Development and DevOps Integrations

Black Duck DevOps integrations and security plug-ins are designed to establish reliable, automated mechanisms to detect and remedy security and compliance risks within complex tech stacks in ways that uphold developers’ need for speed and security’s need for coverage.

Automate risk detection

Trigger application security tests—like SAST and SCA—based on pipeline events including build, SCM check-in, preproduction unit testing, and more.

Accelerate triage and remediation

Enforce risk tolerance policies, establish security gates, and provide clear fix guidance to developers within their existing tools and workflows.

Boost developer productivity

Deliver real-time risk insight and noncompliance alerts to avoid late-stage rework.

  • IDE
  • SCM
  • Build
    and CI
  • Package
    manager
  • Binary
    repository
  • Workflow and
    notifications
  • Security
    testing
  • Production
    deployment
  • Black Duck
  • Coverity
  • Software Risk Manager
  • Code Sight
  • Polaris
  • Seeker
Integrated development environment (IDE) integrations

The Code Sight IDE plug-in integrates SAST and SCA scans into the developer IDE, enabling developers to identify and fix vulnerabilities before committing code, saving time and improving code quality.

Eclipse

Eclipse logo

most popular

Upload binaries to Black Duck for static analysis. Review scan results from within Eclipse to remediate security findings in your apps.

IntelliJ IDEA

IntelliJ IDEA logo

most popular

Upload binaries to Black Duck for static analysis. Review scan results from within Intellij to remediate security findings in your apps.

Visual Studio

Visual Studio logo

most popular

Compile and upload apps to Black Duck for static analysis. Identify security findings, view datapath info, and get remedition guidance within Microsoft Visual Studio.


Source Code Management (SCM) integrations

Black Duck's security tools integrate with leading source code management solutions to enable rapid scans on every pull or merge request to provide quick results and prevent issues from impacting other teams.

GitHub

GitHub logo

Automate Black Duck SAST or SCA scanning of your application code from within GitHub.

GitLab logo

IntelliJ IDEA logo

Automate Black Duck SAST or SCA scanning of our application code with GitLab.

Visual Studio

Visual Studio logo

Black Duck Security Scan Pipe integrates Black Duck security testing into your Bitbucket pipeline.


Build and CI integrations

Black Duck’s security tools integrate with leading build and CI tools to add security into  CI/CD pipelines.  Security teams can enforce policies by integrating scan results into quality gates, enabling them to break builds if violations occur.

Gitlab

GitLab logo

Perform SAST or SCA scans on each new build with integration to GitLab templates.

GitHub

GitHub logo

Perform SAST or SCA scans on each new build with integration GitHub Actions.

Jenkins

Visual Studio logo

Black Duck Jenkins Plugin automates building, uploading, and scanning of application code in Jenkins pipelines.


Package manager integrations

Black Duck works with package management tools to identify open source and third-party components in applications to help manage security, license, and component quality risks associated with dependencies.

Maven

Maven logo

Integrate Black Duck Static Analysis scanning with Apache Maven into existing build processes that you use in your SDLC.

Gogradle

Gogradle logo

Black Duck Static Analysis scanning with Gogradle into existing buid processes that you use in your SDLC.

npm

npm logo

Integrate Static Analysis scanning with npm to seamlessly add static scanning into existing build processes that you use in your SDLC.


Binary repository integrations

Black Duck integrates with binary repositories to host approved open source packages and store build artifacts to help developers identify source code and open source dependency violations to ensure code quality and compliance.

Artifactory

Eclipse logo

Identify source code and open source dependency violations in Artifactory repositories.

Nexus Repository

IntelliJ IDEA logo

Scan docker images for threats with Black Duck Binary Analysis integration.

Amazon ECR

Amazon ECR logo

Streamline AppSec testing of images in Google containers.


Workflow and notifications integrations

Black Duck integrates with popular notification and workflow management tools to flag vulnerabilities and send issues to downstream teams for resolution.

Jira Software

Jira logo

The Black Duck plugin for JIRA creates issues based on vulnerabilities and issue policy violations detected by Black Duck.

Secure Code Warrior

Secure Code Warrior logo

Black Duck and Secure Code Warrior provide an integrated solution to prevent security issues at the developer desktop to accelerate time to remediation.

Slack

Slack logo

The Black Duck plugin for Slack allows you to create Slack notifications based on vulnerabilities and policy violations detected by Black Duck.


Security testing integrations

Black Duck offers an open platform that can integrate with several third-party security testing tools, enabling organizations to consolidate SAST, SCA, DAST, Infrasec, CNAPP, IaC, and pen testing in one place.

Click here for a full list of our supported integrations.

Checkmarx

Checkmarx logo

Black Duck’s ASPM solution can ingest vulnerability findings from Checkmarx into Polaris for a complete and centralized view of application risk posture across your organization.

Snyk

Snyk logo

Black Duck’s ASPM solution can ingest vulnerability findings from Snyk into Polaris for a complete and centralized view of application risk posture across your organization.

Veracode

Slack logo

Black Duck’s ASPM solution can ingest vulnerability findings from Veracode into Polaris for a complete and centralized view of application risk posture across your organization.

Checkmarx logo
Checkmarx
Snyk logo
Snyk
Veracode logo
Veracode

Production deployment integrations

Black Duck solutions integrate with leading production deployment tools to enable application releases that keep pace with development velocity, scale with organizations’ software footprint, and thoroughly test for quality.

Amazon Web Services

AWS logo

Deploy compliant code releases tested by Black Duck to the cloud with Amazon Web Services.

Google Cloud

Google Cloud logo

Deploy compliant code releases tested by Black Duck to the cloud with Google Cloud.

Kubernetes

Kubernetes logo

Deploy compliant containerized apps tested by Black Duck with Kubernetes.