“Black Duck SCA has significantly improved our ability to generate a comprehensive SBOM for our applications,” Brintazzoli said. “The reports are easily exportable and integrate well with our existing compliance and security workflows, streamlining audits and reducing manual effort, as well.”
Improved security posture
Black Duck SCA provides detailed dependency identification, early vulnerability detection, and automated security testing integrated into development workflows, significantly improving security posture.
“Most notably, the automated identification and continuous monitoring of open source components has drastically reduced our exposure to known vulnerabilities,” said Brintazzoli. “We have seen a clear decrease in the number of security issues related to third-party libraries, thanks to timely alerts and remediation guidance.”
Additionally, Black Duck’s license compliance features have minimized the legal risks associated with open source use.
Automated license risk management
Black Duck allows organizations to set license policies in advance, so developers can implement open source without the additional work required to evaluate license obligations.
“Black Duck SCA accurately detects the licenses associated with each component and flags any potential conflicts or obligations in real time,” Brintazzoli said. “This significantly reduces the manual effort required to track license compliance.”
Black Duck SCA also finds explicitly declared licenses, sublicenses, and embedded licenses, and presents the requirements and restrictions in a simplified view, along with complete license text and copyright information.