“It is very important to understand each team’s skills and take a down-to-earth approach. For example, sales and those who are not acquainted with software may not even understand what open source is, so it has to be explained. It is also very important not to just end up emphasizing risks, because that can discourage the use of OSS. While developer support is essential, if you can also involve marketing, sales, and call center agents in training activities, you can propel OSS governance.”
"Black Duck has become a standard part of our due diligence when we buy a software company."
“Implementing Black Duck has given us a single tool to manage and mitigate vulnerabilities, allowing our development, operations, and security teams to see the status of our deployments, The product is easy and straightforward to use, and we’d recommend Black Duck to anyone looking into an SCA solution.”
“Black Duck confirmed our third-party software validation practices. Softegrity SpA, a Synopsys Software Integrity reseller partner, helped to support the relationship between Dextra Technology and Black Duck for this process. With Black Duck and Softegrity, we have partners that we can use to continue strengthening our internal toolchain so that we maintain a high standard of source quality, avoiding potential risks.”
We took the path of looking into tools to improve code quality and security as early as possible in the development lifecycle."
"We connected with Black Duck several months before our IPO because our investors, our board and our management team felt it was important – critical, in fact – to understand the health of our source code in terms of security, quality and licensing."
"Automating the search and selection of OSS with Black Duck gives us the tools we need to put customers at ease."
Black Duck has helped us understand our overall security status, and find and fill security holes."
At day’s end, we have assurance that there’s no red flags or potential issues—that’s the value of Black Duck audits."
“We click one button to set up a CI plan, and it pulls in everything from Black Duck, Defensics, Coverity, and our other security analysis tools, and they automatically get plugged in and start generating reports and scans, and if a bug needs to be fixed, it gets into our bug management system right away.”
"Avira believes security is a right, not a privilege."
“From being concerned that Coverity would slow development or flood us with false positives, we think of Coverity as if it were a member of the software team.”
"Black Duck security experts have been highly responsive and provide us with high-quality subject matter expertise that helps us remediate and mitigate vulnerabilities accurately and efficiently."
"We use open source software in nearly everything we do because it helps us produce higher quality software, better and faster."
“The Black Duck Hub allows us to catch security vulnerabilities before our code goes out to clients.”