Compare Black Duck vs. WhiteSource

Black Duck is ranked 3rd in Software Composition Analysis with 1 review while WhiteSource is ranked 2nd in Software Composition Analysis with 9 reviews. Black Duck is rated 0, while WhiteSource is rated 9.2. The top reviewer of Black Duck writes "Useful for determining the health of applications that contain open source components". On the other hand, the top reviewer of WhiteSource writes "Using it, we can take some measures to improve things, replace a library, or update a library which was too old". Black Duck is most compared with WhiteSource, Veracode Software Composition Analysis and Sonatype Nexus Lifecycle, whereas WhiteSource is most compared with Black Duck , SonarQube and Snyk.
Cancel
You must select at least 2 products to compare!
Black Duck  Logo
8,632 views|6,555 comparisons
WhiteSource Logo
8,187 views|5,871 comparisons
Most Helpful Review
Quotes From Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:

Pros
It highlights what the developers have done, and it shows the impact from an intellectual property point of view.

Read more »

The reporting capability gives us the option to generate an open-source license report in a single click, which gets all copyright and license information, including dependencies.With the fix suggestions feature, not only do you get the specific trace back to where the vulnerability is within your code, but you also get fix suggestions.It gives us full visibility into what we're using, what needs to be updated, and what's vulnerable, which helps us make better decisions.Our dev team uses the fix suggestions feature to quickly find the best path for remediation.For us, the most valuable tool was open-source licensing analysis.The most valuable features are the reporting, customizing libraries "In-house, White list, license selection", comparing the products/projects, and License & Copyright resolution.Attribution and license due diligence reports help us with aggregating the necessary data that we, in turn, have to provide to satisfy the various licenses copyright and component usage disclosures in our software.The most valuable feature is the inventory, where it compiles a list of all of the third-party libraries that we have on our estate.

Read more »

Cons
I would like to see more integration with other solutions, such as IntelliJ IDEA.

Read more »

It would be nice to have a better way to realize its full potential and translate it within the UI or during onboarding.The UI is not that friendly and you need to learn how to navigate easily.WhiteSource Prioritize should be expanded to cover more than Java and JavaScript.The UI can be slow once in a while, and we're not sure if it's because of the amount of data we have, or it is just a slow product, but it would be nice if it could be improved.If anything, I would spend more time making this more user-friendly, better documenting the CLI, and adding more examples to help expand the current documentation.WhiteSource needs improvement in the scanning of the containers and images with distinguishing the layers.Some detected libraries do not specify a location of where in the source they were matched from, which is something that should be enhanced to enable quicker troubleshooting.We specifically use this solution within our CICD pipelines in Azure DevOps, and we would like to have a gate so that if the score falls below a certain value then we can block the pipeline from running.

Read more »

Pricing and Cost Advice
Depending on the use case, the cost could range from $10,000 USD to $70,000 USD.

Read more »

Pricing is competitive.The version that we are using, WhiteSource Bolt, is a free integration with Azure DevOps.We are paying a lot of money to use WhiteSource. In our company, it is not easy to argue that it is worth the price. ‚Äč

Read more »

report
Use our free recommendation engine to learn which Software Composition Analysis solutions are best for your needs.
389,722 professionals have used our research since 2012.
Ranking
Views
8,632
Comparisons
6,555
Reviews
0
Average Words per Review
1,134
Avg. Rating
N/A
Views
8,187
Comparisons
5,871
Reviews
6
Average Words per Review
552
Avg. Rating
8.7
Top Comparisons
Compared 25% of the time.
Compared 21% of the time.
Compared 18% of the time.
Compared 11% of the time.
Also Known As
Blackduck Hub, Black Duck Protex, Black Duck Security Checker
Learn
Synopsys
WhiteSource
Overview

Black Duck Hub is the leading platform for automated license compliance and open source security. Black Duck Hub helps security and development teams identify and mitigate open source-related risks across their application portfolio, while incorporating the functionality of Protex license compliance.

The leading solution for agile open source security and license compliance management, WhiteSource integrates with the DevOps pipeline to detect vulnerable open source libraries in real-time.

It provides remediation paths and policy automation to speed up time-to-fix. It also prioritizes vulnerability alerts based on usage analysis.

We support over 200 programming languages and offer the widest vulnerability database aggregating information from dozens of peer-reviewed, respected sources.

Offer
Learn more about Black Duck
Learn more about WhiteSource
Sample Customers
CopperLeaf, ScienceLogic, Dynatrace, ClickFox, Siemens, Noser Engineering AGMicrosoft, Autodesk, NCR, Comcast, Nokia, Forgerock, indeed.com, GE digital, KPMG, LivePerson, Jack Henry and Associates
Top Industries
VISITORS READING REVIEWS
Software R&D Company44%
Comms Service Provider10%
Manufacturing Company9%
Financial Services Firm7%
VISITORS READING REVIEWS
Software R&D Company45%
Comms Service Provider11%
Insurance Company5%
Manufacturing Company5%
Find out what your peers are saying about Sonatype Nexus Lifecycle vs. WhiteSource and other solutions. Updated: January 2020.
389,722 professionals have used our research since 2012.
We monitor all Software Composition Analysis reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.