Black Duck Application Security Testing (AST) for AWS logo

    Black Duck Application Security Testing (AST) for AWS

    Application security tools and services that integrate security testing into DevOps workflows. Available via Private Offer.

    Ratings and reviews

    4.1
    32 ratings
    0 AWS reviews
    |
    32 external reviews
    External reviews are from G2 .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (32)
    Sonal K.

    Accurate Vulnerability Insights and Remediation—A Must-Have SCA Platform

    Reviewed on Jul 20, 2026
    Review provided by G2
    What do you like best about the product?
    Black Duck is the world leader for its SCA platform. The platform gives accurate vulnerabilities, line-to-line, along with correct remediations to fix the code. Must to have in your organisation.
    What do you dislike about the product?
    Nothing so far. Everything is good as per any organisation requirements.
    What problems is the product solving and how is that benefiting you?
    It solves Software Composition Analysis vulnerabilities like any deprecated libraries or packages used in your organisation and to replace them with the updated ones.
    Computer Software

    Excellent Visibility into Open-Source Vulnerabilities

    Reviewed on Jun 28, 2026
    Review provided by G2
    What do you like best about the product?
    Black Duck provides excellent visibility into open-source vulnerabilities. It makes it very easy to track our dependencies and confirm we aren’t shipping code that contains known security flaws.
    What do you dislike about the product?
    At times, the scans return a high number of false positives, which creates extra manual work for our team to review and dismiss them.
    What problems is the product solving and how is that benefiting you?
    Black Duck helps us address the problem of hidden vulnerabilities in our open-source dependencies. The biggest benefit is that it significantly reduces our security risk by enabling developers to spot and remediate issues well before they make it into production.
    Md Sarfaraz H.

    Reliable Open Source Security Tool with Strong CI/CD Integration

    Reviewed on Jun 25, 2026
    Review provided by G2
    What do you like best about the product?
    I like that Black Duck SCA makes it easy to identify vulnerable open-source dependencies and keeps track of newly discovered security issues. The reports are clear, and the CI/CD integration fits well into the development workflow. It also helps with license compliance, which is a big plus. The AI-powered insights are useful for understanding and prioritizing risks. The only downside is the pricing—it can be expensive, especially for smaller teams, but the features and visibility it provides make it worthwhile for larger organizations.
    What do you dislike about the product?
    One thing I don't like is the pricing—it can be quite expensive, especially for smaller teams. The initial setup and configuration also take some time, and the interface can feel a bit overwhelming for new users. Occasionally, there are false positives that need manual review, and I'd like to see faster scans and more intuitive reporting and dashboards. Overall, it's a solid tool, but there's definitely room to improve usability and cost.
    What problems is the product solving and how is that benefiting you?
    Black Duck SCA helps us identify security vulnerabilities and license compliance issues in open-source dependencies before they become bigger problems. It gives us visibility into the components used across our applications and alerts us when new vulnerabilities are discovered. This helps our team fix issues earlier in the development cycle, reduces security risks, supports compliance requirements, and saves time during security reviews and audits.
    VIVEK S.

    Powerful Open-Source Risk Management, Needs Easier Setup

    Reviewed on May 18, 2026
    Review provided by G2
    What do you like best about the product?
    I appreciate how Black Duck reduces audit stress with its automated compliance reporting. It strengthens DevSecOps workflows by embedding open-source risk management directly into the CI/CD process. I find the detailed dashboards for audits very useful, and I like the customizable rules for governance offered by the policy control features.
    What do you dislike about the product?
    The UI sometimes feels dated and requires expertise to configure effectively. Additionally, the setup is heavy and tough, with a need to make it lighter and reduce the installation process.
    What problems is the product solving and how is that benefiting you?
    Black Duck helps manage open-source risks by detecting vulnerabilities and ensuring license compliance. It automates compliance reporting, reducing audit stress, and strengthens DevSecOps workflows by integrating risk management into CI/CD pipelines.
    Renato Z.

    High-Performing and Effective, with Appreciated Automatic Alerts

    Reviewed on Apr 07, 2026
    Review provided by G2
    What do you like best about the product?
    Perfoming and effective. Automatic alerts are really appreciated and
    What do you dislike about the product?
    Prices are not affordable and UX interface not so easy. Sometimes scanning are a little slow
    What problems is the product solving and how is that benefiting you?
    Black Duck helped us to understand where our code was not performing well. We improved visibility and we were able to keep under control security and legal risks
    Lokesh T.

    Powerful SCA Tool with Extensive Knowledge, but Resource-Heavy On-Prem Deployment

    Reviewed on Oct 17, 2025
    Review provided by G2
    What do you like best about the product?
    I found it as a best SCA tool, where its engine is very powerful in identifying Open source issues, And the main thing is that its Black Duck Knowledge is very huge
    What do you dislike about the product?
    The only drawback is it require huge resource to deploy in on-prem
    What problems is the product solving and how is that benefiting you?
    It solves addressing Open Source Issues basically its a Software composition Analysis tool.
    omkar r.

    Whitehat sentinel

    Reviewed on Feb 02, 2023
    Review provided by G2
    What do you like best about the product?
    Security Experts analyse potential vulnerabilities.
    Minimal false positives.
    Alerts for newly discovered vulnerabilities.tracking all records previous as well as present.
    What do you dislike about the product?
    The vendor provides scanning, identification, engineering support and risked based reporting of security vulnerabilities. It is little bit slow other wise it is very good.
    What problems is the product solving and how is that benefiting you?
    The vendor provides scanning, identification, engineering support and risked based reporting of security vulnerabilities.it support to better quality of software.
    Neri Rafael C.

    good service and excellent support

    Reviewed on Oct 31, 2022
    Review provided by G2
    What do you like best about the product?
    my position within the organization as DevSecOps and developer can be quite complicated without the use of services or tools such as those provided by the whitehat sentinel team, we have used it for more than 4 years and the development support is always elementary, the The issue of security is something serious and it is something that must be studied permanently, they help you to have what you need
    What do you dislike about the product?
    This is very complex since for the niche that they offer service, in my opinion, if they meet the expectations, so I could say that I do not find a specific point to suggest any improvement at the moment.
    What problems is the product solving and how is that benefiting you?
    security at all times is very important in each application development that involves data from clients and administrative personnel, this is something that must always be taken into account and this team does everything to shield our people.
    Ali s.

    Good security, Stable and feature rich.

    Reviewed on Nov 22, 2021
    Review provided by G2
    What do you like best about the product?
    Black duck software composition analysis works amazing on Mac, It has a good security and excellent features that protects and examines our source code from compliance issues.
    What do you dislike about the product?
    Black duck should add features like packet analysis and binary analysis for better performance.
    What problems is the product solving and how is that benefiting you?
    We use black duck to audit our source code to protect from liscence and open source compliance. It is easy to use, stable, and well recognized in the industry.
    Pratik H.

    Legal and Operational risks management tool.

    Reviewed on Nov 03, 2021
    Review provided by G2
    What do you like best about the product?
    It has impressive features for both legal & security 3rd party software compliance. UI is easy to understand. It helps us to analyze the code in a timely and accurate manner.
    What do you dislike about the product?
    According to me it has all the features required. It is fast and easy to use.
    What problems is the product solving and how is that benefiting you?
    The support team is always available to resolve the problem if any. Rest it helps us to know what's in your code and analyze your code in a timely and accurate manner.