanisms to detect and remedy security and compliance risks within complex tech stacks in ways that uphold developers’ need for speed and security’s need for coverage.

Automate risk detection

Trigger application security tests—like SAST and SCA—based on pipeline events including build, SCM check-in, preproduction unit testing, and more.

Accelerate triage and remediation

Enforce risk tolerance policies, establish security gates, and provide clear fix guidance to developers within their existing tools and workflows.

Boost developer productivity

Deliver real-time risk insight and noncompliance alerts to avoid late-stage rework.

  • IDE
  • SCM
  • Build
    and CI
  • Package
    manager
  • Binary
    repository
  • Workflow and
    notifications
  • Security
    testing
  • Production
    deployment
  • Black Duck
  • Coverity
  • Software Risk Manager
  • Code Sight
  • Polaris
  • Seeker

Integrated development environment (IDE) integrations

The Code Sight IDE plug-in integrates SAST and SCA scans into the developer IDE, enabling developers to identify and fix vulnerabilities before committing code, saving time and improving code quality.

Eclipse

Eclipse logo

Upload binaries to Black Duck for static analysis. Review scan results from within Eclipse to remediate security findings in your apps.

IntelliJ IDEA

IntelliJ IDEA logo

Upload binaries to Black Duck for static analysis. Review scan results from within Intellij to remediate security findings in your apps.

Visual Studio

Visual Studio logo

Compile and upload apps to Black Duck for static analysis. Identify security findings, view datapath info, and get remedition guidance within Microsoft Visual Studio.

Android Studio

Android Studio

coverity

PhpStorm

PhpStorm

code sight coverity

WebStorm

WebStorm

code sight coverity

PyCharm

PyCharm

code sight coverity

IBM Engineering Workflow Management

IBM

coverity

QNX Momentics Tool Suite

coverity

RubyMine

RubyMine

code sight coverity


Source Code Management (SCM) integrations

Black Duck's security tools integrate with leading source code management solutions to enable rapid scans on every pull or merge request to provide quick results and prevent issues from impacting other teams.

GitHub

GitHub logo

Automate Black Duck SAST or SCA scanning of your application code from within GitHub.

GitLab logo

IntelliJ IDEA logo

Automate Black Duck SAST or SCA scanning of our application code with GitLab.

Bitbucket

Bitbucket logo

Black Duck Security Scan Pipe integrates Black Duck security testing into your Bitbucket pipeline.


Build and CI integrations

Black Duck’s security tools integrate with leading build and CI tools to add security into  CI/CD pipelines.  Security teams can enforce policies by integrating scan results into quality gates, enabling them to break builds if violations occur.

Gitlab

GitLab logo

Perform SAST or SCA scans on each new build with integration to GitLab templates.

GitHub

GitHub logo

Perform SAST or SCA scans on each new build with integration GitHub Actions.

Jenkins

Visual Studio logo

Black Duck Jenkins Plugin automates building, uploading, and scanning of application code in Jenkins pipelines.

AWS CodeBuild

AWS CodeBuild

black duck

CircleCI

CircleCI

black duck

SBT

sbt

black duck

Travis CI

Travis CI

black duck

Jenkins (commercial)

CloudBees

black duck

TeamCity

TeamCity

software risk manager black duck

CodeShip

CodeShip

black duck

Bamboo

Bamboo

tinfoil coverity black duck

Concourse

Concourse

black duck

Wind River Workbench

Wind River Studio

coverity


Package manager integrations

Black Duck works with package management tools to identify open source and third-party components in applications to help manage security, license, and component quality risks associated with dependencies.

Maven

Maven logo

Integrate Black Duck Static Analysis scanning with Apache Maven into existing build processes that you use in your SDLC.

Gogradle

Gogradle logo

Black Duck Static Analysis scanning with Gogradle into existing buid processes that you use in your SDLC.

npm

npm logo

Integrate Static Analysis scanning with npm to seamlessly add static scanning into existing build processes that you use in your SDLC.

Composer

Composer

black duck

Go Module CLI

Go Module CLI

black duck

Yarn

Yarn

coverity black duck

Bower

Bower

coverity

Comprehensive Perl Archive Network (CPAN)

CPAN

black duck

Go Vndr

Go Vndr

black duck

Poetry

Poetry

black duck

Cargo

Cargo

black duck

Rebar3

Rebar3

black duck

RubyGems

RubyGems

black duck

CocoaPods

CocoaPods

black duck

Conda

Conda

black duck

Lerna

Lerna

black duck

Packrat

Packrat

black duck


Binary repository integrations

Black Duck integrates with binary repositories to host approved open source packages and store build artifacts to help developers identify source code and open source dependency violations to ensure code quality and compliance.

Artifactory

Eclipse logo

Identify source code and open source dependency violations in Artifactory repositories.

Nexus Repository

IntelliJ IDEA logo

Scan docker images for threats with Black Duck Binary Analysis integration.

Amazon ECR

Amazon ECR logo

Streamline AppSec testing of images in Google containers.

Azure Container Registry

Azure

black duck

Google Container Registry

Google

black duck


Workflow and notifications integrations

Black Duck integrates with popular notification and workflow management tools to flag vulnerabilities and send issues to downstream teams for resolution.

Jira Software

Jira logo

The Black Duck plugin for JIRA creates issues based on vulnerabilities and issue policy violations detected by Black Duck.

Secure Code Warrior

Secure Code Warrior logo

Black Duck and Secure Code Warrior provide an integrated solution to prevent security issues at the developer desktop to accelerate time to remediation.

Slack

Slack logo

The Black Duck plugin for Slack allows you to create Slack notifications based on vulnerabilities and policy violations detected by Black Duck.

Azure Boards

Azure Boards

black duck

Bugzilla

Bugzilla

coverity

Software Package Data Exchange (SPDX)

SPDX

black duck

Microsoft Teams

Microsoft Teams

black duck software risk manager


Security testing integrations

Black Duck offers an open platform that can integrate with several third-party security testing tools, enabling organizations to consolidate SAST, SCA, DAST, Infrasec, CNAPP, IaC, and pen testing in one place.

Click here for a full list of our supported integrations.

Checkmarx

Checkmarx logo

Black Duck’s ASPM solution can ingest vulnerability findings from Checkmarx into Polaris for a complete and centralized view of application risk posture across your organization.

Snyk

Snyk logo

Black Duck’s ASPM solution can ingest vulnerability findings from Snyk into Polaris for a complete and centralized view of application risk posture across your organization.

Veracode

Slack logo

Black Duck’s ASPM solution can ingest vulnerability findings from Veracode into Polaris for a complete and centralized view of application risk posture across your organization.

Acunetix

Acunetix

software risk manager

Acunetix

Aqua

software risk manager

Acunetix

Clang

software risk manager

Acunetix

Contrast Assess

software risk manager

Acunetix

Errcheck

software risk manager

Acunetix

Fortify

software risk manager

Acunetix

Gendarme

software risk manager

Acunetix

HCL AppScan

software risk manager

Acunetix

JSHint

software risk manager coverity

Acunetix

Netsparker

software risk manager

Acunetix

Parasoft

software risk manager

Acunetix

PHP_CodeSniffer

software risk manager

Acunetix

Scalastyle

software risk manager

Acunetix

Staticcheck

software risk manager

Acunetix

Trustwave App Scanner

software risk manager

Acunetix

WhiteSource

software risk manager

Acunetix

ThunderScan

software risk manager

Acunetix

Anchore Enterprise

software risk manager

Acunetix

Arachni

software risk manager

Acunetix

Code Cracker

software risk manager

Acunetix

Cppcheck

software risk manager

Acunetix

Error Prone

software risk manager

Acunetix

Gocyclo

software risk manager

Acunetix

Ineffassign

software risk manager

Acunetix

Microsoft

software risk manager

Acunetix

Nexus Lifecycle

software risk manager

Acunetix

software risk manager

Acunetix

Qualys

software risk manager

Acunetix

SD Elements

software risk manager

Acunetix

Tenable

software risk manager

Acunetix

Vet

software risk manager

Acunetix

Android Studio Lint

software risk manager

Acunetix

Brakeman

software risk manager

Acunetix

CodePeer

software risk manager

Acunetix

Dependency-Check

software risk manager

Acunetix

ESLint

software risk manager

Acunetix

Golint

software risk manager

Acunetix

JFrog Xray

software risk manager

Acunetix

Mobile Secure

software risk manager

Acunetix

Nmap

software risk manager

Acunetix

OCLint

software risk manager

Acunetix

Prisma Cloud

software risk manager

Acunetix

Retire.js

software risk manager

Acunetix

Security Code Scan

software risk manager

Acunetix

Vex

software risk manager

Cycode

Cycode

black duck coverity

Vigilant Ops

black duck

Acunetix

Visual Studio Code Analysis

software risk manager coverity

AppSecAI Expert Triage Automation 

coverity

Acunetix

AppSpider

software risk manager

Burp Suite

software risk manager

Acunetix

Checkstyle

software risk manager

Acunetix

CodeSonar

software risk manager

Acunetix

Dependency-Track

software risk manager

Acunetix

Find Security Bugs

software risk manager

Acunetix

software risk manager

Acunetix

Gosec

software risk manager

Acunetix

Jlint

software risk manager

Acunetix

Nessus

software risk manager

Acunetix

OWASP ZAP

software risk manager

Acunetix

PHP Mess Detector

software risk manager

Acunetix

Pylint

software risk manager

Acunetix

SafeSQL

software risk manager

Acunetix

SpotBugs

software risk manager coverity

Acunetix

sqlmap

software risk manager


Production deployment integrations

Black Duck solutions integrate with leading production deployment tools to enable application releases that keep pace with development velocity, scale with organizations’ software footprint, and thoroughly test for quality.

Amazon Web Services

AWS logo

Deploy compliant code releases tested by Black Duck to the cloud with Amazon Web Services.

Google Cloud

Google Cloud logo

Deploy compliant code releases tested by Black Duck to the cloud with Google Cloud.

Kubernetes

Kubernetes logo

Deploy compliant containerized apps tested by Black Duck with Kubernetes.

Amazon Web Services (AWS)

Amazon Web Services (AWS)

seeker

Cloud Foundry

Cloud Foundry

seeker

Microsoft Azure

Microsoft Azure

black duck

IBM Cloud Pak for Applications

IBM Cloud Pak for Applications

black duck

VMware Tanzu

VMware Tanzu

seeker