Total 29 reviews

4.2

All reviews are from verified customers

Rating Distribution

5

Stars

45%

4

Stars

38%

3

Stars

14%

2

Stars

3%

1

Stars

0%

Satisfaction score

Ease of use

8

Value for money

8

Customer Support

8

Functionality

8

GP

Gaurav P.

Medical Devices, N/A employees

More than a year

5.0
November 2025

Great for pipeline security

Pros

Getting it integrated is painless. You can drop Black Duck into CI/CD pipelines and shift security left in the SDLC which bolsters security across the board.

Cons

Reporting still has room for improvement. Embargo vulnerabilities especially potential ones, are not updated with CVE scores as quickly or as easily as they should be.

Rating Distribution

Ease of use

10

Value for money

9

Customer Support

10

Functionality

8

SW

Sam W.

Airlines/Aviation, N/A employees

More than a year

5.0
January 2025

Unmatched security coverage

Pros

It gives you outstanding visibility into software security and the coverage is excellent. In my opinion, it's the best option out there especially since you can integrate it at scale without much trouble.

Cons

The on-premise deployment can be very challenging to get up and running. It involves downloading massive amounts of data which takes a lot of bandwidth, plus significant processing to unpack everything and complete the setup. A cloud-based option may be worth considering.

Rating Distribution

Ease of use

10

Value for money

10

Customer Support

10

Functionality

10

SK

Sharique K.

Hospital & Health Care, N/A employees

More than a year

5.0
August 2021

Simple maintainence and regular updated

Pros

Keeping the vulnerability list current is one of this tool's biggest strengths. Maintenance and administration are easy to manage and integrating it with different CI/CD toolsets is effortless which really supports strong DevSecOps practices.

Cons

If there's any challenge at all, it's more about DevSecOps still being relatively new overall so developers and engineers need time to become more familiar with these security concepts.

Rating Distribution

Ease of use

9

Value for money

10

Customer Support

10

Functionality

10

A

Anonymous

Information Technology and Services, N/A employees

More than a year

5.0
April 2018

detection accuracy is so reliable

Pros

The range of integration options fits pretty much any CI/CD setup you want to use. IDE integrations are simple to roll out so you're not boxed into a single approach if your DevOps team prefers specific technologies. Accuracy and detection capabilities have been very reliable and feel quite strong.

Cons

There is not much I can point to as a real downside. At first, the lack of code snippets felt like a missing piece but that has since been addressed which makes the solution more capable and improves the overall user experience.

Rating Distribution

Ease of use

10

Value for money

10

Customer Support

10

Functionality

10

BP

Benjamin P.

Information Technology and Services, N/A employees

Less than 6 months

3.0
November 2017

Pipleline Integration is a good thing

Pros

We installed and connected it with Bamboo and that has worked well for our pipeline workflow and the follow-up analysis of findings.

Cons

Black Duck promoted Gradle support through an Eclipse integration but in practice it only worked with a very basic Gradle project setup. More recently (11-8-2017), Black Duck told us in a response not to use the Eclipse plugin. That is a major problem for our DevOps process since we need developers to be able to identify issues locally in Eclipse using findings from Black Duck Hub.

Rating Distribution

Ease of use

5

Value for money

5

Customer Support

5

Functionality

5

MI

Marco I.

Computer Software, N/A employees

Less than 6 months

5.0
September 2017

Dashboard gives useful project-level detail

Pros

We brought in this tool to improve open source culture at our company and with our customers and it's been a strong addition. It raises awareness around legal, security and operational risks tied to open source components. One of the biggest advantages is code scanning that works regardless of language or technology and integrates well with CI/CD tools like Jenkins. The interface is clean and logical and the dashboard gives a lot of useful detail about the open source components inside a project. Vulnerability notifications are valuable and the latest versions have better remediation suggestions. Reporting is solid and customizable through the RESTful API and direct database access. Installation was convenient since we use the Docker Compose version,install Docker, download the images and run a command to set up or upgrade. Technical support and customer care have also been very reliable.

Cons

Since this is still a fairly new product even with well-known and established predecessors like Protex behind it, there are still some areas that could be improved to better match user needs. Reporting and API capabilities could be more mature and the documentation also needs some work.

Rating Distribution

Ease of use

10

Value for money

10

Customer Support

9

Functionality

10

RA

rajiv A.

, N/A employees

Less than a year

5.0
August 2017

Helps you catch hidden vulnerabilities

Pros

This tool has made tracking open source components and managing them way simpler than before. Its code inspection for vulnerabilities especially hidden ones, is outstanding. Any organization serious about source code management should consider this. It catches vulnerabilities fast, handles open source license compliance before it becomes a problem and fits right into existing CI pipelines to speed up time to market. Spotting security exposures and hidden vulnerabilities from open source components is much easier now and catching them early in development accelerates everything. Open source license management is far more manageable. The product is already impressive and the Hub knowledge base is extensive and growing every day.

Cons

Reporting could be improved and the API experience needs to be better. Black Duck is still evolving quickly so I'd also like to see the knowledge bases updated faster.

Rating Distribution

Ease of use

10

Value for money

9

Customer Support

10

Functionality

8

CS

Christian S.

, N/A employees

Less than a year

4.0
August 2017

Easy connections to ticketing systems

Pros

Connecting it with other services, like ticketing systems and similar tools, is pretty direct. It also makes it simple to pull up extra details on the vulnerabilities it detects which is very useful.

Cons

One area that still feels unclear is the third category, operational risks and support first advised me to just ignore it. I'm also still not fully sure how the rating is calculated even though it seems like it could be valuable.

Rating Distribution

Ease of use

7

Value for money

7

Customer Support

9

Functionality

9

VK

Viren K.

Banking, N/A employees

Less than 6 months

5.0
August 2017

Scans thoroughly and builds clean bills of materials

Pros

Black Duck has really set the standard for open source software governance. It lets us scan our codebase thoroughly and build a clean bill of materials that includes all OSS components which has been very valuable.

Cons

It is on par with other open source governance platforms overall. Of course, there are a few features that competing tools handle better but Black Duck's development team has been responsive and open to enhancement requests.

Rating Distribution

Ease of use

10

Value for money

10

Customer Support

9

Functionality

9

FF

Frank F.

Music, N/A employees

Less than 6 months

4.0
August 2017

Runs reliably without complex maintenance

Pros

It works reliably without being overly complicated to maintain and the company is very quick to respond whenever the tool reports false positives.

Cons

A few upgrades didn't go as expected. Also some of the details most IT teams typically need seem to be missing from the documentation. It would also be better if group roles, such as Policy Manager, could be assigned per project instead of only across the entire site.

Rating Distribution

Ease of use

9

Value for money

8

Customer Support

8

Functionality

9

MG

Max G.

, N/A employees

Less than 6 months

3.0
August 2017

decent enough

Pros

Fast turnaround is one of its strong points. I also appreciate being able to drill down into results at the file level.

Cons

Getting it implemented is quite difficult and the Python support seems to be geared more toward libraries than actual applications.

Rating Distribution

Ease of use

5

Value for money

5

Customer Support

3

Functionality

7

NG

Naveen G.

Financial Services, N/A employees

More than a year

2.0
August 2017

certificate troubles hold you back

Pros

Since upgrading to HUB4.0, the software responds faster which is a noticeable improvement but there are still many issues related to certificates.

Cons

Manual scanning does not work on Linux servers.

Rating Distribution

Ease of use

3

Value for money

3

Customer Support

5

Functionality

3

TO

Tunde O.

Information Technology and Services, N/A employees

More than a year

5.0
July 2017

Security Coverage like no other.

Pros

Having security, license risk management and operational risk handled in one place is a major benefit. Black Duck covers all three core areas of open source security management really well and in a clean way. The scan speed is another big plus since it helps build a strong case very quickly. I also appreciate that it can be deployed on-premise which lets a company keep its source code in-house instead of having to expose it like with some other tools.

Cons

Pricing tied to the size of the code base being monitored is a bit of a drawback. It would be better if the solution offered project-based pricing or maybe a model based on the number of lines of code. Even with that, it is still a fantastic tool.

Rating Distribution

Ease of use

9

Value for money

8

Customer Support

9

Functionality

9

MF

Mike F.

Financial Services, N/A employees

Less than a year

4.0
July 2017

Automated scans with email failure alerts

Pros

We have it configured to run scans automatically with Bamboo handling the scheduling. We also tied in the Hub APIs to send failure emails to users which helps developers quickly see where the problems are.

Cons

Setting up repositories differently for internal code versus externally facing code is still something we haven't been able to do on our own without getting assistance.

Rating Distribution

Ease of use

8

Value for money

8

Customer Support

7

Functionality

7

LF

Ludmila F.

Information Technology and Services, N/A employees

Less than 6 months

4.0
July 2017

auto-detection handes most of the work

Pros

Automatic identification of open source software handles most of the work which is really helpful. After the initial scan though, more than 800 open source components were still not identified so I had to go through and classify them manually.

Cons

Changing the license and version currently requires going through different links. It would be much better to have a single place where all needed changes can be made.

Rating Distribution

Ease of use

9

Value for money

8

Customer Support

7

Functionality

9

PP

Phutthipong P.

Mechanical or Industrial Engineering, N/A employees

Less than 6 months

4.0
July 2017

Saves time checking open source code

Pros

Helps me save a lot of time when checking open source software and points out parts of the source code that match open source components.

Cons

The pricing is very high especially since it is charged as a yearly subscription instead of a one-time software license. In my embedded systems work, our codebase is very small, under 100 kB but Black Duck Protex is sold with a 1 GB minimum which makes the cost feel unnecessarily expensive.

Rating Distribution

Ease of use

7

Value for money

7

Customer Support

7

Functionality

9

ES

Ed S.

, N/A employees

Less than 6 months

5.0
July 2017

Dependency details with direct CVE links

Pros

Seeing detailed dependency information at a glance is incredibly useful and being able to follow the breadcrumbs directly to CVE reports makes the whole process even better.

Cons

Working with the REST API is extremely difficult and really needs to be more user-friendly. I'd like to simply get an API token and use it for calls but instead I have to scrape the JSESSIONCOOKIE ID and rely on that which takes far too much effort.

Rating Distribution

Ease of use

8

Value for money

10

Customer Support

10

Functionality

10

FD

Franklin D.

Computer Software, N/A employees

More than a year

4.0
July 2017

Quick scans and a responsive interface

Pros

The new Hub product stands out for how quickly it scans software and the interface feels responsive while also looking polished. The Black Duck team has also been quick to respond when problems come up and they've actually implemented some of the improvements we asked for.

Cons

There's no history for comments or edits and updates made in one version of a project don't transfer well to other versions or to other projects using the same components. Getting around the product can also be frustrating as there are often too many clicks to reach a related view and when you go back, the scroll position is gone so you have to remember where you left off and click through pages again. It feels pretty clunky.

Rating Distribution

Ease of use

9

Value for money

7

Customer Support

8

Functionality

9

PT

Pete T.

Banking, N/A employees

Less than a year

3.0
July 2017

A solid scanning tool

Pros

This product does a really good job identifying open-source vulnerabilities in our codebase. The pre-sales team was helpful during the demo and trial, the interface is clean and performance improved noticeably in version 4.0.0.

Cons

Getting it installed was challenging and version 4.0.0 made that even more involved with the move to Docker and the requirement for an SSL/TLS web server certificate which led to extra troubleshooting around trust issues. Support has been frustrating as well since they seem hesitant to get on the phone and mostly rely on occasional email replies. The documentation also has some holes. I'm still surprised there isn't a prebuilt Black Duck Hub virtual appliance ready to deploy into VMware and there's no guidance for using it with vSphere Integrated Containers, only Docker and Openshift. Reporting also still needs further improvement.

Rating Distribution

Ease of use

5

Value for money

6

Customer Support

5

Functionality

4

TJ

Torsten J.

Automotive, N/A employees

Less than 6 months

4.0
July 2017

Automations and reports save a lot of time

Pros

All the automations are really useful and the knowledge base is extensive. Automatic reports are another big plus. I also appreciate having both the modern and classic views available, along with the ability to search and compare source code without much effort.

Cons

Usability is unfortunately more complicated than it should be. In some situations, such as resolving license conflicts, it is not very clear how to proceed. It would help a lot if the detailed workflow steps for running an analysis were explained more clearly.

Rating Distribution

Ease of use

7

Value for money

8

Customer Support

7

Functionality

9