sca-blackduck - Scan dependencies with Black Duck
Scans open source dependencies for vulnerabilities, license compliance risks, and supply chain threats using Synopsys Black Duck.
Tags
Updated: 2026-09-29Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Scan project dependencies
- Identify vulnerability findings
- Map CVEs to CWEs
- Map findings to OWASP
- Assess license compliance
- Generate remediation reports
- Generate software bills of materials
- Enforce security policies
- Integrate dependency scanning into CI/CD
- Assess supply chain risks
Inputs
- Project source code
- Dependency manifests
- Black Duck URL
- Black Duck API token
- Project name
- Project version
- CI/CD configuration
Outputs
- Vulnerability findings
- License compliance findings
- Supply chain risk findings
- Remediation guidance
- Compliance reports
- Software bills of materials
- Policy violation status
- CI/CD scan results
Requirements
- Docker
- Git
- Black Duck Detect
- Black Duck instance access
- Black Duck API token
- Permissions to scan projects
