Polaris

One
Platform.

Complete Application
Security.
Integrate AppSec to match the speed, scale, and ambition of AI-powered development with the Black Duck Polaris™ Platform.

We have a storied past, but we’re driven by the future

Our pedigree: We helped the world embrace open source software safely and securely. We unified disparate technologies to build the first comprehensive application security platform. We defied the assumption that a vendor couldn’t test both embedded software and web apps. We bridged the gap between testing in the cloud and on-prem. And we grew into the largest, most trusted application security testing (AST) provider in the world, recognized as the eight-time Leader in the Gartner® Magic Quadrant™ for AST.

The future we’re building: Black Duck is now defining the next frontier of application security. With the avalanche of AI-generated code plus expanding regulatory pressure, you need solutions that can scale, adapt, and keep pace with the demands of your business.

Black Duck meets the demands of modern software development with True Scale Application Security. In the cloud or on-prem, 100,000 lines of code or 100 million. For safety-critical systems with stringent compliance requirements or modern web apps deploying 100 times per day. Our flexible, scalable, high-precision solutions enable you to code with confidence.

Backed by 20+ years of human-curated intelligence

4,000+ organizations choose Black Duck for unmatched software risk insight.

Keep security in sync with development

Polaris combines Black Duck’s market-leading SAST, SCA, and DAST engines with IaC analysis and secrets detection into a single, developer-first SaaS platform.

Address the new era of software development

95%
of organizations use AI tools for software development.
Component Showcase Image

Build secure code at AI speed

When innovation moves fast, your security must move faster. Accelerate modern software development with agentic AI AppSec that secures every line of code with no friction or delay.

65%
of organizations reported experiencing a software supply chain attack in the past year.
Component Showcase Image

Strengthen software supply chain security

When every component matters, compromise isn’t an option. Get total visibility and compliance, and eliminate risk across your software supply chain.

24%
of organizations perform comprehensive IP, license, security, and quality evaluations.
Component Showcase Image

Deliver code quality and compliance

For safety-critical systems, flawless code is non-negotiable. Deliver products that customers trust with zero defects, zero compromises, and total visibility.

“Since adopting Polaris more broadly, we now catch a majority of fixable issues earlier in the IDE and PR stages instead of after merge, which has reduced remediation time for high-severity findings and cut down on late-stage security work. We’ve been able to expand SAST coverage to most active repos without adding AppSec headcount, including legacy and newer services.”
Vignesh Kannan
Software Security Lead, H&M
“We would strongly recommend the Black Duck AST tools to all enterprises, especially those specializing in embedded systems where code quality is of paramount importance.”
Do Van Khac
Chief delivery officer and executive VP, FPT Software
“Polaris delivers measurable operational efficiency and faster decision-making by providing a unified, scalable platform that transforms raw industrial data into real-time, actionable insights.”
Senior Member of Technical Staff
Large Enterprise, Internet Software Services

Compliance made simple

Built-in static analysis reports provide insight into issue types and severity to help prioritize remediation efforts and track progress toward each standard across teams and projects.

Explore Topics

Component Showcase Image

Agile Manifesto for a Holistic AppSec Environment

Learn about the ins and outs of the Agile Software Development Methodology.

FAQ

The Black Duck Polaris Platform is a comprehensive, cloud-native, SaaS application security testing solution designed to unify and automate application security throughout the software development life cycle. It integrates the industry’s most powerful security analysis engines—including SAST with Polaris fAST Static, SCA with Polaris fAST SCA, and DAST with Polaris fAST Dynamic—into a single, fully integrated platform.

Polaris empowers development, DevOps, and security teams by providing fast feedback, seamless CI/CD integration, and comprehensive vulnerability detection with governance controls. Built for scalability and flexibility, Polaris eliminates the traditional overhead of on-premises tools, allowing you to onboard and scan code within minutes from popular repositories like GitHub and GitLab. By shifting security left and consolidating multiple testing types, Polaris transforms application security into an automated, continuous process, ensuring that you maintain comprehensive visibility and control over your application security risks across diverse technology stacks.

FAQ

The Black Duck Polaris Platform is a comprehensive, cloud-native, SaaS application security testing solution designed to unify and automate application security throughout the software development life cycle. It integrates the industry’s most powerful security analysis engines—including SAST with Polaris fAST Static, SCA with Polaris fAST SCA, and DAST with Polaris fAST Dynamic—into a single, fully integrated platform.

Polaris empowers development, DevOps, and security teams by providing fast feedback, seamless CI/CD integration, and comprehensive vulnerability detection with governance controls. Built for scalability and flexibility, Polaris eliminates the traditional overhead of on-premises tools, allowing you to onboard and scan code within minutes from popular repositories like GitHub and GitLab. By shifting security left and consolidating multiple testing types, Polaris transforms application security into an automated, continuous process, ensuring that you maintain comprehensive visibility and control over your application security risks across diverse technology stacks.

Black Duck by the numbers

0 %
Of Black Duck SCA users reported a reduction in time spent finding and fixing open source risks.
0 %
Of Black Duck SCA users found and fixed open source risks at least 10% faster.
0 %
Less time spent finding and fixing open source risks on average since implementing Black Duck SCA.

Select the plan that fits your needs

Standard Edition

Enable developers and DevOps teams to address open source policy concerns without slowing innovation.

Open source detection
  • Unlimited application and container scans
  • Rapid open source dependency analysis
  • Undeclared component identification
  • Custom component detection

Open source detection

Equip the entire enterprise with a software supply chain security and risk management solution. Get complete supply chain visibility, address risk, and establish trust with consumers.

Open source detection
  • Unlimited application and container scans
  • Rapid open source dependency analysis
  • Detection of partial code snippets
  • Binary file and firmware analysis
  • Undeclared component identification
  • Custom component detection

Integrated development environment (IDE) integrations

The Code Sight IDE plug-in integrates SAST and SCA scans into the developer IDE, enabling developers to identify and fix vulnerabilities before committing code, saving time and improving code quality.

software risk manager, coverity, code sight

Eclipse

Upload binaries to Black Duck for static analysis. Review scan results from within Eclipse to remediate security findings in your apps.
software risk manager, coverity, code sight

IntelliJ IDEA

Upload binaries to Black Duck for static analysis. Review scan results from within Intellij to remediate security findings in your apps.
Software risk manager, coverity code sight

Visual Studio

Compile and upload apps to Black Duck for static analysis. Identify security findings, view datapath info, and get remedition guidance within the IDE.
Coverity

Android Studio

code sight, coverity

PyCharm

Source Code Management (SCM) integrations

Black Duck’s security tools integrate with leading source code management solutions to enable rapid scans on every pull or merge request to provide quick results and prevent issues from impacting other teams.

coverity, polaris, black duck

GitHub

Automate Black Duck SAST or SCA scanning of your application code from within GitHub.
coverity, polaris, black duck

GitLab

Perform SAST or SCA scans on each new build with integration to GitLab templates.
coverity, software risk manager

Bitbucket

Black Duck Security Scan Pipe integrates Black Duck security testing into your Bitbucket pipeline.

Build and CI integrations

Black Duck’s security tools integrate with leading build and CI tools to add security into CI/CD pipelines. Security teams can enforce policies by integrating scan results into quality gates, enabling them to break builds if violations occur.

Coverity, Polaris, Black Duck

GitHub

Automate Black Duck SAST or SCA scanning of your application code from within GitHub.
coverity, polaris, black duck

GitLab

Perform SAST or SCA scans on each new build with integration to GitLab templates.

Package manager integrations

Black Duck works with package management tools to identify open source and third-party components in applications to help manage security, license, and component quality risks associated with dependencies.

coverity, black duck

Maven

Integrate Black Duck Static Analysis scanning with Apache Maven into existing build processes that you use in your SDLC.
Black Duck

Gogradle

Black Duck Static Analysis scanning with Gogradle into existing buid processes that you use in your SDLC.

Binary repository integrations

Black Duck integrates with binary repositories to host approved open source packages and store build artifacts to help developers identify source code and open source dependency violations to ensure code quality and compliance.

Black Duck

Artifactory

Identify source code and open source dependency violations in Artifactory repositories.
black duck

Nexus Repository

Scan docker images for threats with Black Duck Binary Analysis integration.

Workflow and notifications integrations

Black Duck integrates with popular notification and workflow management tools to flag vulnerabilities and send issues to downstream teams for resolution.

Coverity, black duck, seeker, polaris, software risk manager

Jira Software

The Black Duck plugin for JIRA creates issues based on vulnerabilities and issue policy violations detected by Black Duck.
Software risk manager, coverity, seeker

Secure Code Warrior

Black Duck and Secure Code Warrior provide an integrated solution to prevent security issues at the developer desktop to accelerate time to remediation.

Security testing integrations

Black Duck offers an open platform that can integrate with several third-party security testing tools, enabling organizations to consolidate SAST, SCA, DAST, Infrasec, CNAPP, IaC, and pen testing in one place.

Click here for a full list of our supported integrations.

software risk manager

Checkmarx

Black Duck’s ASPM solution can ingest vulnerability findings from Checkmarx into Polaris for a complete and centralized view of application risk posture across your organization.
Software risk manager

Snyk

Black Duck’s ASPM solution can ingest vulnerability findings from Snyk into Polaris for a complete and centralized view of application risk posture across your organization.

Production deployment integrations

Black Duck solutions integrate with leading production deployment tools to enable application releases that keep pace with development velocity, scale with organizations’ software footprint, and thoroughly test for quality.

Seeker

Amazon Web Services

Deploy compliant code releases tested by Black Duck to the cloud with Amazon Web Services.
black duck

Google Cloud

Deploy compliant code releases tested by Black Duck to the cloud with Google Cloud.

Aerospace and defense

DISA-STIG

Coverity® Static Analysis identifies potential security vulnerabilities and defects in application code, enabling organizations with DISA-STIG requirements to track, prioritize, and resolve issues in accordance with these guidelines. Code scans can uncover a wide range of defects that impact DISA-STIG compliance, including race conditions, error handling, and overflows.

DO-330 / DO-178C

Coverity integrates into the development life cycle for software used in airborne systems to identify code defects that could prevent compliance with DO-330 requirements. It provides detailed remediation guidance to help resolve issues that could impact the safety, reliability, and effectiveness of those systems. And the Coverity Qualification Kit ensures that Coverity is configured and operating properly in the end-user build environment as required by DO-178C standards.

Automotive

AUTOSAR

Coverity supports AUTOSAR requirements by identifying code quality and security defects and mapping them to the rules of this standard. Code scans can be automated to run on pull requests to uncover issues early in the SDLC, when they’re easiest to resolve. Native reports make it easy to enforce AUTOSAR coding standards, prioritize issues, and provide evidence of compliance.

MISRA

Coverity static analysis supports MISRA coding standards and can identify relevant defects, assign scores based on predefined policies, and prioritize issues for remediation. Code scans can be triggered on pull requests to uncover issues early in the SDLC, when they’re easiest to resolve. Native reporting provides evidence of compliance to the MISRA coding standards.

ISO 26262

Black Duck helps organizations achieve ISO 26262 compliance for developing and testing safety-critical software by providing static analysis for proprietary code, software composition analysis to identify weaknesses in third-party and open source components, and fuzz testing to uncover defects and zero-day vulnerabilities in services and protocols. The Coverity Qualification Kit ensures that Coverity is configured and operating properly in the end-user build environment as required by ISO 26262 standards.

ISO / SAE 21434

Black Duck helps organizations meet ISO 21434 requirements for secure software development by providing automated static code analysis, vulnerability scanning of open source components, fuzz testing, and penetration testing into the software development life cycle for road vehicle systems. Issue reporting can be tailored specific to ISO 21434 requirements to track and manage compliance with these standards.

Hyundai Coding Standards

Coverity provides code quality and security checkers to find defects that violate the Hyundai Coding Standards for C, C++, and Java. Native reporting helps security teams prioritize results by displaying details of all outstanding violations along with a description of each rule and its severity level, priority, and the number of times that rule has been violated.

Jason Schmitt

Chief Executive Officer

more

Dipto Chakravarty

Chief Product & Technology Officer

more

Sean Forkan

Chief Revenue Officer

more
Dom Glavach

Dom Glavach

Chief Information Security Officer

more
Jim Ivers

Jim Ivers

Chief Marketing Officer

more
 


VXLAN Test Suite Data Sheet

Test Suite: VXLAN Test Suite

Direction: Server

VXLAN (Virtual eXtensible Local Area Network) is a network virtualization technology that attempts to address the scalability problem associated with large cloud computing deployments. It uses an encapsulation technique to encapsulate OSI layer 2 Ethernet frames within layer 4 UDP datagrams, using 4789 as the default IANA-assigned destination UDP port number. VXLAN tunnel endpoints (VTEPs) terminate VXLAN tunnels and could be on a physical switch or physical server and could be implemented in software or hardware. The VXLAN Test Suite has been designed to act as a malicious VTEP which sends exceptional requests in VXLAN protocol layers to the tested entity.

Used specifications

Specification Title
RFC7348 Virtual eXtensible Local Area Network (VXLAN): A Framework for Overlaying Virtualized Layer 2 Networks over Layer 3 Networks
draft-stewart-sctp-pktdrprep-15 Protocol for determining a network host’s link layer or hardware address when only its Internet Layer (IP) or Network Layer address is known.

Tool-specific information

Tested messages Specifications
VXLAN messages with ICMPv4 Echo Request as payload RFC7348, RFC777
VXLAN messages with ICMPv6 Echo Request as payload RFC7348, RFC4443

Detailed, data-rich reports for efficient remediation

Our comprehensive reports include contextualized logs that detail the protocol path and message sequences, vulnerability mapping to industry standards such as CWE and injection type, and single test cases so you can re-create each issue and verify the fix. You can also generate remediation packages for your suppliers to facilitate secure, collaborative remediation across the supply chain.

Table of Contents

    Aerospace and defense

    DISA-STIG

    Coverity® Static Analysis identifies potential security vulnerabilities and defects in application code, enabling organizations with DISA-STIG requirements to track, prioritize, and resolve issues in accordance with these guidelines. Code scans can uncover a wide range of defects that impact DISA-STIG compliance, including race conditions, error handling, and overflows.

    DO-330 / DO-178C

    Coverity integrates into the development life cycle for software used in airborne systems to identify code defects that could prevent compliance with DO-330 requirements. It provides detailed remediation guidance to help resolve issues that could impact the safety, reliability, and effectiveness of those systems. And the Coverity Qualification Kit ensures that Coverity is configured and operating properly in the end-user build environment as required by DO-178C standards.

    Automotive

    AUTOSAR

    Coverity supports AUTOSAR requirements by identifying code quality and security defects and mapping them to the rules of this standard. Code scans can be automated to run on pull requests to uncover issues early in the SDLC, when they’re easiest to resolve. Native reports make it easy to enforce AUTOSAR coding standards, prioritize issues, and provide evidence of compliance.

    MISRA

    Coverity static analysis supports MISRA coding standards and can identify relevant defects, assign scores based on predefined policies, and prioritize issues for remediation. Code scans can be triggered on pull requests to uncover issues early in the SDLC, when they’re easiest to resolve. Native reporting provides evidence of compliance to the MISRA coding standards.

    ISO 26262

    Black Duck helps organizations achieve ISO 26262 compliance for developing and testing safety-critical software by providing static analysis for proprietary code, software composition analysis to identify weaknesses in third-party and open source components, and fuzz testing to uncover defects and zero-day vulnerabilities in services and protocols. The Coverity Qualification Kit ensures that Coverity is configured and operating properly in the end-user build environment as required by ISO 26262 standards.

    ISO / SAE 21434

    Black Duck helps organizations meet ISO 21434 requirements for secure software development by providing automated static code analysis, vulnerability scanning of open source components, fuzz testing, and penetration testing into the software development life cycle for road vehicle systems. Issue reporting can be tailored specific to ISO 21434 requirements to track and manage compliance with these standards.

    Hyundai Coding Standards

    Coverity provides code quality and security checkers to find defects that violate the Hyundai Coding Standards for C, C++, and Java. Native reporting helps security teams prioritize results by displaying details of all outstanding violations along with a description of each rule and its severity level, priority, and the number of times that rule has been violated.