Skip to content
Support
  • English
    • Japanese
SAST vs. SCA: What’s the difference? Do I need both? Image
  • Products & Services
    • Products
    • Services
    • Integrations
    • col
      • PolarisIntegrated SaaS Application Security and Risk Management platform.
      • SignalNewAgentic Application Security for AI-Powered software development.
    • col
      • Coverity Static
      • Black Duck SCA
      • Continuous Dynamic
      • Seeker Interactive
      • Fuzz Testing
      • Software Risk Manager ASPM
    • Open Source & Security Audits
    • Program Strategy & Planning
    • Implementation & Deployment
    • Customer Success & Support
    • IDE
    • SCM
    • Build/CI Tools
    • Workflow
    • Cloud Deployment
    ContextAI™: The model for building secure software.
    ContextAI™: The model for building secure software.
    Learn more
  • Solutions
    • By Use Case
    • By Technology
    • By Industry
    • solution-col-1
      • AI-Generated Code
      • API Security Testing
      • Application Security Testing
      • DevSecOps
      • EU Cyber Resilience Act Compliance
      • Software Supply Chain Security
    • solution-col-2
      • Manage Enterprise AppSec Risk
      • Container Security
      • Open Source License Compliance
      • M&A Due Diligence
      • Quality and Security Standards Compliance
    • solution-col-1
      • AI AppSecNew
      • Static Analysis (SAST)
      • Dynamic Application Security Testing
    • solution-col-2
      • Application Security Posture Management (ASPM)
      • Software Composition Analysis (SCA)
      • Interactive Application Security Testing (IAST)
    • Automotive
    • Embedded Software and ISV
    • Financial Services
    • Medical Devices
    • Public Sector
    The State of AI-Powered Software Development
    The State of AI-Powered Software Development
    Read the report
    Explore All Solutions
  • Resources
    • Knowledge Hub
    • Get Support
    • Explore Resources
    • Black Duck Academy
    • Cybersecurity Research Center
    • Search Knowledge Base
    • Discussions
    • Documentation
    • Ideas
    • Support
    • AppSec Glossary
    • Case Studies
    • Blog
    • Customer Value
    • eBooks
    • Datasheets
    • Webinars
    • Research & Reports
    • White Papers
    See why Black Duck is a Leader
    See why Black Duck is a Leader
    Read the report
    View Newsroom
  • Company
    • About Us
    • Latest Updates
    • col-1
      • About Black Duck
      • Leadership
      • Newsroom
      • Blog
      • Partners
      • Customer Value
    • col-2
      • Careers
      • Contact Sales
    • Newsroom
    • Software and Application Security Blog
    • Cybersecurity Research Center
    Learn why Black Duck is a Leader for the eighth year in a row
    Learn why Black Duck is a Leader for the eighth year in a row
    Read the report
Contact sales
  • Products & Services
    Back
    • Products & Services
    • Products
      • col
        • PolarisIntegrated SaaS Application Security and Risk Management platform.
        • SignalNewAgentic Application Security for AI-Powered software development.
      • col
        • Coverity Static
        • Black Duck SCA
        • Continuous Dynamic
        • Seeker Interactive
        • Fuzz Testing
        • Software Risk Manager ASPM
    • Services
      • Open Source & Security Audits
      • Program Strategy & Planning
      • Implementation & Deployment
      • Customer Success & Support
    • Integrations
      • IDE
      • SCM
      • Build/CI Tools
      • Workflow
      • Cloud Deployment
  • Solutions
    Back
    • Solutions
    • By Use Case
      • solution-col-1
        • AI-Generated Code
        • API Security Testing
        • Application Security Testing
        • DevSecOps
        • EU Cyber Resilience Act Compliance
        • Software Supply Chain Security
      • solution-col-2
        • Manage Enterprise AppSec Risk
        • Container Security
        • Open Source License Compliance
        • M&A Due Diligence
        • Quality and Security Standards Compliance
    • By Technology
      • solution-col-1
        • AI AppSecNew
        • Static Analysis (SAST)
        • Dynamic Application Security Testing
      • solution-col-2
        • Application Security Posture Management (ASPM)
        • Software Composition Analysis (SCA)
        • Interactive Application Security Testing (IAST)
    • By Industry
      • Automotive
      • Embedded Software and ISV
      • Financial Services
      • Medical Devices
      • Public Sector
  • Resources
    Back
    • Resources
    • Knowledge Hub
      • Black Duck Academy
      • Cybersecurity Research Center
      • Search Knowledge Base
    • Get Support
      • Discussions
      • Documentation
      • Ideas
      • Support
    • Explore Resources
      • AppSec Glossary
      • Case Studies
      • Blog
      • Customer Value
      • eBooks
      • Datasheets
      • Webinars
      • Research & Reports
      • White Papers
  • Company
    Back
    • Company
    • About Us
      • col-1
        • About Black Duck
        • Leadership
        • Newsroom
        • Blog
        • Partners
        • Customer Value
      • col-2
        • Careers
        • Contact Sales
    • Latest Updates
      • Newsroom
      • Software and Application Security Blog
      • Cybersecurity Research Center
  • English
    • Japanese
Support
Contact sales
  • Home
  • Blog page

SCA

SCA

102 Stories 28 Writers
SAST vs. SCA: What’s the difference? Do I need both?
SAST vs. SCA: What’s the difference? Do I need both?
Nov 19, 2019 | 5 min read
Blue Yonder: Extending their SDLC to remediate open source issues
Blue Yonder: Extending their SDLC to remediate open source issues
Fred Bals
Nov 12, 2019 | 4 min read
Coverity release ties in well to the latest MITRE CWE Top 25
Coverity release ties in well to the latest MITRE CWE Top 25
Sep 26, 2019 | 3 min read
3 use cases where source code scanning doesn’t cut it
3 use cases where source code scanning doesn’t cut it
Shandra Gemmiti
Jul 29, 2019 | 4 min read
You’re using open source software, and you need to keep track of it
You’re using open source software, and you need to keep track of it
Taylor Armerding
Jun 12, 2019 | 6 min read
  • Prev
  • 1
  • …
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • Next

Top Writers

  • Mike McGuire
    Mike McGuire
  • Fred Bals
    Fred Bals
  • Taylor Armerding
    Taylor Armerding

Last Published

Mar 09, 2017 - Aug 19, 2026
800 District Ave. Ste 201
Burlington, MA 01803
Contact sales
  • SOLUTIONS
    • AI-generated Code
    • API Security Testing
    • Application Security Testing
    • DevSecOps
    • EU Cyber Resilience Act Compliance
    • Software Supply Chain Security
    • Manage AppSec Risk
    • Container Security
    • Open Source License Compliance
    • M&A Due Diligence
    • Quality & Security Standards Compliance
  • PRODUCTS & SERVICES
    • AppSec SaaS Platform
    • AI Application Security
    • Static Analysis (SAST)
    • Software Composition Analysis Tools
    • Interactive Analysis (IAST)
    • Dynamic Analysis (DAST)
    • Protocol Fuzzing
    • AppSec Program Services
  • RESOURCES & SUPPORT
    • Customer Value
    • Datasheets
    • Webinars
    • Demos
    • Research & Reports
    • White Papers
    • Software and Application Security Blog
    • Support
    • Documentation
    • Product Education
    • Add-On Services
  • COMPANY
    • About Black Duck
    • Newsroom
    • Careers
    • Partners
    • Customer Stories
    • Glossary
    • Office Locations
    • Sitemap
© 2026 Black Duck Software, Inc. All Rights Reserved
  • Agreements
  • Privacy
  • Security
  • Sitemap
  • Manage Email Preferences
  • Do Not Sell or Share My Information