Compare Black Duck vs. WhiteSource

Cancel
You must select at least 2 products to compare!
Black Duck Logo
16,225 views|11,242 comparisons
WhiteSource Logo
18,685 views|14,546 comparisons
Most Helpful Review
Find out what your peers are saying about Black Duck vs. WhiteSource and other solutions. Updated: July 2021.
524,194 professionals have used our research since 2012.
Quotes From Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:

Pros
"I like the fact that the product auto analyzes components.""The stability is okay.""The solution works well on Mac products.""The most valuable feature is the vulnerability scanning, and that it's easy to use.""The knowledge base and the management system are the most valuable features of Black Duck Hub. It has a very helpful management environment. They offer an editor where we can check the discovered license, which is retrieved from their knowledge base. They have a huge knowledge base build over the years. It gives you some possibilities, such as this license with possibility A could cause a vulnerability issue or a potential breach."

More Black Duck Pros »

"The most valuable feature is the inventory, where it compiles a list of all of the third-party libraries that we have on our estate.""Attribution and license due diligence reports help us with aggregating the necessary data that we, in turn, have to provide to satisfy the various licenses copyright and component usage disclosures in our software.""The most valuable features are the reporting, customizing libraries "In-house, White list, license selection", comparing the products/projects, and License & Copyright resolution.""For us, the most valuable tool was open-source licensing analysis.""It gives us full visibility into what we're using, what needs to be updated, and what's vulnerable, which helps us make better decisions.""The reporting capability gives us the option to generate an open-source license report in a single click, which gets all copyright and license information, including dependencies.""With the fix suggestions feature, not only do you get the specific trace back to where the vulnerability is within your code, but you also get fix suggestions.""Our dev team uses the fix suggestions feature to quickly find the best path for remediation."

More WhiteSource Pros »

Cons
"The scanner client is limited by the size of software it can handle.""It needs to be more user-friendly for developers and in general, to ensure compliance.""We're not too sure about the extension of the firewall. It never shows up in the Hub.""The initial setup could be simplified. It was somewhat complex.""It is a cloud-only solution. In many cases, companies like to evaluate the software, but they're very reluctant to give you the software. It would be great if they could offer an on-prem component that could be used to scan the code and then upload the discovery results to the cloud and get all the information from there, but there is no such possibility. You have to upload the code to the Black Duck cloud system. Of course, they have a strong legal department, and they offer some configuration, but it is never enough. You have to give the code, which is a drawback. In modern designs like Snyk or FOSSA, you don't need to give the code. It requires more native integration with Coverity because they go together technically. You need both Coverity and Black Duck Hub. It would be really helpful for companies working in this space to get a combined offer from the same company. They should provide an option to buy Coverity for an additional fee. Coverity combined with Black Duck Hub will provide a one-step analysis to get everything you need and a unified report. It would be really great to be able to connect Black Duck Hub with Coverity unified reports."

More Black Duck Cons »

"We specifically use this solution within our CICD pipelines in Azure DevOps, and we would like to have a gate so that if the score falls below a certain value then we can block the pipeline from running.""Some detected libraries do not specify a location of where in the source they were matched from, which is something that should be enhanced to enable quicker troubleshooting.""WhiteSource needs improvement in the scanning of the containers and images with distinguishing the layers.""If anything, I would spend more time making this more user-friendly, better documenting the CLI, and adding more examples to help expand the current documentation.""WhiteSource Prioritize should be expanded to cover more than Java and JavaScript.""It would be nice to have a better way to realize its full potential and translate it within the UI or during onboarding.""The UI is not that friendly and you need to learn how to navigate easily.""The UI can be slow once in a while, and we're not sure if it's because of the amount of data we have, or it is just a slow product, but it would be nice if it could be improved."

More WhiteSource Cons »

Pricing and Cost Advice
"The price is quite high because the behavior of the software during the scan is similar to competing products.""The price is low. It's not an expensive solution.""Black Duck is more suitable if you require a lot of licensing compliance. For smaller organizations, WhiteSource is better because its pricing policies are not really suitable for huge organizations."

More Black Duck Pricing and Cost Advice »

"The version that we are using, WhiteSource Bolt, is a free integration with Azure DevOps.""Pricing is competitive.""The solution involves a yearly licensing fee."

More WhiteSource Pricing and Cost Advice »

report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
524,194 professionals have used our research since 2012.
Questions from the Community
Top Answer: The knowledge base and the management system are the most valuable features of Black Duck Hub. It has a very helpful management environment. They offer an editor where we can check the discovered… more »
Top Answer: Black Duck is more suitable if you require a lot of licensing compliance. For smaller organizations, WhiteSource is better because its pricing policies are not really suitable for huge organizations.
Top Answer: It is a cloud-only solution. In many cases, companies like to evaluate the software, but they're very reluctant to give you the software. It would be great if they could offer an on-prem component… more »
Top Answer: The license management of WhiteSource was at a good level. As compared to other tools that I have used, its functionality for the licenses for the code libraries was quite good. Its UI was also fine.
Top Answer: We have ended our relationship with WhiteSource. We were using an agent that we built in the pipeline so that you can scan the projects during build time. But unfortunately, that agent didn't work at… more »
Top Answer: I would rate WhiteSource a three out of ten considering the fact that we couldn't use it while we were paying for it. It had good features, but we couldn't use it.
Ranking
Views
16,225
Comparisons
11,242
Reviews
5
Average Words per Review
737
Rating
7.4
Views
18,685
Comparisons
14,546
Reviews
12
Average Words per Review
438
Rating
8.4
Popular Comparisons
Also Known As
Blackduck Hub, Black Duck Protex, Black Duck Security Checker
Learn More
Overview

Black Duck is a comprehensive solution for managing security, license compliance, and code quality risks that come from the use of open source in applications and containers. Named a leader in software composition analysis (SCA) by Forrester, Black Duck gives you unmatched visibility into third-party code, enabling you to control it across your software supply chain and throughout the application life cycle.

The leading solution for agile open source security and license compliance management, WhiteSource integrates with the DevOps pipeline to detect vulnerable open source libraries in real-time.

It provides remediation paths and policy automation to speed up time-to-fix. It also prioritizes vulnerability alerts based on usage analysis.

We support over 200 programming languages and offer the widest vulnerability database aggregating information from dozens of peer-reviewed, respected sources.

Offer
Learn more about Black Duck
Learn more about WhiteSource
Sample Customers
Samsung, Siemens, ScienceLogic, Noser Engineering AG, ClickFox, Dynatrace, CopperLeaf
Microsoft, Autodesk, NCR, Comcast, Nokia, Forgerock, indeed.com, GE digital, KPMG, LivePerson, Jack Henry and Associates
Top Industries
VISITORS READING REVIEWS
Computer Software Company36%
Comms Service Provider14%
Financial Services Firm10%
Manufacturing Company9%
REVIEWERS
Computer Software Company33%
Media Company11%
Energy/Utilities Company11%
Consumer Goods Company11%
VISITORS READING REVIEWS
Computer Software Company37%
Comms Service Provider18%
Financial Services Firm6%
Manufacturing Company5%
Company Size
VISITORS READING REVIEWS
Small Business17%
Midsize Enterprise6%
Large Enterprise77%
REVIEWERS
Small Business38%
Midsize Enterprise8%
Large Enterprise54%
VISITORS READING REVIEWS
Small Business20%
Midsize Enterprise6%
Large Enterprise74%
Find out what your peers are saying about Black Duck vs. WhiteSource and other solutions. Updated: July 2021.
524,194 professionals have used our research since 2012.

Black Duck is ranked 6th in Software Composition Analysis (SCA) with 5 reviews while WhiteSource is ranked 3rd in Software Composition Analysis (SCA) with 12 reviews. Black Duck is rated 7.4, while WhiteSource is rated 8.4. The top reviewer of Black Duck writes "Auto analyzes components and supports a range of scales". On the other hand, the top reviewer of WhiteSource writes "Policy automation and automatic fix suggestions help us to save time in finding and solving problems". Black Duck is most compared with Snyk, Sonatype Nexus Lifecycle, Veracode Software Composition Analysis, JFrog Xray and FOSSA, whereas WhiteSource is most compared with SonarQube, Snyk, Sonatype Nexus Lifecycle, Veracode and Checkmarx. See our Black Duck vs. WhiteSource report.

See our list of best Software Composition Analysis (SCA) vendors.

We monitor all Software Composition Analysis (SCA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.