Software Integrity Blog

Archive for the 'Software Composition Analysis (SCA)' Category

 

Get earlier, actionable vulnerability insights from Black Duck Security Advisories

Identifying security vulnerabilities is only half the battle. To remediate and prioritize them, you need Black Duck Security Advisories.

Continue Reading...

Posted in Managing security risks, Software Composition Analysis (SCA)

 

Discovery capabilities: A core differentiator for Black Duck SCA

Stay on top of open source vulnerabilities and license obligations with discovery capabilities from Black Duck.

Continue Reading...

Posted in Building secure software, Open Source Security, Software Composition Analysis (SCA)

 

How to manage open source risks using Black Duck SCA

Open source risk goes beyond application security. Legal, operational, and supply chain implications demand a capable solution like Black Duck SCA.

Continue Reading...

Posted in Open source and software supply chain risks, Software Composition Analysis (SCA)

 

Things to consider when choosing a software composition analysis tool

The rise of open source software is not without risks for today’s applications. Use a software composition analysis tool to mitigate these risks.

Continue Reading...

Posted in Building secure software, Software Composition Analysis (SCA)

 

Making SCA part of your AST Strategy

Open source software is now used in nearly every organization, which makes it critical to know your code. Learn how an SCA tool can help you.

Continue Reading...

Posted in Security news and research, Software Composition Analysis (SCA)

 

Black Duck continues to expand vulnerability prioritization methods

Today’s release of Black Duck adds vulnerability impact analysis, which indicates whether your application executes vulnerable code. Let’s look at how this addition further augments your prioritization efforts.

Continue Reading...

Posted in Application Security, Security news and research, Software Composition Analysis (SCA)

 

An introduction to installing Black Duck

Get started with the Dockerized Black Duck installation. This post outlines workplace specifications, tools, and steps for installing Black Duck.

Continue Reading...

Posted in Building secure software, Software Composition Analysis (SCA)

 

The advanced license compliance functionality you didn’t know your SCA tool needed

Open source license noncompliance can have severe implications. Here are four advanced license compliance features that help protect your proprietary code.

Continue Reading...

Posted in Open source and software supply chain risks, Software Composition Analysis (SCA)

 

Why developers need a supplemental source to NVD vulnerability data

The NVD is a good source for open source vulnerability data. But with an average 27-day reporting delay, it shouldn’t be your only source of information.

Continue Reading...

Posted in Open source and software supply chain risks, Open Source Security, Software Composition Analysis (SCA)

 

[Webinars] Vulnerability reports, application security for DevOps and CI/CD

Learn how vulnerability reports can help you fix critical vulnerabilities effectively, and the essentials of application security for DevOps and CI/CD.

Continue Reading...

Posted in Agile, CI/CD, & DevOps, Open Source Security, Software Composition Analysis (SCA), Software Security Program, Webinars