Enter Black Duck® Supply Chain Edition. This new offering provides expanded visibility, security controls, and compliance to your existing supply chain security activities. Here are some of the key capabilities.
Comprehensive open source discovery
With the majority of the software supply chain comprised of open source, failure to properly track and manage it equates to a glaring gap in any risk management strategy. Additionally, any required Software Bill of Materials (SBOM) will mandate that all OSS dependencies be listed.
With Black Duck, you can easily identify all open source components using a combination of dependency, CodePrintâ„¢, snippet, binary, and container analysis to surface every single dependency, regardless of language or package manager, so you get the most comprehensive view of OSS available.
Third-party SBOM import and analysis
Most commercial and enterprise software teams use third-party code from an outside vendor. And although security teams can perform their own analysis of these third-party artifacts, it is much easier …