Black Duck

Enterprise SCA platform with deep open-source detection, license compliance, and code origin analysis

ToolSoftware Composition AnalysisCloudSelf-hosted

Pricing: Custom enterprise pricing

Updated February 2026.

What is Black Duck?

Black Duck (a Synopsys product) is an enterprise-grade software composition analysis platform that provides deep visibility into open-source risks, license compliance, and code origin analysis. Black Duck's multi-factor open-source detection uses package managers, file-level analysis, and code snippet matching to identify open-source components even when they are not declared in manifests, making it the most thorough SCA tool for auditing software acquisitions, M&A due diligence, and regulatory compliance. Black Duck is part of Synopsys's broader application security portfolio alongside Coverity (SAST) and Polaris.

Best for: Enterprises needing the deepest open-source detection including undeclared components, M&A due diligence, and regulatory compliance for software supply chain

Key Features

Multi-factor open-source detection (package, file, snippet)
KnowledgeBase with 7M+ open-source components tracked
License compliance and conflict resolution
Code origin analysis for M&A due diligence
Binary analysis for compiled artifacts
Automated policy management and enforcement
Integration with Synopsys Coverity and Polaris
SBOM generation and export capabilities

Are you Black Duck? Improve this listing with screenshots, case studies and more.

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent Black Duck? Request a correction.