WhiteSource Reviews

Filter by:
Industry
Loading...
Filter Unavailable
Company Size
Loading...
Filter Unavailable
Job Level
Loading...
Filter Unavailable
Rating
Loading...
Filter Unavailable
Considered
Loading...
Filter Unavailable
Order by:
Loading...
  • Date
  • Highest Rating
  • Lowest Rating
  • Review Length
Search:
Showingreviews based on the current filters. Reset all filters
Real User
VP R&D at a computer software company with 51-200 employees
Jan 14 2020

What is most valuable?

The policy automation on effective vulnerabilities feature had a major impact on how we address open source vulnerabilities since it focuses on effective vulnerabilities and directs you to the specific methods. Other services will give a… more»

How has it helped my organization?

WhiteSource improved our team’s ability to deal with vulnerabilities in a timely manner. Most of the time the alerts pile up and no one wants to deal with it, but the process now is much more simplified and convenient. It is still a task… more»

What needs improvement?

The UI is not that friendly and you need to learn how to navigate easily. It also doesn’t run as smoothly as I would want or expect, and I believe it requires some improvements. That said, the Success team is very attentive and does reply… more»

Which solution did I use previously and why did I switch?

We didn't use anything before, only manually.

Which other solutions did I evaluate?

We’ve evaluated Snyk, also used their free version and free dependency checkers.
Vendor
User at a tech vendor with 1,001-5,000 employees
Dec 16 2019

What is most valuable?

The most valuable features of this solution are: * The vulnerability and license alerts are the main purposes of us utilizing this tool. We don't want to ship software and mistakenly include a GPL… more»

How has it helped my organization?

We moved from Black Duck to WhiteSource as it was a more modern and scalable solution, with better integration support to various build and source environments. The ease of running scans and getting… more»

What needs improvement?

Places in need of improvement are: * Some detected libraries do not specify a location of where in the source they were matched from, which is something that should be enhanced to enable quicker… more»

What's my experience with pricing, setup cost, and licensing?

Pricing is competitive.

Which solution did I use previously and why did I switch?

Prior to this solution, we used Black Duck. As of two years ago, when we made the switch, WhiteSource's UI was more modern, the SaaS solution more scalable, and the integration capabilities far… more»

Which other solutions did I evaluate?

We also use NPM Audit and Snyk, but as an augmentation; not as competitors.
Learn what your peers think about WhiteSource. Get advice and tips from experienced pros sharing their opinions. Updated: April 2020.
431,024 professionals have used our research since 2012.
Real User
Co Founder at a consumer goods company with 11-50 employees
Jan 05 2020

What is most valuable?

WhiteSource is very accurate and covers all of our languages (including C++). WhiteSource Prioritize is amazing. If we are using a vulnerable library, it shows us if we are actually using the vulnerable method or not. This saves us a lot of… more»

How has it helped my organization?

The best thing is that it changed the mindset of our developers. They are now more aware and proactive when it comes to the security risks in open source vulnerabilities and the need to update packages from time to time. It gives us full… more»

What needs improvement?

WhiteSource Prioritize should be expanded to cover more than Java and JavaScript. We are currently using WhiteSource Prioritize for Java and it cuts our vulnerability alerts by almost 90%. However, Prioritize doesn't cover python or other… more»

What other advice do I have?

The good thing is that their product just keeps getting better. They are very attentive to their customers. All in all, if you care about security, this product is a must. We all love open source, but I was always afraid of the headache in… more»

Which other solutions did I evaluate?

We tested Black Duck as well but detected quite a lot of false positives.
Alon Michaeli
Real User
Founder & CEO at Data+
May 28 2020

What is most valuable?

The most valuable features for us are: * Fix suggestions. Our dev team uses the fix suggestions feature to quickly find the best path for remediation. Before that you would have to research online for fixes, and most of the time it’s not… more»

How has it helped my organization?

WhiteSource is very easy to run and use. It reduced significantly the time our developers used to spend on issues in open-source libraries. We used a free tool before and the number of alerts was too high to handle. We recently implemented… more»

What needs improvement?

The changes that we would like to see are mostly usability issues. The UI can be slow once in a while, and we're not sure if it's because of the amount of data we have, or it is just a slow product, but it would be nice if it could be… more»

Which solution did I use previously and why did I switch?

No

Which other solutions did I evaluate?

Yes, Snyk
Real User
VP R&D at a tech services company with 11-50 employees
Dec 26 2019

What is most valuable?

For us, the most valuable tool was open-source licensing analysis. Although we don't use it on a weekly basis, when we needed to produce a reliable analysis of our open-source licensing exposure, we… more»

How has it helped my organization?

WhiteSource allowed us to minimize our exposure to open-source vulnerabilities with ease. Aside from identifying the out-dated or compromised packages really easily, it allows us to actually see which… more»

What needs improvement?

The agent usage was not as smooth as the online experience. It lacks in terms of documentation and the errors and warnings it produces are not always very clear. We were able to get it up and running… more»

Which solution did I use previously and why did I switch?

We did not use another solution prior to this one.

What other advice do I have?

Overall, this is a great product.

Which other solutions did I evaluate?

We did not evaluate other options.
Real User
Project Manager at a health, wellness and fitness company with 11-50 employees
Jan 14 2020

What is most valuable?

Our use case focuses on licenses, so the most valuable feature would probably be the license reports and policies, which is why we reached out in the first place. The reporting capability gives us the option to generate an open-source… more»

How has it helped my organization?

We were able to integrate the product naturally into our development process and it provided results really fast. You can easily use the unified agent and connect your CICD tools. It scans all of your source code quickly and it took us just… more»

What needs improvement?

It would be nice to have a better way to realize its full potential and translate it within the UI or during onboarding.

What other advice do I have?

I believe we’re still in a stage where we’re trying to gain all the benefits of the solution and understand what features can be maximized. The product is simple on one hand as it's so easy to use, run and get insights from, but on the… more»

Which other solutions did I evaluate?

Given the different solutions in that space, WhiteSource was the best solution for our needs. We’ve found it was able to manage all dependencies, automate alerts, and provide us with easy and quick license reports, attribution and copyright… more»
Daniel Hall
Real User
Technical Architect at Dwr Cymru Welsh Water
Sep 19 2019

What is most valuable?

The most valuable feature is the inventory, where it compiles a list of all of the third-party libraries that we have on our estate. This helps us quite a bit.

What needs improvement?

We specifically use this solution within our CICD pipelines in Azure DevOps, and we would like to have a gate so that if the score falls below a certain value then we can block the pipeline from… more»

What's my experience with pricing, setup cost, and licensing?

The version that we are using, WhiteSource Bolt, is a free integration with Azure DevOps.

Which solution did I use previously and why did I switch?

For this use case, we did not use another solution prior to this one.

What other advice do I have?

For anybody who is researching this type of solution, my suggestion is to try them first. We tried quite a few of the various toolings available, and some of them are just not workable. They're very… more»

Which other solutions did I evaluate?

We are still evaluating at the moment, and have not officially adopted WhiteSource as of yet.
Real User
DevOps CI/CD Team Lead at a computer software company with 10,001+ employees
Jun 17 2020

What is most valuable?

The most valuable feature is the unified JAR to scan for all langs (wss-scanner jar). It helps us to scan easily and is agnostic to the technology.

How has it helped my organization?

In general, we are covered for open source licensing issues and CVE errors on particular versions for open source dependencies. Moreover, we have covered ourselves for security auditing by stating… more»

What needs improvement?

The dashboard UI and UX are problematic. This solution looks like a 1995 web site and it's very hard to understand what the issue is and why it failed.

Which solution did I use previously and why did I switch?

This is my first open-source scanning solution.

What other advice do I have?

Improve the UI please... developers cannot find themselves in this dashboard.

Which other solutions did I evaluate?

I didn't choose it but I saw a demo of Synk.
See 1 More WhiteSource Reviews

Articles

User Assessments By Topic About WhiteSource

Learn what your peers think about WhiteSource. Get advice and tips from experienced pros sharing their opinions. Updated: April 2020.
431,024 professionals have used our research since 2012.

WhiteSource Questions

What is WhiteSource?

The leading solution for agile open source security and license compliance management, WhiteSource integrates with the DevOps pipeline to detect vulnerable open source libraries in real-time.

It provides remediation paths and policy automation to speed up time-to-fix. It also prioritizes vulnerability alerts based on usage analysis.

We support over 200 programming languages and offer the widest vulnerability database aggregating information from dozens of peer-reviewed, respected sources.

WhiteSource customers

Microsoft, Autodesk, NCR, Comcast, Nokia, Forgerock, indeed.com, GE digital, KPMG, LivePerson, Jack Henry and Associates

Read Archived Reviews
BUYER'S GUIDE
Download our free WhiteSource Report and get advice and tips from experienced pros sharing their opinions.