Gaurav P.
Medical Devices, N/A employees
More than a year
“Great for pipeline security”
Pros
Getting it integrated is painless. You can drop Black Duck into CI/CD pipelines and shift security left in the SDLC which bolsters security across the board.
Cons
Reporting still has room for improvement. Embargo vulnerabilities especially potential ones, are not updated with CVE scores as quickly or as easily as they should be.
Rating Distribution
Ease of use
10
Value for money
9
Customer Support
10
Functionality
8
Sam W.
Airlines/Aviation, N/A employees
More than a year
“Unmatched security coverage”
Pros
It gives you outstanding visibility into software security and the coverage is excellent. In my opinion, it's the best option out there especially since you can integrate it at scale without much trouble.
Cons
The on-premise deployment can be very challenging to get up and running. It involves downloading massive amounts of data which takes a lot of bandwidth, plus significant processing to unpack everything and complete the setup. A cloud-based option may be worth considering.
Rating Distribution
Ease of use
10
Value for money
10
Customer Support
10
Functionality
10
Sharique K.
Hospital & Health Care, N/A employees
More than a year
“Simple maintainence and regular updated”
Pros
Keeping the vulnerability list current is one of this tool's biggest strengths. Maintenance and administration are easy to manage and integrating it with different CI/CD toolsets is effortless which really supports strong DevSecOps practices.
Cons
If there's any challenge at all, it's more about DevSecOps still being relatively new overall so developers and engineers need time to become more familiar with these security concepts.
Rating Distribution
Ease of use
9
Value for money
10
Customer Support
10
Functionality
10
Anonymous
Information Technology and Services, N/A employees
More than a year
“detection accuracy is so reliable”
Pros
The range of integration options fits pretty much any CI/CD setup you want to use. IDE integrations are simple to roll out so you're not boxed into a single approach if your DevOps team prefers specific technologies. Accuracy and detection capabilities have been very reliable and feel quite strong.
Cons
There is not much I can point to as a real downside. At first, the lack of code snippets felt like a missing piece but that has since been addressed which makes the solution more capable and improves the overall user experience.
Rating Distribution
Ease of use
10
Value for money
10
Customer Support
10
Functionality
10
Benjamin P.
Information Technology and Services, N/A employees
Less than 6 months
“Pipleline Integration is a good thing”
Pros
We installed and connected it with Bamboo and that has worked well for our pipeline workflow and the follow-up analysis of findings.
Cons
Black Duck promoted Gradle support through an Eclipse integration but in practice it only worked with a very basic Gradle project setup. More recently (11-8-2017), Black Duck told us in a response not to use the Eclipse plugin. That is a major problem for our DevOps process since we need developers to be able to identify issues locally in Eclipse using findings from Black Duck Hub.
Rating Distribution
Ease of use
5
Value for money
5
Customer Support
5
Functionality
5
Marco I.
Computer Software, N/A employees
Less than 6 months
“Dashboard gives useful project-level detail”
Pros
We brought in this tool to improve open source culture at our company and with our customers and it's been a strong addition. It raises awareness around legal, security and operational risks tied to open source components. One of the biggest advantages is code scanning that works regardless of language or technology and integrates well with CI/CD tools like Jenkins. The interface is clean and logical and the dashboard gives a lot of useful detail about the open source components inside a project. Vulnerability notifications are valuable and the latest versions have better remediation suggestions. Reporting is solid and customizable through the RESTful API and direct database access. Installation was convenient since we use the Docker Compose version,install Docker, download the images and run a command to set up or upgrade. Technical support and customer care have also been very reliable.
Cons
Since this is still a fairly new product even with well-known and established predecessors like Protex behind it, there are still some areas that could be improved to better match user needs. Reporting and API capabilities could be more mature and the documentation also needs some work.
Rating Distribution
Ease of use
10
Value for money
10
Customer Support
9
Functionality
10
rajiv A.
, N/A employees
Less than a year
“Helps you catch hidden vulnerabilities”
Pros
This tool has made tracking open source components and managing them way simpler than before. Its code inspection for vulnerabilities especially hidden ones, is outstanding. Any organization serious about source code management should consider this. It catches vulnerabilities fast, handles open source license compliance before it becomes a problem and fits right into existing CI pipelines to speed up time to market. Spotting security exposures and hidden vulnerabilities from open source components is much easier now and catching them early in development accelerates everything. Open source license management is far more manageable. The product is already impressive and the Hub knowledge base is extensive and growing every day.
Cons
Reporting could be improved and the API experience needs to be better. Black Duck is still evolving quickly so I'd also like to see the knowledge bases updated faster.
Rating Distribution
Ease of use
10
Value for money
9
Customer Support
10
Functionality
8
Christian S.
, N/A employees
Less than a year
“Easy connections to ticketing systems”
Pros
Connecting it with other services, like ticketing systems and similar tools, is pretty direct. It also makes it simple to pull up extra details on the vulnerabilities it detects which is very useful.
Cons
One area that still feels unclear is the third category, operational risks and support first advised me to just ignore it. I'm also still not fully sure how the rating is calculated even though it seems like it could be valuable.
Rating Distribution
Ease of use
7
Value for money
7
Customer Support
9
Functionality
9
Viren K.
Banking, N/A employees
Less than 6 months
“Scans thoroughly and builds clean bills of materials”
Pros
Black Duck has really set the standard for open source software governance. It lets us scan our codebase thoroughly and build a clean bill of materials that includes all OSS components which has been very valuable.
Cons
It is on par with other open source governance platforms overall. Of course, there are a few features that competing tools handle better but Black Duck's development team has been responsive and open to enhancement requests.
Rating Distribution
Ease of use
10
Value for money
10
Customer Support
9
Functionality
9
Frank F.
Music, N/A employees
Less than 6 months
“Runs reliably without complex maintenance”
Pros
It works reliably without being overly complicated to maintain and the company is very quick to respond whenever the tool reports false positives.
Cons
A few upgrades didn't go as expected. Also some of the details most IT teams typically need seem to be missing from the documentation. It would also be better if group roles, such as Policy Manager, could be assigned per project instead of only across the entire site.
Rating Distribution
Ease of use
9
Value for money
8
Customer Support
8
Functionality
9
Max G.
, N/A employees
Less than 6 months
“decent enough”
Pros
Fast turnaround is one of its strong points. I also appreciate being able to drill down into results at the file level.
Cons
Getting it implemented is quite difficult and the Python support seems to be geared more toward libraries than actual applications.
Rating Distribution
Ease of use
5
Value for money
5
Customer Support
3
Functionality
7
Naveen G.
Financial Services, N/A employees
More than a year
“certificate troubles hold you back”
Pros
Since upgrading to HUB4.0, the software responds faster which is a noticeable improvement but there are still many issues related to certificates.
Cons
Manual scanning does not work on Linux servers.
Rating Distribution
Ease of use
3
Value for money
3
Customer Support
5
Functionality
3
Tunde O.
Information Technology and Services, N/A employees
More than a year
“Security Coverage like no other.”
Pros
Having security, license risk management and operational risk handled in one place is a major benefit. Black Duck covers all three core areas of open source security management really well and in a clean way. The scan speed is another big plus since it helps build a strong case very quickly. I also appreciate that it can be deployed on-premise which lets a company keep its source code in-house instead of having to expose it like with some other tools.
Cons
Pricing tied to the size of the code base being monitored is a bit of a drawback. It would be better if the solution offered project-based pricing or maybe a model based on the number of lines of code. Even with that, it is still a fantastic tool.
Rating Distribution
Ease of use
9
Value for money
8
Customer Support
9
Functionality
9
Mike F.
Financial Services, N/A employees
Less than a year
“Automated scans with email failure alerts”
Pros
We have it configured to run scans automatically with Bamboo handling the scheduling. We also tied in the Hub APIs to send failure emails to users which helps developers quickly see where the problems are.
Cons
Setting up repositories differently for internal code versus externally facing code is still something we haven't been able to do on our own without getting assistance.
Rating Distribution
Ease of use
8
Value for money
8
Customer Support
7
Functionality
7
Ludmila F.
Information Technology and Services, N/A employees
Less than 6 months
“auto-detection handes most of the work”
Pros
Automatic identification of open source software handles most of the work which is really helpful. After the initial scan though, more than 800 open source components were still not identified so I had to go through and classify them manually.
Cons
Changing the license and version currently requires going through different links. It would be much better to have a single place where all needed changes can be made.
Rating Distribution
Ease of use
9
Value for money
8
Customer Support
7
Functionality
9
Phutthipong P.
Mechanical or Industrial Engineering, N/A employees
Less than 6 months
“Saves time checking open source code”
Pros
Helps me save a lot of time when checking open source software and points out parts of the source code that match open source components.
Cons
The pricing is very high especially since it is charged as a yearly subscription instead of a one-time software license. In my embedded systems work, our codebase is very small, under 100 kB but Black Duck Protex is sold with a 1 GB minimum which makes the cost feel unnecessarily expensive.
Rating Distribution
Ease of use
7
Value for money
7
Customer Support
7
Functionality
9
Ed S.
, N/A employees
Less than 6 months
“Dependency details with direct CVE links”
Pros
Seeing detailed dependency information at a glance is incredibly useful and being able to follow the breadcrumbs directly to CVE reports makes the whole process even better.
Cons
Working with the REST API is extremely difficult and really needs to be more user-friendly. I'd like to simply get an API token and use it for calls but instead I have to scrape the JSESSIONCOOKIE ID and rely on that which takes far too much effort.
Rating Distribution
Ease of use
8
Value for money
10
Customer Support
10
Functionality
10
Franklin D.
Computer Software, N/A employees
More than a year
“Quick scans and a responsive interface”
Pros
The new Hub product stands out for how quickly it scans software and the interface feels responsive while also looking polished. The Black Duck team has also been quick to respond when problems come up and they've actually implemented some of the improvements we asked for.
Cons
There's no history for comments or edits and updates made in one version of a project don't transfer well to other versions or to other projects using the same components. Getting around the product can also be frustrating as there are often too many clicks to reach a related view and when you go back, the scroll position is gone so you have to remember where you left off and click through pages again. It feels pretty clunky.
Rating Distribution
Ease of use
9
Value for money
7
Customer Support
8
Functionality
9
Pete T.
Banking, N/A employees
Less than a year
“A solid scanning tool”
Pros
This product does a really good job identifying open-source vulnerabilities in our codebase. The pre-sales team was helpful during the demo and trial, the interface is clean and performance improved noticeably in version 4.0.0.
Cons
Getting it installed was challenging and version 4.0.0 made that even more involved with the move to Docker and the requirement for an SSL/TLS web server certificate which led to extra troubleshooting around trust issues. Support has been frustrating as well since they seem hesitant to get on the phone and mostly rely on occasional email replies. The documentation also has some holes. I'm still surprised there isn't a prebuilt Black Duck Hub virtual appliance ready to deploy into VMware and there's no guidance for using it with vSphere Integrated Containers, only Docker and Openshift. Reporting also still needs further improvement.
Rating Distribution
Ease of use
5
Value for money
6
Customer Support
5
Functionality
4
Torsten J.
Automotive, N/A employees
Less than 6 months
“Automations and reports save a lot of time”
Pros
All the automations are really useful and the knowledge base is extensive. Automatic reports are another big plus. I also appreciate having both the modern and classic views available, along with the ability to search and compare source code without much effort.
Cons
Usability is unfortunately more complicated than it should be. In some situations, such as resolving license conflicts, it is not very clear how to proceed. It would help a lot if the detailed workflow steps for running an analysis were explained more clearly.
Rating Distribution
Ease of use
7
Value for money
8
Customer Support
7
Functionality
9