Automate risk detection
Accelerate triage and remediation
Boost developer productivity
The Code Sight IDE plug-in integrates SAST and SCA scans into the developer IDE, enabling developers to identify and fix vulnerabilities before committing code, saving time and improving code quality.
Eclipse
IntelliJ IDEA
Visual Studio
Android Studio
Cursor
IBM
PhpStorm
PyCharm
RubyMine
QNX Momentics Tool Suite
Visual Studio Code
WebStorm
Windsurf
Wind River
Black Duck's security tools integrate with leading source code management solutions to enable rapid scans on every pull or merge request to provide quick results and prevent issues from impacting other teams.
GitHub
GitLab
Bitbucket
Azure DevOps
Black Duck’s security tools integrate with leading build and CI tools to add security into CI/CD pipelines. Security teams can enforce policies by integrating scan results into quality gates, enabling them to break builds if violations occur.
GitHub Actions
GitLab CI
Jenkins
AWS CodeBuild
Azure DevOps
Bamboo
Bitbucket Pipelines
CircleCI
CloudBees
CodeShip
Concourse
Gradle
sbt
TeamCity
Travis CI
Wind River Studio
Black Duck works with package management tools to identify open source and third-party components in applications to help manage security, license, and component quality risks associated with dependencies.
Maven
Gogradle
npm
Apache Ivy
Bazel
BitBake
Bower
Cargo
CocoaPods
Composer
Conan
Conda
CPAN
CRAN
Dart
Erlang
Git
Go Dep
Go Module CLI
Go Modules
Go Vendor
Go Vndr
Gradle
Hex
Lerna
NuGet
Packagist
Packrat
PEAR
Pip
Pnpm
Poetry
Rebar
Rebar3
RubyGems
sbt
Swift and Xcode
Yarn
Yocto Project (YP)
Black Duck integrates with binary repositories to host approved open source packages and store build artifacts to help developers identify source code and open source dependency violations to ensure code quality and compliance.
Artifactory
Nexus Repository
Amazon ECR
Azure
Docker Registry
Google Container Registry
Black Duck integrates with popular notification and workflow management tools to flag vulnerabilities and send issues to downstream teams for resolution.
Jira Software
Secure Code Warrior
Slack
Azure DevOps
Bugzilla
CycloneDX
GitHub Issues
Microsoft Teams
SPDX
Black Duck offers an open platform that can integrate with several third-party security testing tools, enabling organizations to consolidate SAST, SCA, DAST, Infrasec, CNAPP, IaC, and pen testing in one place.
Click here for a full list of our supported integrations.
Checkmarx
Snyk
Veracode
Acunetix
Anchore Enterprise
Android Studio Lint
AppSecAI Expert Triage Automation
AppSpider
Aqua
Arachni
Black Duck Binary Analysis
Brakeman
Burp Suite
Checkstyle
Clang
Clippy
Code Cracker
CodePeer
CodeSonar
CoGuard - Infrastructure Security and Automation
Contrast Assess
Coverity
Cppcheck
Cycode
DefenseCode ThunderScan
Dependency-Check
Dependency-Check (SCA)
Dependency-Track
Errcheck
Error Prone
ESLint
Find Security Bugs
Fortify
FxCop
Gendarme
GitLab Security
Go Vet
Gocyclo
GoLint
GoSec
HCL AppScan on Cloud
HCL AppScan Source
Helix QAC
Ineffassign
IriusRisk Threat Modeling
JFrog Xray
Jlint
JSHint
Microsoft
Microsoft Code Analysis
Mobile Secure
MobSF
MobSF Scan
NDepend
Nessus
Netsparker
Nexus Lifecycle
Nmap
NowSecure
OCLint
OWASP ZAP
Parasoft JTest / C++Test / dotTest
PHPMD
PHP_CodeSniffer
PHP Mess Detector
phpcs-security-audit
PMD
Prisma Cloud
Pylint
Q-mast
Qualys
Rapid Scan SAST
Retire.js
SafeSQL
SARIF
SATE
Scalastyle
SCARF
SciTools Understand
SD Elements
Security Code Scan
Semgrep
Software Risk Manager
SonarQube Generic Issue Import Format
SpotBugs / FindBugs
sqlmap
Staticcheck
Tenable
TFLint
Thunderscan
TruffleHog
Trustwave App Scanner
Vex
Vigilant Ops
Visual Studio Code Analysis
WhiteSource
WPScan
ZPA
Black Duck solutions integrate with leading production deployment tools to enable application releases that keep pace with development velocity, scale with organizations’ software footprint, and thoroughly test for quality.
Amazon Web Services
Google Cloud
Kubernetes
Cloud Foundry
IBM Cloud Pak for Applications
Microsoft Azure
Red Hat OpenShift
VMware Tanzu