We performed a comparison between Black Duck and Fortify Static Code Analyzer based on real PeerSpot user reviews.
Find out what your peers are saying about Synopsys, Veracode, Snyk and others in Software Composition Analysis (SCA)."The solution is stable."
"The stability is okay."
"The UI is the solution's most valuable feature since it allows for easy pipeline integration."
"We didn't have a central inventory to quickly identify issues or determine how many products were affected. Now under Black Duck, it's all consolidated. You search for a component and immediately see which products use it."
"The solution works well on Mac products."
"The product enables other applications to be secure."
"The installation is very easy."
"Policy management is a valuable feature."
"I like Fortify Software Security Center or Fortify SSC. This tool is installed on each developer's machine, but Fortify Software Security Center combines everything. We can meet there as security professionals and developers. The developers scan their code and publish the results there. We can then look at them from a security perspective and see whether they fixed the issues. We can agree on whether something is a false positive and make decisions."
"We write software, and therefore, the most valuable aspect for us is basically the code analysis part."
"Fortify Static Code Analyzer tells us if there are any security leaks or not. If there are, then it's notifying us and does not allow us to pass the DevOps pipeline. If it is finds everything's perfect, as per our given guidelines, then it is allowing us to go ahead and start it, and we are able to deploy it."
"We've found the documentation to be very good."
"You can really see what's happening after you've developed something."
"The reference provided for each issue is extremely helpful."
"The integration Subset core integration, using Jenkins is one of the good features."
"I like the Fortify taxonomy as it provides us with a list of all of the vulnerabilities found. Fortify release updated rule packs quarterly, with accompanying documentation, that lets us know what new features are being released."
"They are giving a lot of APIs and Python scripts for certain functionalities, but instead of using APIs and Python scripts, they should provide these functionalities through the UI. Users should be able to customize and add more fields through the UI. Users should be able to add more fields and generate reports. Currently, they are not giving flexibility in the UI. They're providing a script that simply generates an Excel file or CSV file. There is no flexibility."
"We're not too sure about the extension of the firewall. It never shows up in the Hub."
"It needs to be more user-friendly for developers and in general, to ensure compliance."
"The documentation is quite scattered."
"It's still a bit inconsistent. For example, if I scan today, it might not show the same results tomorrow."
"The solution's pricing model and documentation areas of concern where improvement is needed."
"I would like to see improvements in Black Duck's reporting capabilities."
"Black Duck can improve the time it takes for a scan. Most of the time it's not ideal when integrated with the live DevSecOps pipeline. We have to create a separate job to scan the library because it takes a couple of hours to scan all those libraries. The scanning could be faster."
"The generation of false positives should be reduced."
"Their licensing is expensive."
"I know the areas that they are trying to improve on. They've been getting feedback for several years. There are two main points. The first thing is keeping current with static code languages. I know it is difficult because code languages pop up all the time or there are new variants, but it is something that Fortify needs to put a better focus on. They need to keep current with their language support. The second thing is a philosophical issue, and I don't know if they'll ever change it. They've done a decent job of putting tools in place to mitigate things, but static code analysis is inherently noisy. If you just take a tool out of the box and run a scan, you're going to get a lot of results back, and not all of those results are interesting or important, which is different for every organization. Currently, we get four to five errors on the side of tagging, and it notifies you of every tiny inconsistency. If the tool sees something that it doesn't know, it flags, which becomes work that has to be done afterward. Clients don't typically like it. There has got to be a way of prioritizing. There are a ton of filter options within Fortify, but the problem is that you've got to go through the crazy noisy scan once before you know which filters you need to put in place to get to the interesting stuff. I keep hearing from their product team that they're working on a way to do container or docker scanning. That's a huge market mover. A lot of people are interested in that right now, and it is relevant. That is definitely something that I'd love to see in the next version or two."
"The product shows false positives for Python applications."
"The troubleshooting capabilities of this solution could be improved. This would reduce the number of cases that users have to submit."
"It can be tricky if you want to exclude some files from scanning. For instance, if you do not want to scan and push testing files to Fortify Software Security Center, that is tricky with some IDEs, such as IntelliJ. We found that there is an Exclude feature that is not working. We reported that to them for future fixing. It needs some work on the plugins to make them consistent across IDEs and make them easier."
"Not all languages are supported in Fortify."
"It comes with a hefty licensing fee."
Black Duck is ranked 1st in Software Composition Analysis (SCA) with 19 reviews while Fortify Static Code Analyzer is ranked 3rd in Static Code Analysis with 14 reviews. Black Duck is rated 7.8, while Fortify Static Code Analyzer is rated 8.4. The top reviewer of Black Duck writes "Enables applications to be secure, but it must provide more open APIs". On the other hand, the top reviewer of Fortify Static Code Analyzer writes "Seamless to integrate and identify vulnerabilities and frees up staff time". Black Duck is most compared with Snyk, JFrog Xray, Mend.io, FOSSA and Sonatype Lifecycle, whereas Fortify Static Code Analyzer is most compared with Snyk, Veracode, Sonatype Lifecycle, GitLab and Mend.io.
We monitor all Software Composition Analysis (SCA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.