Live Best Practice Session: Software Composition Analysis with Black Duck
This session introduces how Black Duck helps organizations manage open source risk effectively across the software development lifecycle.
Our Live sessions are offered on Demand. Click the Let's Get Started button to find out how to get more details on this offering. Note you must be logged into the Black Duck community. More details about the session are below.
This session highlights how Black Duck helps organizations proactively manage open source risk across the software development lifecycle—turning visibility into action.
Key Takeaways
-
- Open Source Risk Is Real: Incidents like the Equifax breach underscore the need for timely detection and remediation of vulnerabilities in third-party components.
- Visibility Is Foundational: You can’t manage what you can’t see. A complete and accurate Software Bill of Materials (SBOM) is essential.
- Multi-Factor Discovery: Black Duck uses package manager introspection, file signature scanning, snippet matching, and binary analysis to uncover all open source in use—even the hidden stuff.