My Certificates/Courses Pocket Guide Documentation Join Discussions Search

Live Best Practice Session: Software Composition Analysis with Black Duck

This session introduces how Black Duck helps organizations manage open source risk effectively across the software development lifecycle.

rate limit

Code not recognized.

About this course

 

Our Live sessions are offered on Demand. Click the Let's Get Started button to find out how to get more details on this offering. Note you must be logged into the Black Duck community.  More details about the session are below. 

This session highlights how Black Duck helps organizations proactively manage open source risk across the software development lifecycle—turning visibility into action.

Key Takeaways

    • Open Source Risk Is Real: Incidents like the Equifax breach underscore the need for timely detection and remediation of vulnerabilities in third-party components.
    • Visibility Is Foundational: You can’t manage what you can’t see. A complete and accurate Software Bill of Materials (SBOM) is essential.
    • Multi-Factor Discovery: Black Duck uses package manager introspection, file signature scanning, snippet matching, and binary analysis to uncover all open source in use—even the hidden stuff.

About this course

 

Our Live sessions are offered on Demand. Click the Let's Get Started button to find out how to get more details on this offering. Note you must be logged into the Black Duck community.  More details about the session are below. 

This session highlights how Black Duck helps organizations proactively manage open source risk across the software development lifecycle—turning visibility into action.

Key Takeaways

    • Open Source Risk Is Real: Incidents like the Equifax breach underscore the need for timely detection and remediation of vulnerabilities in third-party components.
    • Visibility Is Foundational: You can’t manage what you can’t see. A complete and accurate Software Bill of Materials (SBOM) is essential.
    • Multi-Factor Discovery: Black Duck uses package manager introspection, file signature scanning, snippet matching, and binary analysis to uncover all open source in use—even the hidden stuff.