
Black Duck integration
Add exploit evidence to Black Duck's component risk and license compliance findings.
Integration details
Primary category
Software Composition Analysis
Sync direction
Black Duck ↔ Konvu
Findings are ingested from Black Duck into Konvu. Based on your workflow, Konvu can then push context, status changes, and severity updates back to Black Duck.
Status
Available
What is Black Duck?
Black Duck by Synopsys is an SCA solution focused on open source risk management, providing vulnerability detection, license compliance, and code quality analysis.
Why connect Black Duck to Konvu
- Filter Black Duck's comprehensive CVE catalog to components with demonstrated exploit potential.
- Prioritize remediation for dependencies flagged by both Black Duck's policy engine and Konvu's exploitability analysis.
- Enrich Black Duck reports with evidence explaining why specific vulnerabilities were accepted or fixed.
How it works
Scan
Black Duck produces findings from scans or assessments.
Ingest & enrich
Konvu ingests those findings and enriches them with code, configuration, and deployment context.
Assess exploitability
Konvu determines exploitability and recommended action with evidence attached.
Sync decisions
Based on your workflow, Konvu can push context, status updates, and severity adjustments back into Black Duck.
Quick setup
Configure Black Duck from the integrations list in Konvu.
- 1Go to /configuration/integrations in Konvu and choose Black Duck.
- 2Authorize access and confirm the data sources you want to sync.
- 3Save the configuration to start syncing.
Sync direction
Black Duck ↔ Konvu
Findings are ingested from Black Duck into Konvu. Based on your workflow, Konvu can then push context, status changes, and severity updates back to Black Duck.
More integrations
View allCheckmarx
Focus Checkmarx SAST and SCA alerts on code paths with demonstrated exploit potential.
Dependabot
Prioritize Dependabot PRs based on whether flagged vulnerabilities are exploitable.

Endor Labs
Focus Endor Labs dependency findings on vulnerabilities that are reachable and exploitable.
GitHub
Prioritize GitHub CodeQL and Dependabot alerts by adding exploit context to each finding.
GitLab
Add exploitability analysis to GitLab's built-in SAST and SCA pipeline findings.
OWASP Dependency-Check
Filter Dependency-Check's NVD matches to vulnerabilities with real exploit potential.