“Our customers are some of the most well-known companies in the technology industry, and their combined expectations, and the critical nature of the software that we provide for key management systems and hardware security modules, means that we must use every possible tool that is available to improve code quality, security, and stability.”
"Having a tool that lets us look at our code and look at what issues could be introduced enables us to be a lot more informed and have a higher degree of confidence that when we release software we’re not introducing additional risks."
“We would recommend Synopsys as a provider of a comprehensive set of holistic, complementary AppSec solutions, backed by a pool of sharp consultants who understand globally the industries they work with, as well as an organization’s unique processes. For a B2B global organization like MEGA, it’s a must.”
"SFR chose Seeker to help prevent code vulnerabilities of web applications and obtain real-time results for quick remediation."
Black Duck has helped us understand our overall security status, and find and fill security holes."
"Black Duck security experts have been highly responsive and provide us with high-quality subject matter expertise that helps us remediate and mitigate vulnerabilities accurately and efficiently."
“We have over a hundred products, with each of those products themselves having hundreds to thousands of different open source components. A decade ago, we had little concept of identifying and understanding open source security vulnerabilities in our BOM. The move to Black Duck was to address our not knowing about open source security issues. We recognized that we needed a solution to ensure we were tracking and managing open source and commercial components as part of our overall software security initiative.”
“All of our core products are using Code Center. About three years ago, we began to use Black Duck SCA when building the CI/CD process for our JDA Luminate product line, newly developed, SaaS-native products. Our goal is full migration to Black Duck SCA by the beginning of 2020.”
“Identifying open source components and the different licensing types associated with the underlying source code was vital so that we could understand what risks and obligations potentially existed for us.”
“With the Black Duck Suite we found the right solution to execute our open source governance policy by providing a scalable and transparent approval process.”
“With the continuously increasing importance of open source software globally and SAP’s strategy to utilize the benefits that come with open source software, it was necessary for us to scale our open source-related processes through further automation. We conducted an exhaustive search of applications on the market, and the Black Duck Suite was the best solution we tested. The Black Duck Suite will help us further automate and scale our open source processes in order to support our open source software strategy.”
"Coverity is a cornerstone in building secure C code as part of our security development lifecycle."
"We really want to push the envelope of security. Working with Synopsys helped us move closer to that goal."
We took the path of looking into tools to improve code quality and security as early as possible in the development lifecycle."
“Project managers can set policies for any given project and open Hub to get a full report on open source in use.”