About Black Duck
Black Duck is an application security vendor whose products cover static analysis, software composition analysis, dynamic testing and AI-assisted AppSec. They help security and development teams find vulnerabilities, handle open source licensing risk and harden the software supply chain.
The portfolio includes Polaris, a SaaS platform for application security and risk management; Signal, an agentic offering for AI-powered software development; Coverity for static analysis; Black Duck SCA; continuous dynamic testing; Seeker for interactive testing; fuzz testing; and Software Risk Manager for application security posture management. Services range from security audits to program planning, implementation and customer support, and integrations reach IDEs, source control, build tools and cloud deployments.
Solutions are grouped by use case, such as AI-generated code, API security testing, DevSecOps, container security, license compliance, M&A due diligence and readiness for the EU Cyber Resilience Act, and by industry including automotive, medical devices, financial services and the public sector.
Key features
- Static analysis with Coverity
- Software composition analysis for open source
- Dynamic and interactive application testing
- Fuzz testing for unknown flaws
- Application security posture management
- Open source license compliance
- Integrations with IDEs, SCM and CI tools
Good fit for
- →Automotive and medical device teams securing embedded software
- →Companies assessing open source risk during M&A
- →Teams meeting EU Cyber Resilience Act requirements
- Tags
- sca
- sast
- dast
- iast
- application-security
- open-source-compliance
- supply-chain-security
Black Duck: questions and answers
- What is Black Duck used for?
- Black Duck offers application security testing and software composition analysis tools for finding vulnerabilities and managing open source license risk. It is a good fit for automotive and medical device teams securing embedded software, companies assessing open source risk during M&A, and teams meeting EU Cyber Resilience Act requirements.
- How much does Black Duck cost?
- Black Duck doesn't publish fixed prices; pricing is quoted on request.
- Is Black Duck open source?
- No. Black Duck is proprietary (closed-source) software. Open-source alternatives to Black Duck include Semgrep, Horusec and Dependency-Track.
- Can I self-host Black Duck?
- Yes. Although Black Duck is closed source, it can be self-hosted on your own servers, and the vendor also offers a hosted version.
- What are some alternatives to Black Duck?
- Black Duck competes with Snyk, Mend and Sonatype. For open-source options, see Enlisted's ranked list of open-source Black Duck alternatives.
Open-source alternatives to Black Duck
See all
Semgrep
Security
Lightweight static analysis for many languages. Find bug variants with patterns that look
LGPL-2.1vs Snyk★ 17k
Horusec
Security
Horusec is an open source tool that improves identification of vulnerabilities in your pro
Apache-2.0vs Checkmarx★ 1.3k
Dependency-Track
Security
Dependency-Track is an intelligent Component Analysis platform that allows organizations t
Apache-2.0vs Snyk★ 4.3k
Trivy
Security
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code rep
Apache-2.0vs Snyk★ 38k
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
SonarQube
Developer Tools
Continuous Inspection
LGPL-3.0vs Codacy★ 11k
SaaS alternatives to Black Duck
See all
Snyk
Security
Developer security platform that scans code, dependencies, containers and IaC
SaaS
Mend
Security
Application security platform for software composition analysis and code scanning
SaaS
Sonatype
Security
Software supply chain security platform with Lifecycle and Firewall products
SaaSVeracode
Security
Application security testing platform covering static, dynamic and software composition
SaaS
Checkmarx
Security
Application security testing platform with SAST, SCA and API security
SaaS
Socket
Security
Supply chain security that detects risky open source packages before install
SaaS

