Skip to content
Support
  • English
    • Japanese
Securing the software supply chain with Black Duck Supply Chain Edition Image
  • Products & Services
    • Products
    • Services
    • Integrations
    • col
      • PolarisIntegrated SaaS Application Security and Risk Management platform.
      • SignalNewAgentic Application Security for AI-Powered software development.
    • col
      • Coverity Static
      • Black Duck SCA
      • Continuous Dynamic
      • Seeker Interactive
      • Fuzz Testing
      • Software Risk Manager ASPM
    • Open Source & Security Audits
    • Program Strategy & Planning
    • Implementation & Deployment
    • Customer Success & Support
    • IDE
    • SCM
    • Build/CI Tools
    • Workflow
    • Cloud Deployment
    ContextAI™: The model for building secure software.
    ContextAI™: The model for building secure software.
    Learn more
  • Solutions
    • By Use Case
    • By Technology
    • By Industry
    • solution-col-1
      • AI-Generated Code
      • API Security Testing
      • Application Security Testing
      • DevSecOps
      • EU Cyber Resilience Act Compliance
      • Software Supply Chain Security
    • solution-col-2
      • Manage Enterprise AppSec Risk
      • Container Security
      • Open Source License Compliance
      • M&A Due Diligence
      • Quality and Security Standards Compliance
    • solution-col-1
      • AI AppSecNew
      • Static Analysis (SAST)
      • Dynamic Application Security Testing
    • solution-col-2
      • Application Security Posture Management (ASPM)
      • Software Composition Analysis (SCA)
      • Interactive Application Security Testing (IAST)
    • Automotive
    • Embedded Software and ISV
    • Financial Services
    • Medical Devices
    • Public Sector
    The State of AI-Powered Software Development
    The State of AI-Powered Software Development
    Read the report
    Explore All Solutions
  • Resources
    • Knowledge Hub
    • Get Support
    • Explore Resources
    • Black Duck Academy
    • Cybersecurity Research Center
    • Search Knowledge Base
    • Discussions
    • Documentation
    • Ideas
    • Support
    • AppSec Glossary
    • Case Studies
    • Blog
    • Customer Value
    • eBooks
    • Datasheets
    • Webinars
    • Research & Reports
    • White Papers
    See why Black Duck is a Leader
    See why Black Duck is a Leader
    Read the report
    View Newsroom
  • Company
    • About Us
    • Latest Updates
    • col-1
      • About Black Duck
      • Leadership
      • Newsroom
      • Blog
      • Partners
      • Customer Value
    • col-2
      • Careers
      • Contact Sales
    • Newsroom
    • Software and Application Security Blog
    • Cybersecurity Research Center
    Learn why Black Duck is a Leader for the eighth year in a row
    Learn why Black Duck is a Leader for the eighth year in a row
    Read the report
Contact sales
  • Products & Services
    Back
    • Products & Services
    • Products
      • col
        • PolarisIntegrated SaaS Application Security and Risk Management platform.
        • SignalNewAgentic Application Security for AI-Powered software development.
      • col
        • Coverity Static
        • Black Duck SCA
        • Continuous Dynamic
        • Seeker Interactive
        • Fuzz Testing
        • Software Risk Manager ASPM
    • Services
      • Open Source & Security Audits
      • Program Strategy & Planning
      • Implementation & Deployment
      • Customer Success & Support
    • Integrations
      • IDE
      • SCM
      • Build/CI Tools
      • Workflow
      • Cloud Deployment
  • Solutions
    Back
    • Solutions
    • By Use Case
      • solution-col-1
        • AI-Generated Code
        • API Security Testing
        • Application Security Testing
        • DevSecOps
        • EU Cyber Resilience Act Compliance
        • Software Supply Chain Security
      • solution-col-2
        • Manage Enterprise AppSec Risk
        • Container Security
        • Open Source License Compliance
        • M&A Due Diligence
        • Quality and Security Standards Compliance
    • By Technology
      • solution-col-1
        • AI AppSecNew
        • Static Analysis (SAST)
        • Dynamic Application Security Testing
      • solution-col-2
        • Application Security Posture Management (ASPM)
        • Software Composition Analysis (SCA)
        • Interactive Application Security Testing (IAST)
    • By Industry
      • Automotive
      • Embedded Software and ISV
      • Financial Services
      • Medical Devices
      • Public Sector
  • Resources
    Back
    • Resources
    • Knowledge Hub
      • Black Duck Academy
      • Cybersecurity Research Center
      • Search Knowledge Base
    • Get Support
      • Discussions
      • Documentation
      • Ideas
      • Support
    • Explore Resources
      • AppSec Glossary
      • Case Studies
      • Blog
      • Customer Value
      • eBooks
      • Datasheets
      • Webinars
      • Research & Reports
      • White Papers
  • Company
    Back
    • Company
    • About Us
      • col-1
        • About Black Duck
        • Leadership
        • Newsroom
        • Blog
        • Partners
        • Customer Value
      • col-2
        • Careers
        • Contact Sales
    • Latest Updates
      • Newsroom
      • Software and Application Security Blog
      • Cybersecurity Research Center
  • English
    • Japanese
Support
Contact sales
  • Home
  • Blog page

SCA

SCA

102 Stories 28 Writers
Securing the software supply chain with Black Duck Supply Chain Edition
Securing the software supply chain with Black Duck Supply Chain Edition
Mike McGuire
Apr 09, 2024 | 5 min read
4 approaches to vulnerability remediation
4 approaches to vulnerability remediation
Natalie Lightner
Mar 27, 2024 | 5 min read
AppSec Decoded: Open source trends uncovered in the 2024 OSSRA report
AppSec Decoded: Open source trends uncovered in the 2024 OSSRA report
Taylor Armerding
Mar 22, 2024 | 2 min read
What is a software bill of materials?
What is a software bill of materials?
Fred Bals
Mar 17, 2024 | 6 min read
Attesting to secure software development practices
Attesting to secure software development practices
Tim Mackey
Mar 12, 2024 | 3 min read
  • Prev
  • 1
  • …
  • 4
  • 5
  • 6
  • 7
  • 8
  • …
  • 21
  • Next

Top Writers

  • Mike McGuire
    Mike McGuire
  • Fred Bals
    Fred Bals
  • Taylor Armerding
    Taylor Armerding

Last Published

Mar 09, 2017 - Aug 19, 2026
800 District Ave. Ste 201
Burlington, MA 01803
Contact sales
  • SOLUTIONS
    • AI-generated Code
    • API Security Testing
    • Application Security Testing
    • DevSecOps
    • EU Cyber Resilience Act Compliance
    • Software Supply Chain Security
    • Manage AppSec Risk
    • Container Security
    • Open Source License Compliance
    • M&A Due Diligence
    • Quality & Security Standards Compliance
  • PRODUCTS & SERVICES
    • AppSec SaaS Platform
    • AI Application Security
    • Static Analysis (SAST)
    • Software Composition Analysis Tools
    • Interactive Analysis (IAST)
    • Dynamic Analysis (DAST)
    • Protocol Fuzzing
    • AppSec Program Services
  • RESOURCES & SUPPORT
    • Customer Value
    • Datasheets
    • Webinars
    • Demos
    • Research & Reports
    • White Papers
    • Software and Application Security Blog
    • Support
    • Documentation
    • Product Education
    • Add-On Services
  • COMPANY
    • About Black Duck
    • Newsroom
    • Careers
    • Partners
    • Customer Stories
    • Glossary
    • Office Locations
    • Sitemap
© 2026 Black Duck Software, Inc. All Rights Reserved
  • Agreements
  • Privacy
  • Security
  • Sitemap
  • Manage Email Preferences
  • Do Not Sell or Share My Information