Opiniones de Black Duck Hub

Calificación media

  • En general
    4,2/5
  • Facilidad de uso
    3,7/5
  • Atención al cliente
    4,1/5

Sobre Black Duck Hub

Los desarrolladores aseguran y gestionan software de código abierto, eliminando los dolores de cabeza relacionados con las vulnerabilidades de seguridad de código abierto y el cumplimiento de las licencias.

Descubre más sobre Black Duck Hub

Mostrando 28 opiniones de %{reviews_total}

Usuario verificado
Consulting Partner, Cyber Security Delivery - Africa
Tecnología y servicios de la información, 2-10 empleados
Ha utilizado el software durante: Más de un año
  • Calificación global
    5/5
  • Facilidad de uso
    5/5
  • Características y funcionalidades
    5/5
  • Asistencia técnica
    4/5
  • Relación calidad-precio
    5/5
  • Probabilidad de recomendación
    10/10
  • Fuente de la reseña 
  • Fuente: GetApp
  • Publicado el 10/4/2018

"Ease of Use and extensible integration availability"

Puntos a favor: The integrations points are quite very wide and cater to whatever type of CI/ CDthat you may want to use, also, the IDE integrations are quite easy to deploy, thereby not locking you into a corner if your DevOps team are fixed on one particular type of technologies. Also, the accuracy and detection capability seems to be very solid

Contras: not sure if there is something that i did not really like, maybe initially it did not have the code snippets, but that has been taken care of now ; giving the solution better capability and usage experience

  • Fuente de la reseña 
  • Fuente: GetApp
  • Publicado el 10/4/2018
Rajiv A.
senior specialist cloud architect
Ha utilizado el software durante: 6-12 meses
  • Calificación global
    5/5
  • Facilidad de uso
    5/5
  • Características y funcionalidades
    5/5
  • Asistencia técnica
    3/5
  • Relación calidad-precio
    5/5
  • Probabilidad de recomendación
    10/10
  • Fuente de la reseña 
  • Publicado el 29/8/2017

"The ease of identifying and managing the open source code vulnerabilities and license risks."

Comentarios: Ease in identifying the security exposures and hidden vulnerabilities created by open source components.
Time to market is faster for identifying the vulnerabilities early during the development stage.
open source license management becomes so easy now.

Puntos a favor: The ease of identifying and managing the open source code and as well examining the source code for vulnerabilities and specifically the hidden security vulnerabilities is amazing. This is the product that every organization should look out to manage the source code for identifying quickly about vulnerabilities, open source code license management which can be lethal if ignored. Easily integrates with your current CI engines and sets the pace for your time to market. Ease in identifying the security exposures and hidden vulnerabilities created by open source components.
Time to market is faster for identifying the vulnerabilities early during the development stage.
open source license management becomes so easy now.
The product is really amazing already. Hub knowledge bases are huge and growing day by day.

Contras: Improve in reporting, and better API experience. Black Duck is a duckling and is growing fast.Suggest black duck to update the KBs quickly.

  • Fuente de la reseña 
  • Publicado el 29/8/2017
Pete T.
Infrastructure & Security Manager
Banca, 1001-5000 empleados
Ha utilizado el software durante: 6-12 meses
  • Calificación global
    3/5
  • Facilidad de uso
    3/5
  • Características y funcionalidades
    3/5
  • Asistencia técnica
    2/5
  • Relación calidad-precio
    2/5
  • Probabilidad de recomendación
    7/10
  • Fuente de la reseña 
  • Publicado el 26/7/2017

"Great software which I believe in, but not a pain free experience."

Comentarios: Ability to detect open source vulnerabilities in our code.

Puntos a favor: Ability to detect open source vulnerabilities in our code. Pre-sales contact & support was good (demo, trial etc). Clean interface. Performance improved in v4.0.0.

Contras: Difficult installation process, made more complicated with the introduction of Docker in v4.0.0 & with introduction of mandatory SSL/TLS web server certificate which requires troubleshooting trust issues. Support team are reluctant to pick up the phone or enter into telephone support, with sporadic email communication being the favoured option. Some gaps in documentation. Why is there no pre-built Black Duck Hub virtual appliance that I can drop into VMware? No documentation for implementing with vSphere Integrated Containers (VIC), only documentation for Docker & Openshift. Reporting improvements still to be made.

Respuesta de proveedores

por Black Duck el 31/7/2017

Thank you for providing feedback about your experience with Black Duck Hub. We¿re so sorry you are having issues ¿ and we¿d like to work together to fix that. We have escalated your case so that we can resolve it quickly.

Our customer support team strives to provide support in the way that works best for you, so we noted in your account that you prefer to be reached via phone. A senior support representative will reach out to you via phone.

Many of the issues you experienced during deployment were due to our old AppMgr architecture. The new Docker deployment is a more stable environment built to fix many of the issues you experienced. The Docker deployment can be harder to implement and run the first time; our senior support representative will be guiding you through this process. We will do better next time you have an issue; please escalate any issues you have to your Customer Success Manager.

  • Fuente de la reseña 
  • Publicado el 26/7/2017
Marco I.
System Analyst
Software informático, 1001-5000 empleados
Ha utilizado el software durante: 1-5 meses
  • Calificación global
    5/5
  • Facilidad de uso
    5/5
  • Características y funcionalidades
    4/5
  • Asistencia técnica
    5/5
  • Relación calidad-precio
    5/5
  • Probabilidad de recomendación
    10/10
  • Fuente de la reseña 
  • Publicado el 30/9/2017

"Using Black Duck HUB for Open Source Governance in software projects."

Comentarios: We are working in improving Open Source Culture in our Company and Customers: Black Duck HUB is a very good tool for awareness about legal, security and operational risks in using Open Source Components.

Puntos a favor: We are working in improving Open Source Culture in our Company and Customers: Black Duck HUB is a very good tool for awareness about legal, security and operational risks in using Open Source Components.
A very good thing is that it provide features for code scanning, independently from language and technology, also integrated with CI/CD tools like Jenkins.
The GUI is very easy to use and intuitive, the dashboard give a lot of information about Open Source Components in the project and you can take advantage of notification about new vulnerability.
In the latest versions Back Duck Hub is also improved in remediation suggestions about vulnerability.
Black Duck provide also good reports and you can customize it using restful API and direct access to a Report Database.
What is more it is really easy to install, we use the docker compose version: just install Docker, download images and run a command to set up the environment or upgrade to a new version!
Last but not least the technical support and customer care is really good.

Contras: Black Duck HUB is a quite new product, despite it has very famous and consolidate ancestors like Protex. So some features can improve and better meet users needs, especially about reports and API. Also documentation can improve .

  • Fuente de la reseña 
  • Publicado el 30/9/2017
Emmanuel C.
Project Manager, Technology
Ha utilizado el software durante: 6-12 meses
  • Calificación global
    5/5
  • Facilidad de uso
    5/5
  • Características y funcionalidades
    4/5
  • Asistencia técnica
    5/5
  • Relación calidad-precio
    3/5
  • Probabilidad de recomendación
    Sin valoración
  • Fuente de la reseña 
  • Publicado el 25/7/2017

"Excellent open source governance tool!"

Puntos a favor: I love the speed and overall simplicity of the application. It does a good job of finding most open source packages and performs identification automatically. It is very useful to see where a component is being used across my organization, as well as see other factors beyond license risk like security and operational risk.

Contras: The application is expensive due to the billing model that enforces a quota on amount of code scanned. This disincentivizes me to use the application when I would ordinarily want to scan as much of my code as possible due to its ease of use. It has fewer features when compared to Protex, but Black Duck is slowly resolving this.

Respuesta de proveedores

por Black Duck el 28/8/2017

Thank you for your feedback, we love hearing from our customers. You are correct ¿ Hub features are continually improved and we hope you are staying up to date and enjoying the new features. We have been working hard to close the gap on feature differences, and most will be available in Hub by end of the year. Additionally, Hub has many features not available in Protex, including showing security vulnerabilities. If you haven¿t already checked it out, check out one of our favorite new features in this video (https://www.youtube.com/watch?v=_4v2WwVQs1I) ¿ Hub Detect!

  • Fuente de la reseña 
  • Publicado el 25/7/2017
Ramani S.
Business Analyst
Ha utilizado el software durante: Más de un año
  • Calificación global
    4/5
  • Facilidad de uso
    4/5
  • Características y funcionalidades
    4/5
  • Asistencia técnica
    3/5
  • Relación calidad-precio
    3/5
  • Probabilidad de recomendación
    Sin valoración
  • Fuente de la reseña 
  • Publicado el 29/6/2017

"So far my experience with BlackDuck is great. I have seen almost positive response pretty much"

Puntos a favor: I like BD Hub when compare to Protex and CodeCenter. It's easy to handle and all in place rather than 2 legs at 2 different places. I have seen little issue with GUI provided along with Hub bit it's managable. The integration with Hub was easy along with Jenkins, Coverity, Jira and other tools. If properly integrated BD Hub along with Jenkins then the issue can be identified with Opertaional/Vulnerability/License much earlier than later. The Hub version of current one in-terms installation looks easy as one bundle instead of few different add-ons as prior. I had little issues while installation since of pre required suff with Linux lsb since it had multiple dependencies, otherwise it was easy to breeze through. Overall, my experience is good so far.

Contras: I have only exposures to 3 BD softwares Protex, CodeCenter and Hub. Out of it, I like Protex as least one. Since it was NOT very much user friendly. It's my experience but could have been better.

Respuesta de proveedores

por Black Duck el 9/8/2017

Thank you for sharing your feedback. We agree with you - the integrations for Hub make identifying open source risks earlier in the SDLC much simpler. Please reach out to support if you have any questions.

  • Fuente de la reseña 
  • Publicado el 29/6/2017
Franklin D.
Internal Consultant
Software informático, 501-1000 empleados
Ha utilizado el software durante: Más de dos años
  • Calificación global
    4/5
  • Facilidad de uso
    2/5
  • Características y funcionalidades
    3/5
  • Asistencia técnica
    3/5
  • Relación calidad-precio
    3/5
  • Probabilidad de recomendación
    6/10
  • Fuente de la reseña 
  • Publicado el 28/7/2017

"Pretty good at finding vulnerabilities; workflow to keep track of mitigations is hopeless"

Comentarios: We are able to anticipate the issues that our customers will find in our software when they scan it with Black Duck, before we ship to them. Thus, we can mitigate problems before they go out the door.

Puntos a favor: The new Hub product is very fast to scan software, and the UI is responsive and nice-looking. The Black Duck team is responsive to problems. They have made some of the improvements we've requested.

Contras: There is no support for a workflow that keeps track of changes we make. There's no history of comments or changes. Updates made to one version of a project are not easily available to other versions, or to other projects that use the same components. It is frustrating to navigate -- often too many clicks to get to a related view, and then the scroll position is lost when you go back so you have to remember where you were, click to successive pages... clunky.

Respuesta de proveedores

por Black Duck el 7/8/2017

Thanks so much for your review ¿ we always value feedback and while we appreciate your complements, we also really appreciate your feedback on areas of improvement. As always, our product team values your insights to improve the experience and keep the bar high. Regarding change history and UI issues, we are working to continue improving this area, including visibility and ease of use in upcoming releases. Our latest 4.0 release made some changes to improve UI navigation (especially when navigating back to list screens) that should help ¿ please check it out and let us know your thoughts! Thanks again for your feedback.

  • Fuente de la reseña 
  • Publicado el 28/7/2017
Mallika G.
DevOps Lead
Tecnología y servicios de la información, 51-200 empleados
Ha utilizado el software durante: 6-12 meses
  • Calificación global
    4/5
  • Facilidad de uso
    5/5
  • Características y funcionalidades
    4/5
  • Asistencia técnica
    5/5
  • Relación calidad-precio
    3/5
  • Probabilidad de recomendación
    5/10
  • Fuente de la reseña 
  • Publicado el 10/7/2017

"Could be better for .Net applications."

Puntos a favor: Reports are very good. Operational risk, License report etc are all very helpful. Could use more information for .Net applications though.

Contras: KB isn't really that good for third party dlls etc for .Net applications.
If the Jsons we send out to customer support could be automated as well (by Jenkins plugin) that'd be helpful instead of manually running them.

Respuesta de proveedores

por Black Duck el 28/8/2017

We are glad that you find the reporting useful. Our recently released Hub Detect (in Hub 4.1) can generate Dry Runs, which should help with support processes. In addition, Hub Detect is also better at identifying Nuget packages. Documentation on how to set up Hub Detect can be found here: https://blackducksoftware.atlassian.net/wiki/spaces/INTDOCS/pages/49131875/Hub+Detect. We¿ll reach out to help answer any remaining questions you may have.

  • Fuente de la reseña 
  • Publicado el 10/7/2017
Mike F.
Sr. QA
Servicios financieros, 501-1000 empleados
Ha utilizado el software durante: 6-12 meses
  • Calificación global
    4/5
  • Facilidad de uso
    3/5
  • Características y funcionalidades
    4/5
  • Asistencia técnica
    5/5
  • Relación calidad-precio
    4/5
  • Probabilidad de recomendación
    7/10
  • Fuente de la reseña 
  • Publicado el 31/7/2017

"just started using it"

Comentarios: list of open source licenses as well as where our code is using these to validate we are using them correctly

Puntos a favor: right now we have it setup to automatically scan using bamboo as the scheduler, we also set it up to email users using the hub apis to get the "failures" out to let developers know where issues are

Contras: being able to setup the repositories for internal vs externally facing code without getting help to do this

Respuesta de proveedores

por Black Duck el 28/8/2017

Thanks for your review ¿ we¿re glad that you are able to understand your code better. Someone from our product team will be reaching out to better understand additional requirements and to help you get these deployed appropriately.

  • Fuente de la reseña 
  • Publicado el 31/7/2017
Benjamin P.
Principal Application Architect
Tecnología y servicios de la información, 10 000+ empleados
Ha utilizado el software durante: 1-5 meses
  • Calificación global
    3/5
  • Facilidad de uso
    1/5
  • Características y funcionalidades
    3/5
  • Asistencia técnica
    1/5
  • Relación calidad-precio
    Sin valoración
  • Probabilidad de recomendación
    2/10
  • Fuente de la reseña 
  • Fuente: GetApp
  • Publicado el 8/11/2017

"Black Duck does not provide integration with Eclipse (or other IDE)"

Puntos a favor: We have installed Black Duck hub and integrated with Bamboo. This is good for our pipeline workflow and subsequent analysis of findings.

Contras: Black Duck advertised Gradle support with an integration with Eclipse. The implementation only worked in a simple configuration of a Gradle project. Recently (11-8-2017) Black Duck informed us in a response not to the plugin for Eclispe. This is vital to our DevOps workflow where we want to enable developers to identify issues based on findings with Black Duck hub in their local Eclipse.

Respuesta de proveedores

por Black Duck Software el 29/11/2017

Thank you for taking the time to review Black Duck Hub on GetApp. Currently Black Duck Hub integrates with Eclipse & Visual Studio IDEs. In Eclipse, we support Maven and Gradle package managers. Our Product Manager is interested to hear your feedback directly to understand how you are looking to use the integration and help bridge any gaps. Your Customer Success Manager will be reaching out to facilitate this call at your earliest convenience.

  • Fuente de la reseña 
  • Fuente: GetApp
  • Publicado el 8/11/2017
Basma S.
Senior Release Engineer
Seguridad e investigaciones, 1001-5000 empleados
Ha utilizado el software durante: 6-12 meses
  • Calificación global
    5/5
  • Facilidad de uso
    4/5
  • Características y funcionalidades
    5/5
  • Asistencia técnica
    5/5
  • Relación calidad-precio
    3/5
  • Probabilidad de recomendación
    7/10
  • Fuente de la reseña 
  • Publicado el 29/6/2017

"Stable Software to identify open source vulnerabilities"

Puntos a favor: It is very easy to use and integrate with the current continuous integration infrastructure. It is adding new features frequently to improve usability.

Contras: The result from scanning is not always that great. It should focus on improving findings. There are a lot of false alarms that should be corrected to update its database. It should support more languages in future.

Respuesta de proveedores

por Black Duck el 28/8/2017

Thank you for your review and we are glad you are enjoying the continued improvements. We are continuing to improve our language database and have recently released features in Hub 4.1 that should help improve scan results ¿ check out our new video blog that highlights these features here: https://www.youtube.com/watch?v=_4v2WwVQs1I. Your CSM will reach out to help you with your specific use cases.

  • Fuente de la reseña 
  • Publicado el 29/6/2017
Tunde O.
Consulting Partner, Africa
Tecnología y servicios de la información, 2-10 empleados
Ha utilizado el software durante: Más de un año
  • Calificación global
    5/5
  • Facilidad de uso
    5/5
  • Características y funcionalidades
    4/5
  • Asistencia técnica
    4/5
  • Relación calidad-precio
    5/5
  • Probabilidad de recomendación
    10/10
  • Fuente de la reseña 
  • Publicado el 31/7/2017

"Super fast, neat and top notch solution for Software Composition Analysis"

Puntos a favor: The fact that it combines all three core areas of Open Source Security Management is a very deep advantage. whether the need is security or license risk management or operational risk concerns. Black Duck does it well and neat.
Also, the scan speed helps you quickly make a good case within the shortest possible time.
it can be delivered On premise, allowing the user company to keep their source code and not release their source code unlike some other solution.

Contras: the fact that the code base monitored. would have been nice if the solution could be project based pricing or perhaps priced as a function of the number of lines of code. Nonetheless, still a fantastic tool

Respuesta de proveedores

por Black Duck el 9/8/2017

Thank you for your feedback. We love hearing from our customers, and use this information to continuously improve our offering. Please contact support if you have any questions.

  • Fuente de la reseña 
  • Publicado el 31/7/2017
Ludmila F.
Software Engineer
Tecnología y servicios de la información, 5001-10 000 empleados
Ha utilizado el software durante: 1-5 meses
  • Calificación global
    4/5
  • Facilidad de uso
    2/5
  • Características y funcionalidades
    4/5
  • Asistencia técnica
    Sin valoración
  • Relación calidad-precio
    Sin valoración
  • Probabilidad de recomendación
    7/10
  • Fuente de la reseña 
  • Publicado el 31/7/2017

"I couldn't find clear instructions on how to integrate scan with TFS builds."

Puntos a favor: I like that identification of open source software is automatic for most part. Although after the first scan more than 800 open source component were not identified so I have to do it manually.

Contras: It's different links to change license and version. It would be nice to have one location to make all changes if needed.

Respuesta de proveedores

por Black Duck el 9/8/2017

Thanks for your feedback.

Black Duck leverages multiple scanning techniques to get the most accurate number of matches for your codebase. We have launched Hub-Detect (https://www.github.com/blackducksoftware.com/hub-detect/), which is an umbrella implementation that leverages all our scanning techniques OTB! For your situation, you can invoke this implementation as a post-build step within your TFS job or alternatively, even run it from the command line. This ensures you have a single solution doing all your scans and ensuring you get complete results rolled up into your project.

This implementation is available with your existing Hub license and can be downloaded from GitHub here (https://www.github.com/blackducksoftware.com/hub-detect/).
As always, documentation for all our integrations will be on our public wiki space. Watch this space for the user guide at https://blackducksoftware.atlassian.net/wiki/spaces/INTDOCS/overview.
Contact support if you need help.

  • Fuente de la reseña 
  • Publicado el 31/7/2017
Torsten J.
IT consultant
Automoción, 10 000+ empleados
Ha utilizado el software durante: 1-5 meses
  • Calificación global
    4/5
  • Facilidad de uso
    3/5
  • Características y funcionalidades
    5/5
  • Asistencia técnica
    4/5
  • Relación calidad-precio
    4/5
  • Probabilidad de recomendación
    7/10
  • Fuente de la reseña 
  • Publicado el 26/7/2017

"This product is very powerful in analyzing, but still a lot of Manual work has to be done."

Comentarios: abetter possibilty to assess open source software

Puntos a favor: the automations, the huge nowledge base and last but not least automatic reports. two different views, modern and classic. Easy seraching and comparing of source code.

Contras: the ease of use is unfortenatley complicated. In some cases it is unclear how to solve license conflicts for example. i would propose to make clearer what the detailed workflow steps for an analyze is.

Respuesta de proveedores

por Black Duck el 28/8/2017

Thank you for your feedback, we are excited that the automations, knowledge base and automatic reports are working for you. Our engineering team will be reaching out to better understand your ease of use issues, including any specific feedback on licensing and analysis workflow required.

  • Fuente de la reseña 
  • Publicado el 26/7/2017
Philip B.
Engineering Excellence Manager
Tecnología y servicios de la información, 51-200 empleados
Ha utilizado el software durante: 6-12 meses
  • Calificación global
    4/5
  • Facilidad de uso
    3/5
  • Características y funcionalidades
    4/5
  • Asistencia técnica
    5/5
  • Relación calidad-precio
    4/5
  • Probabilidad de recomendación
    10/10
  • Fuente de la reseña 
  • Publicado el 1/6/2017

"Black Duck met Entersekt's checklist of what we needed in an OSS management solution."

Puntos a favor: Seamless integration & ease of use; Relevant feedback; Earlier in the SDLC; Real-time and continuous monitoring; Automated Notifications; Easy-to-digest reports with minimal false positives; Jenkins support & secure scanning; Code doesnt leave intranet; Identify open source licenses

Contras: The navigation of the UI can do with some more intuitive organization potentially with some contextual assistance to interpret what the summary number mean exactly on some of the report screens.

Respuesta de proveedores

por Black Duck el 9/8/2017

Thank you for sharing a review, Philip! Your feedback helps us improve our product, and we look forward to future discussions with you.

  • Fuente de la reseña 
  • Publicado el 1/6/2017
Jason L.
Group Head of IT Strategy and Architecture
Banca, 501-1000 empleados
Ha utilizado el software durante: 6-12 meses
  • Calificación global
    5/5
  • Facilidad de uso
    5/5
  • Características y funcionalidades
    5/5
  • Asistencia técnica
    5/5
  • Relación calidad-precio
    5/5
  • Probabilidad de recomendación
    10/10
  • Fuente de la reseña 
  • Publicado el 22/6/2017

"Excellent product . Post sale as good as pre sale"

Puntos a favor: Feature rich. Nuget integration. Post sales ...supports dev, security and dev ops...policy implementation

Contras: Linux hosted

  • Fuente de la reseña 
  • Publicado el 22/6/2017
Andrew W.
Release Engineer
Ha utilizado el software durante: 6-12 meses
  • Calificación global
    3/5
  • Facilidad de uso
    4/5
  • Características y funcionalidades
    4/5
  • Asistencia técnica
    5/5
  • Relación calidad-precio
    5/5
  • Probabilidad de recomendación
    Sin valoración
  • Fuente de la reseña 
  • Publicado el 28/6/2017

"It filled the needs of our team."

Puntos a favor: New feature are constantly being added. The support team is quick to get back with questions and issues.

Contras: Upgrading it is a major pain / undertaking. Each time we need to upgrade the system we have to do the equivalent of installing it from scratch.

Respuesta de proveedores

por Black Duck el 28/8/2017

We are glad you are pleased with our new features and the support you have received. We recently released a new deployment architecture with Hub 4.0, which should help alleviate some of that pain. In fact, our VP of Engineering just released this video https://www.youtube.com/watch?v=kvkqzFm4bgA to help answer some of the customer questions we¿ve received. Your CSM will be in touch to help answer any additional questions. In the meantime, please reach out to support.

  • Fuente de la reseña 
  • Publicado el 28/6/2017
Naveen G.
Infrastructure and Security Analyst
Servicios financieros, 1001-5000 empleados
Ha utilizado el software durante: Más de un año
  • Calificación global
    2/5
  • Facilidad de uso
    2/5
  • Características y funcionalidades
    3/5
  • Asistencia técnica
    1/5
  • Relación calidad-precio
    1/5
  • Probabilidad de recomendación
    2/10
  • Fuente de la reseña 
  • Publicado el 1/8/2017

"Technical Customer support is not good taking ages to resolve the issue"

Comentarios: Web Interface and easy to the scan tool Web GUI performance is better then old version. Docker Containerized technology

Puntos a favor: After upgrade to HUB4.0 software response is quick but lot of Issues with Certificates issues. Manual scan do not work on Linux servers

Respuesta de proveedores

por Black Duck el 28/8/2017

Thanks for bringing this to our attention. We strive to make installs and upgrades as smooth as possible for our customers but unfortunately we can¿t always plan for all scenarios. We value your feedback and our support team will be reaching out.

  • Fuente de la reseña 
  • Publicado el 1/8/2017
Frank F.
Senior Chief Engineer
Música, 501-1000 empleados
Ha utilizado el software durante: 1-5 meses
  • Calificación global
    4/5
  • Facilidad de uso
    5/5
  • Características y funcionalidades
    4/5
  • Asistencia técnica
    4/5
  • Relación calidad-precio
    4/5
  • Probabilidad de recomendación
    8/10
  • Fuente de la reseña 
  • Publicado el 7/8/2017

"Helps identify the open source software in use in our projects."

Puntos a favor: Works well and is not overly complicated to maintain. Company is very responsive to any false findings the tool reports.

Contras: Some of the upgrades did not go smoothly. Some of the information that most IT departments require seems to be missing from the documentation. The group roles (ie Policy manager) would be nice to assign on a project by project basis as opposed to site wide.

Respuesta de proveedores

por Black Duck el 28/8/2017

We are glad you find our team responsive to your needs. Hopefully our new, container based architecture helps address the upgrade issues (if you haven¿t heard about it yet, check out the video here: https://www.youtube.com/watch?v=kvkqzFm4bgA&t=1s). We know that user and role management are important features and we continually enhance them based on customer feedback. We appreciate your feedback and will reach out to make sure we understand all the specifics to help guide future consideration.

  • Fuente de la reseña 
  • Publicado el 7/8/2017
Christian S.
Head of Platform Security
Ha utilizado el software durante: 6-12 meses
  • Calificación global
    4/5
  • Facilidad de uso
    3/5
  • Características y funcionalidades
    4/5
  • Asistencia técnica
    5/5
  • Relación calidad-precio
    4/5
  • Probabilidad de recomendación
    8/10
  • Fuente de la reseña 
  • Publicado el 21/8/2017

"Easy to integrate with our Continuous Integration framework."

Puntos a favor: It is easy to interface with other services such as ticketing systems and the like. It is easy to get additional information about identified vulnerabilities.

Contras: The third category, operational risks, is not really clear and customer support initially suggested to ignore them. I am still confused by how the rating is done although it could be valuable.

  • Fuente de la reseña 
  • Publicado el 21/8/2017
Maurice S.
Software Engineer
  • Calificación global
    5/5
  • Facilidad de uso
    5/5
  • Características y funcionalidades
    5/5
  • Asistencia técnica
    5/5
  • Relación calidad-precio
    5/5
  • Probabilidad de recomendación
    Sin valoración
  • Fuente de la reseña 
  • Publicado el 28/6/2017

"Modern Open Source Manger"

Puntos a favor: The thing I like most about the Hub is the integrations. Engineers are moving toward a more automated build process and a have a tool that can support that is very nice.

Respuesta de proveedores

por Black Duck el 9/8/2017

Thank you for reviewing the software. We agree that integrations are very important, particularly for organizations using continuous integration in their SDLC.

  • Fuente de la reseña 
  • Publicado el 28/6/2017
Phutthipong P.
Engineer
Ingeniería industrial o mecánica, 1001-5000 empleados
Ha utilizado el software durante: 1-5 meses
  • Calificación global
    4/5
  • Facilidad de uso
    2/5
  • Características y funcionalidades
    3/5
  • Asistencia técnica
    4/5
  • Relación calidad-precio
    1/5
  • Probabilidad de recomendación
    6/10
  • Fuente de la reseña 
  • Publicado el 31/7/2017

"It's tooling to scan code"

Comentarios: Save my time

Puntos a favor: save time for checking open source software and hiligh on source code that same open source software

Contras: Price very expensive and it's not license that 's software fee. it have to pay year by year. In my job work on embeded system, our code size is very small (under 100 kB). But Blackduck protex sell in minimum 1GB that is one reasone for pricing high.

Respuesta de proveedores

por Black Duck el 9/8/2017

Thank you for providing your feedback. We love hearing from our customers! We're glad that our tools are helping you save time. If you need help with integrations or upgrades, please contact our customer support team.

  • Fuente de la reseña 
  • Publicado el 31/7/2017
Sanjay K.
IT Business Analyst
Banca, 10 000+ empleados
Ha utilizado el software durante: 1-5 meses
  • Calificación global
    4/5
  • Facilidad de uso
    4/5
  • Características y funcionalidades
    4/5
  • Asistencia técnica
    5/5
  • Relación calidad-precio
    4/5
  • Probabilidad de recomendación
    8/10
  • Fuente de la reseña 
  • Publicado el 26/7/2017

"Customer Support was quick & helpful. Most of the software already up there & less turnaround time"

Comentarios: Helped to verify the softwares for our product software developed in external environment by vendor.

Puntos a favor: Simple and easy to use, Responsive Customer support. Most of the softwares were already available. The new addition softwares takes less turnaround time for availability.

Contras: Don't see any as such. However would like to see latest softwares already added so that easy for the users.

Respuesta de proveedores

por Black Duck el 9/8/2017

Thank you so much for your feedback! We love hearing from our customers and are working to make our updates as easy as possible for you.

  • Fuente de la reseña 
  • Publicado el 26/7/2017
Viren K.
Vice President
Banca, 10 000+ empleados
Ha utilizado el software durante: 1-5 meses
  • Calificación global
    5/5
  • Facilidad de uso
    5/5
  • Características y funcionalidades
    5/5
  • Asistencia técnica
    5/5
  • Relación calidad-precio
    5/5
  • Probabilidad de recomendación
    10/10
  • Fuente de la reseña 
  • Publicado el 11/8/2017

"Open Software Software Governance"

Puntos a favor: Blackduck is the industry leader in Open Source Software governance. Black Duck enable us to not only look into our code base and establish a clean bill of materials, including all OSS components,

Contras: Blackduck software is stands in par with other open source software governance solutions. Obviously there some feature other comparable solutions does better than then Blackduck. Blackducks development team is accommodating for feature request enhancements.

  • Fuente de la reseña 
  • Publicado el 11/8/2017
Ed S.
Software Developer
Ha utilizado el software durante: 1-5 meses
  • Calificación global
    5/5
  • Facilidad de uso
    4/5
  • Características y funcionalidades
    3/5
  • Asistencia técnica
    5/5
  • Relación calidad-precio
    5/5
  • Probabilidad de recomendación
    8/10
  • Fuente de la reseña 
  • Publicado el 31/7/2017

"Great experience. API needs a little work"

Comentarios: Lots of information readily available

Puntos a favor: I love the ability to see at a glance detailed dependency information. Also being able to follow the breadcrumbs to CVE reports.

Contras: The REST API is extremely hard to work with and needs to be more user friendly. I want to be able to just get an API token and use it to make calls. Instead I have to scrape the JSESSIONCOOKIE id and use that. It's a lot of work.

Respuesta de proveedores

por Black Duck el 28/8/2017

Thanks for sharing your experience ¿ we are so glad that you are finding value in Black Duck. We appreciate the feedback on the Rest API, and a member of our product team will be reaching out to better understand your current implementation and help recommend a solution.

  • Fuente de la reseña 
  • Publicado el 31/7/2017