Software Integrity Blog

Archive for the 'Software Composition Analysis' Category

 

Top 3 reasons to choose Black Duck

What sets Black Duck apart from other SCA solutions? Industry-leading innovation, extensive vulnerability detection, and a broad range of integrations.

Continue Reading...

Posted in Open Source Security, Software Composition Analysis | Comments Off on Top 3 reasons to choose Black Duck

 

How to choose application security vendors and tools

Unless you build your own AppSec tools, you need to know how to choose an application security vendor and whether to opt for individual tools or a suite.

Continue Reading...

Posted in Interactive Application Security Testing (IAST), Software Composition Analysis | Comments Off on How to choose application security vendors and tools

 

Introducing Black Duck for Google Cloud Build

To support the launch of Binary Authorization, we’re releasing Black Duck for Google Cloud Build to help ensure your images are free of policy violations.

Continue Reading...

Posted in Agile, CI/CD & DevOps, Container Security, News & Announcements, Open Source Security, Software Composition Analysis | Comments Off on Introducing Black Duck for Google Cloud Build

 

Introducing the Black Duck Jira Cloud integration

The Black Duck Jira Cloud integration is based on a flexible, customizable model, backed by the same exemplary Black Duck software composition product.

Continue Reading...

Posted in News & Announcements, Open Source Security, Software Composition Analysis | Comments Off on Introducing the Black Duck Jira Cloud integration

 

You’re using open source software, and you need to keep track of it

How should you track open source? It’s almost definitely in your codebase, so the question is not whether to track it but what could happen if you don’t.

Continue Reading...

Posted in Open Source Security, Software Composition Analysis | Comments Off on You’re using open source software, and you need to keep track of it

 

Technology company M&A: Do due diligence on SDLC process/tools

Technical due diligence on the target’s SDLC is a must for acquirers in software M&A. What you don’t know about their process and tools could hurt you.

Continue Reading...

Posted in Mergers & Acquisitions, Open Source Security, Software Composition Analysis | Comments Off on Technology company M&A: Do due diligence on SDLC process/tools

 

Forrester recognizes Synopsys as a leader in software composition analysis

Black Duck is among platforms that lead the pack, cited for “very strong policy management and SDLC integrations and strong proactive vulnerability management.”

Continue Reading...

Posted in News & Announcements, Open Source Security, Software Composition Analysis | Comments Off on Forrester recognizes Synopsys as a leader in software composition analysis

 

The hidden costs and risks of free puppies (and open source)

SCA tools are an essential part of your AppSec toolkit, because free and open source software—just like free puppies—comes with hidden costs and risks.

Continue Reading...

Posted in Agile, CI/CD & DevOps, Open Source Security, Software Composition Analysis | Comments Off on The hidden costs and risks of free puppies (and open source)

 

Hacking Security Episode 3: OSSRA report findings

Hacking Security is a monthly podcast on emerging trends in application security. Episode 3 explores key findings from the 2018 OSSRA report.

Continue Reading...

Posted in Mergers & Acquisitions, Open Source Security, Software Composition Analysis | Comments Off on Hacking Security Episode 3: OSSRA report findings

 

Eating our own duck food: Software composition analysis in the Synopsys SDLC

In the Synopsys Software Integrity Group, we test all our products against one another—turning our security into a force multiplier for our customers’ security.

Continue Reading...

Posted in Software Composition Analysis | Comments Off on Eating our own duck food: Software composition analysis in the Synopsys SDLC