My Certificates/Courses Documentation Join Discussions Search

Black Duck SCA Onboarding and Operational Guidance

Onboard (log in to the system, generate API tokens, create projects and versions) 



Identify what scanner(s) they need for their product (based on languages used and capabilities required (like snippet scanning, which will be needed for virtually all of the products we onboard, but for which documentation is notably weaker)) 


Get data into the platform 


Perform result review, processing the results of scans after they’ve been performed. So far, I’ve identified the following steps that need to be wrapped in a coherent document: 


Groom the BOM 


Triage Risk 


Understand and perform vulnerability management over time 

  


Integrate with CI/CD – only once scan requirements and configuration are well understood. We expect teams to first need to perform manual activities as noted above to configure the scanner, at which point it can be added to CI as needed. 


Video Courses