Black Duck’s open source KnowledgeBase™ is the industry’s most comprehensive database of open source project, license, and security information, sourced and curated by the Synopsys Cybersecurity Research Center (CyRC), covering more than 6.3 million open source components from over 29,000 forges and repositories.
unique open source licenses
open source projects
The KnowledgeBase contains more than 2,750 unique open source licenses (GPL, LGPL, Apache, etc.), with full license text for the most popular open source licenses and dozens of encoded attributes and obligations for each license.
We track more than 208,000 unique vulnerabilities affecting more than 426,000 component versions, including thousands of Black Duck exclusive vulnerabilities not contained in the National Vulnerability Database (NVD) or other sources.
We catalog more than 6.3 million unique open source projects, allowing highly accurate matches to the components that compose your software, including modified code and open source code snippets.
Deep license data identifies embedded licenses to help organizations trust the use of thousands of projects with no declared license. Deep license data exposes projects with no license data, which are high-risk, and provides full license text for the most popular open source licenses.
With millions of open source projects available globally from thousands of websites and forges, it can be difficult (and sometimes impossible) to effectively track your open source use and manage the application security, software license compliance, and component quality risks that come with it. Black Duck solves this problem, giving development, security, and legal teams maximum visibility and control of open source in their applications and containers. The open source KnowledgeBase is the foundation for Black Duck, providing the industry’s most comprehensive database of open source component, vulnerability, and license information.
Watch the video
Download the supply chain security solution guide
Learn more about the market-leading SCA tool
Download the latest OSSRA report
See why Black Duck is a Leader
See why Synopsys is a Leader in AppSec