Vendor Profile

Black Duck

Black Duck (a Synopsys product) is an enterprise-grade software composition analysis platform that provides deep visibility into open-source risks, license compliance, and code origin analysis. Black Duck's multi-factor open-source detection uses package managers, file-level analysis, and code snippet matching to identify open-source components even when they are not declared in manifests, making it the most thorough SCA tool for auditing software acquisitions, M&A due diligence, and regulatory compliance. Black Duck is part of Synopsys's broader application security portfolio alongside Coverity (SAST) and Polaris.

Last updated

Founded
2002
Pricing
Custom enterprise pricing (typically $40K+ annually)
Verify with vendor
Deployment
CloudSelf-Hosted
Software Composition Analysis

Key Features

+Multi-factor open-source detection (package, file, snippet)
+KnowledgeBase with 7M+ open-source components tracked
+License compliance and conflict resolution
+Code origin analysis for M&A due diligence
+Binary analysis for compiled artifacts
+Automated policy management and enforcement
+Integration with Synopsys Coverity and Polaris
+SBOM generation and export capabilities

Pros & Cons

Pros

  • +Most thorough open-source detection including undeclared and embedded components
  • +Massive KnowledgeBase tracking 7M+ open-source components and versions
  • +Gold standard for M&A software due diligence and audit
  • +Comprehensive SBOM generation for supply chain transparency
  • +Part of Synopsys ecosystem with Coverity SAST and Polaris platform

Cons

  • Significantly more expensive than Snyk with enterprise-only pricing
  • Developer experience is audit-oriented rather than developer-friendly
  • Scan performance is slower due to deep multi-factor analysis
  • Complex deployment and configuration for enterprise environments
  • Less suited for real-time developer feedback in CI/CD pipelines

Best For

Enterprises needing the deepest open-source detection including undeclared components, M&A due diligence, and regulatory compliance for software supply chain

User Reviews

No reviews yet. Be the first to share your experience!

Sources & References

  1. Black Duck — Official Website & Documentation[Vendor]
  2. Black Duck Reviews on G2[User Reviews]
  3. Black Duck Reviews on TrustRadius[User Reviews]
  4. Black Duck Reviews on PeerSpot[User Reviews]

Are you from Black Duck?

Claim this listing to update your product information, respond to reviews, and ensure accuracy.