Development and DevOps Integrations

Shipping secure, high-quality software at the speeds required by CI/CD pipelines and AI-generated coding is not possible when AppSec is tacked on to the end of development cycles—at least not without some concessions. That's why Black Duck DevOps integrations and security plug-ins are designed to establish reliable, automated mechanisms to detect and remedy security and compliance risks within complex tech stacks in ways that uphold developers’ need for speed and security’s need for coverage.

Black Duck’s suite of out-of-the-box DevOps integrations, plug-ins, and templates help enterprises to achieve three critical benefits.

Automate risk detection

Test everything as quickly as possible. Trigger application security tests—like SAST and SCA—based on pipeline events including build, SCM check-in, preproduction unit testing, and more.

Accelerate triage and remediation

Align development and security to fix issues faster. Enforce risk tolerance policies, establish security gates, and provide clear fix guidance to developers within the tools and workflows they already use.

Boost developer productivity

Let developers—and their AI assistants—work quickly. Deliver real-time risk insight and noncompliance alerts to avoid late-stage rework. Empower developers to focus on innovation without losing control over security.

By integrating Black Duck AppSec testing solutions into the SDLC and CI/CD pipelines, you establish closed-loop systems between security and development teams that ensure consistent visibility, optimize efficiency, and greatly reduce the window of opportunity for an attack.

  • SCM
  • IDE
  • Package
    manager
  • Build
    and CI
  • Binary
    repository
  • Workflow and
    notifications
  • Security
    testing
  • Vulnerability
    management
  • Production
    deployment
  • Black Duck
  • Coverity
  • Software Risk Manager
  • Code Sight
  • Polaris
  • Seeker

Source code management (SCM) integrations

Integrated development environment (IDE) integrations

Android Studio

Android Studio

coverity

PhpStorm

PhpStorm

code sight coverity

PyCharm

PyCharm

code sight coverity

IBM Engineering Workflow Management

IBM

coverity

QNX Momentics Tool Suite

QNX Momentics Tool Suite

coverity

WebStorm

WebStorm

code sight coverity

RubyMine

RubyMine

code sight coverity

Package manager integrations

Composer

Composer

black duck

Go Module CLI

Go Module CLI

black duck

Yarn

Yarn

coverity black duck

Bower

Bower

coverity

Comprehensive Perl Archive Network (CPAN)

CPAN

black duck

Go Vndr

Go Vndr

black duck

Poetry

Poetry

black duck

Cargo

Cargo

black duck

Gogradle

Gogradle

black duck

Rebar3

Rebar3

black duck

CocoaPods

CocoaPods

black duck

Conda

Conda

black duck

Lerna

Lerna

black duck

Packrat

Packrat

black duck

RubyGems

RubyGems

black duck

Build and CI integrations

AWS CodeBuild

AWS CodeBuild

black duck

CircleCI

CircleCI

black duck

SBT

sbt

black duck

Jenkins (commercial)

CloudBees

black duck

TeamCity

TeamCity

software risk manager black duck

CodeShip

CodeShip

black duck

Travis CI

Travis CI

black duck

Bamboo

Bamboo

tinfoil coverity black duck

Concourse

Concourse

black duck

Wind River Workbench

Wind River Studio

coverity

Binary repository integrations

Amazon Elastic Container Registry

Amazon ECR

black duck

Google Container Registry

Google

black duck

Nexus Repository

Nexus Repository

black duck

Azure Container Registry

Azure

black duck

Workflow and notifications integrations

Azure Boards

Azure Boards

black duck

Secure Code Warrior

Secure Code Warrior

software risk manager coverity seeker

Bugzilla

Bugzilla

coverity

Slack

Slack

black duck seeker software risk manager

Software Package Data Exchange (SPDX)

SPDX

black duck

Microsoft Teams

Microsoft Teams

black duck software risk manager

Security testing integrations

Acunetix

Acunetix

software risk manager

Acunetix

Aqua

software risk manager

Acunetix

CxIAST

software risk manager

Acunetix

Clang

software risk manager

Acunetix

Contrast Assess

software risk manager

Acunetix

Errcheck

software risk manager

Acunetix

Fortify

software risk manager

Acunetix

Gendarme

software risk manager

Acunetix

HCL AppScan

software risk manager

Acunetix

JSHint

software risk manager coverity

Acunetix

Netsparker

software risk manager

Acunetix

NowSecure INTEL

software risk manager

Acunetix

Parasoft C/C++test

software risk manager

Acunetix

PHP_CodeSniffer

software risk manager

Acunetix

Qualys Vulnerability Management (VM)

software risk manager

Acunetix

Scalastyle

software risk manager

Acunetix

Snyk Container

software risk manager

Acunetix

Staticcheck

software risk manager

Acunetix

Trustwave App Scanner

software risk manager

Acunetix

Veracode Static Analysis

software risk manager

Acunetix

WhiteSource

software risk manager

Acunetix

Anchore Enterprise

software risk manager

Acunetix

Arachni

software risk manager

Acunetix

CxSCA

software risk manager

Acunetix

Code Cracker

software risk manager

Acunetix

Cppcheck

software risk manager

Acunetix

Error Prone

software risk manager

Acunetix

Fortify

software risk manager

Acunetix

Gocyclo

software risk manager

Acunetix

Ineffassign

software risk manager

Acunetix

Microsoft

software risk manager

Acunetix

Nexus Lifecycle

software risk manager

Acunetix

Parasoft dotTEST

software risk manager

Acunetix

software risk manager

Acunetix

Qualys Web Application Scanning (WAS)

software risk manager

Acunetix

SD Elements

software risk manager

Acunetix

Snyk Open Source

software risk manager

Acunetix

Tenable.io

software risk manager

Acunetix

Veracode Dynamic Analysis

software risk manager

Acunetix

Vet

software risk manager

Acunetix

Android Studio Lint

software risk manager

Acunetix

Brakeman

software risk manager

Acunetix

CxSAST

software risk manager

Acunetix

CodePeer

software risk manager

Acunetix

Dependency-Check

software risk manager

Acunetix

ESLint

software risk manager

Acunetix

Fortify WebInspect

software risk manager

Acunetix

Golint

software risk manager

Acunetix

JFrog Xray

software risk manager

Acunetix

Mobile Secure

software risk manager

Acunetix

Nmap

software risk manager

Acunetix

OCLint

software risk manager

Acunetix

Parasoft Jtest

software risk manager

Acunetix

Prisma Cloud

software risk manager

Acunetix

Retire.js

software risk manager

Acunetix

Security Code Scan

software risk manager

Acunetix

Snyk Open Source License Compliance Management

software risk manager

Acunetix

Tenable.sc

software risk manager

Acunetix

Veracode Manual Penetration Testing (MPT)

software risk manager

Acunetix

Vex

software risk manager

Cycode

Cycode

black duck coverity

Acunetix

Visual Studio Code Analysis

software risk manager coverity

AppSecAI Expert Triage Automation

AppSecAI Expert Triage Automation 

coverity

Acunetix

AppSpider

software risk manager

Burp Suite Logo

Burp Suite Enterprise Edition

software risk manager

Burp Suite Logo

Burp Suite Professional

software risk manager

Acunetix

Checkstyle

software risk manager

Acunetix

CodeSonar

software risk manager

Acunetix

Dependency-Track

software risk manager

Acunetix

Find Security Bugs

software risk manager

Acunetix

software risk manager

Acunetix

Gosec

software risk manager

Acunetix

Jlint

software risk manager

Acunetix

Nessus

software risk manager

Acunetix

NowSecure Auto

software risk manager

Acunetix

OWASP ZAP

software risk manager

Acunetix

PHP Mess Detector

software risk manager

Acunetix

Pylint

software risk manager

Acunetix

SafeSQL

software risk manager

Acunetix

SpotBugs

software risk manager coverity

Acunetix

sqlmap

software risk manager

Acunetix

ThunderScan

software risk manager

Acunetix

Veracode Software Composition Analysis (SCA)

software risk manager

VigilantOp

Vigilant Ops

black duck

Vulnerability management integrations

Acunetix

Deepfactor Developer Security

black duck

Production deployment integrations

Amazon Web Services (AWS)

Amazon Web Services (AWS)

seeker

Cloud Foundry

Cloud Foundry

seeker

Microsoft Azure

Microsoft Azure

black duck

IBM Cloud Pak for Applications

IBM Cloud Pak for Applications

black duck

VMware Tanzu

VMware Tanzu

seeker