Konvu is a RSAC Launch Pad finalist 🎉Meet the founders in SF →

    Back to integrations
    SCA

    Black Duck integration

    Add exploit evidence to Black Duck's component risk and license compliance findings.

    Integration details

    Primary category

    Software Composition Analysis

    Sync direction

    Black Duck ↔ Konvu

    Findings are ingested from Black Duck into Konvu. Based on your workflow, Konvu can then push context, status changes, and severity updates back to Black Duck.

    Status

    Available

    What is Black Duck?

    Black Duck by Synopsys is an SCA solution focused on open source risk management, providing vulnerability detection, license compliance, and code quality analysis.

    Why connect Black Duck to Konvu

    • Filter Black Duck's comprehensive CVE catalog to components with demonstrated exploit potential.
    • Prioritize remediation for dependencies flagged by both Black Duck's policy engine and Konvu's exploitability analysis.
    • Enrich Black Duck reports with evidence explaining why specific vulnerabilities were accepted or fixed.

    How it works

    1

    Scan

    Black Duck produces findings from scans or assessments.

    2

    Ingest & enrich

    Konvu ingests those findings and enriches them with code, configuration, and deployment context.

    3

    Assess exploitability

    Konvu determines exploitability and recommended action with evidence attached.

    4

    Sync decisions

    Based on your workflow, Konvu can push context, status updates, and severity adjustments back into Black Duck.

    Quick setup

    Configure Black Duck from the integrations list in Konvu.

    1. 1Go to /configuration/integrations in Konvu and choose Black Duck.
    2. 2Authorize access and confirm the data sources you want to sync.
    3. 3Save the configuration to start syncing.

    Sync direction

    Black Duck ↔ Konvu

    Findings are ingested from Black Duck into Konvu. Based on your workflow, Konvu can then push context, status changes, and severity updates back to Black Duck.