Using open source code helps development teams save time and tap into the knowledge of domain experts who contribute to open source projects. Black Duck engages with open source security initiatives in multiple areas including best practices, information sharing, license compliance, software Bill of Materials (SBOM), API standardization, and more.

To help raise the bar for open source software security and stay informed about the latest development innovations, Black Duck employees serve or have served as subject matter experts for open source community initiatives—including working groups, programs, and projects related to open source governance, adoption, and success.

Open Source Community Initiatives

auto-grade-linux-logo
Automotive Grade Linux (AGL)
cloud-native-logo
Cloud Native Computing Foundation (CNCF)
cloud-native-landscape-logo
Cloud Native Landscape
cii-logo
Core Infrastructure Initiative
Laboratory for Innovation Science at Harvard
okd-logo
OpenShift Kubernetes Distribution (OKD)
open-chain-logo
OpenChain
oin-logo
Open Invention Network (OIN)
osc-logo
OpenShift Commons
open-ssf-logo
Open Source Security Foundation (OpenSSF)
owasp-logo
Open Web Application Security Project (OWASP)
spdx-logo
Software Package Data Exchange (SPDX)
uptane-logo
Uptane
wasc-logo
Web Application Security Consortium
zephyr-logo
Zephyr