--- title: Black Duck Polaris Platform Reviews meta_title: 'Black Duck Polaris Platform Reviews 2026: Details, Pricing, & Features | G2' meta_description: Filter 104 reviews by the users' company size, role or industry to find out how Black Duck Polaris Platform works for a business like yours. aggregate_rating: rating_value: 4.2 review_count: 104 scale: '5' date_modified: '2026-09-30' parent_category: name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t" url: https://www.g2.com/categories/devsecops ---

Black Duck Polaris Platform Reviews & Product Details

Profile Status

This profile is currently managed by Black Duck Polaris Platform but has limited features.

Are you part of the Black Duck Polaris Platform team? Upgrade your plan to enhance your branding and engage with visitors to your profile!

Value at a Glance

Averages based on real user reviews.

Time to Implement

4 months

Return on Investment

18 months

User Insights

Average based on 104 real user reviews.

Implementation Time

4 months

Perceived Cost

$$$$$

Typical contract price

$0k - $0k

Sign in to view

Per Year

Neri Rafael C.
NC
Neri Rafael C.
Developer TI
Small-Business (50 or fewer emp.)
Business partner of the seller or seller's competitor, not included in G2 scores.
"good service and excellent support"
5/5
What do you like best about Black Duck Polaris Platform?

my position within the organization as DevSecOps and developer can be quite complicated without the use of services or tools such as those provided by the whitehat sentinel team, we have used it for more than 4 years and the development support is always elementary, the The issue of security is something serious and it is something that must be studied permanently, they help you to have what you need Review collected by and hosted on G2.com.

What do you dislike about Black Duck Polaris Platform?

This is very complex since for the niche that they offer service, in my opinion, if they meet the expectations, so I could say that I do not find a specific point to suggest any improvement at the moment. Review collected by and hosted on G2.com.

OR
omkar r.
Consultant
Mid-Market (51-1000 emp.)
"Whitehat sentinel"
4.5/5
What do you like best about Black Duck Polaris Platform?

Security Experts analyse potential vulnerabilities. Minimal false positives. Alerts for newly discovered vulnerabilities, tracking all records previous as well as present. Review collected by and hosted on G2.com.

What do you dislike about Black Duck Polaris Platform?

The vendor provides scanning, identification, engineering support and risk-based reporting of security vulnerabilities. It is a little bit slow otherwise it is very good. Review collected by and hosted on G2.com.

Deepti S.
DS
Deepti S.
5G Software Developer 2
Enterprise (> 1000 emp.)
"Optimized code with Coverity tool"
5/5
What do you like best about Black Duck Polaris Platform?

I love the feature how Coverity tool by Synopsys can detect issues in the code and thus provides a way to make your code way more optimized. Review collected by and hosted on G2.com.

What do you dislike about Black Duck Polaris Platform?

I dislike that sometimes there are false positive issues for which there is no perfect fix, but Coverity indicates it as a bug. But there is always a way to declare that false positive and it's good enough. Review collected by and hosted on G2.com.

Shreyans M.
SM
Shreyans M.
Scrum Master
Mid-Market (51-1000 emp.)
"Benchmark in software composition analysis"
4.5/5
What do you like best about Black Duck Polaris Platform?

One of the top solution providers to help manage security vulnerabilities, code quality, code smells, bugs and compliance risk associated with third-party open source code in an effective way. It supports wide range of languages some of which include Java, Cobol, Javascript, C#, C and C++. This software is the benchmark solution to elevate the continuous inspection element in CI/CD model Review collected by and hosted on G2.com.

What do you dislike about Black Duck Polaris Platform?

The cost is relatively higher than the other solutions in the market which makes it a difficult choice for organisations Review collected by and hosted on G2.com.

Pratik H.
PH
Pratik H.
IT Project Coordinator
Mid-Market (51-1000 emp.)
"Legal and Operational risks management tool."
4/5
What do you like best about Black Duck Polaris Platform?

It has impressive features for both legal & security 3rd party software compliance. UI is easy to understand. It helps us to analyze the code in a timely and accurate manner. Review collected by and hosted on G2.com.

What do you dislike about Black Duck Polaris Platform?

According to me it has all the features required. It is fast and easy to use. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
II
Verified User in Information Technology and Services
Enterprise (> 1000 emp.)
"What's there in your code?"
4.5/5
What do you like best about Black Duck Polaris Platform?

Blackduck is part of Devonshire which provides us automatic scanning. Black duck is not just for devops but also Secops. Blackduck has the most extensive open source KB in the industry Review collected by and hosted on G2.com.

What do you dislike about Black Duck Polaris Platform?

I am expecting better governance of teams. I have various teams using the capacity and I need to know which team is using how much. Black duck can come up with tenancy. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Verified User in Information Technology and Services
Small-Business (50 or fewer emp.)
"Synopsis is the best platform for VLSI."
4.5/5
What do you like best about Black Duck Polaris Platform?

I have used the tools of Synopsys in the past years, spending most of my time utilizing them. They provide a unique feature that other companies in the present market do not offer. What I have done using these tools is the back-end implementation in VLSI. Their customer support is very good, and they provide solutions when a customer faces issues. They come with many training sessions conducted by trained staff for beginners or those new to the tools. They also provide documentation of the tools for the reader. Review collected by and hosted on G2.com.

What do you dislike about Black Duck Polaris Platform?

License the synopsis and training sessions; the synopsis is a bit costly, which is not affordable to everyone. Review collected by and hosted on G2.com.

SAILEE J.
SJ
SAILEE J.
Scrum Master [Associate]
Small-Business (50 or fewer emp.)
"Need of today’s market"
4.5/5
What do you like best about Black Duck Polaris Platform?

Black duck is certainly an industry leader in open source scanning primarily due to the fact that it is simpler to use and hence eliminate majority open source vulnerabilities and bugs and licensing issues. Should there be any enhancement request Blackduck is fairly adaptive and responsive towards implementing the same. Review collected by and hosted on G2.com.

What do you dislike about Black Duck Polaris Platform?

The reporting could be enhanced as it does not provide the output the way one would expect it to be owing to which, it adds additional overhead to present the result in a better way Review collected by and hosted on G2.com.

Ali s.
AS
Ali s.
Customer Service Representative
Mid-Market (51-1000 emp.)
"Good security, Stable and feature rich."
4.5/5
What do you like best about Black Duck Polaris Platform?

Black duck software composition analysis works amazing on Mac, It has a good security and excellent features that protects and examines our source code from compliance issues. Review collected by and hosted on G2.com.

What do you dislike about Black Duck Polaris Platform?

Black duck should add features like packet analysis and binary analysis for better performance. Review collected by and hosted on G2.com.

Verified User in Computer Software
IC
Verified User in Computer Software
Enterprise (> 1000 emp.)
"Coverity SAST Review"
5/5
What do you like best about Black Duck Polaris Platform?

We use the Coverity Static Analysis tool for security scans of C/C++ server code. Coverity is having a higher detection rate as we highly rely on this code scan for our application code. We had seamlessly integrated this SAST tool (Coverity) to our CI/CD Pipeline and the vulnerabilities were being notified to the respective developer via mail. It provides a mechanism to audit the findings and mark false positives in an efficient way. Support for several languages is one another factor that stands out well when compared to other tools. Time it takes to scan huge code lines is significantly faster compared to other tools. Review collected by and hosted on G2.com.

What do you dislike about Black Duck Polaris Platform?

However there are some improvements points which I thought I should highlight to make this tool even more better for the end users. strzcpy vs. NULL_STRING Coverity does not recognize that strzcpy adds a terminating x00. ab_pfetch* On Windows we currently have many OVERRUN false positives. bsearch on fixed width table vs. Literal Coverity’s model for bsearch assumes that bsearch access the key on the full width of the key. If bsearch is given a fixed (max) size table, and say strcmp as compare function, then in reality when bsearch is called with a small literal as key, then all is good. Alas Coverity thinks that bsearch will read beyond the end of the literal, even though strcmp will not. NO_EFFECT on var_arg On Windows we currently have a NO_EFFECT warning on all uses of va_args TAINTED_SCALAR Coverity to warn for uses of tainted data, data that might be controlled by an attacker. This may lead to data corruption, code injection,... When possible Coverity reports additional defects describing the dangerous use of the tainted data INTEGER_OVERFLOW. RW.LITERAL_OPERATOR_NOT_FOUND on printf with TEL_Format When using TEL defined format such as TEL_Flpu, TEL_Fsu, TEL_Fpid ,... Coverity sometimes requires a space before the 'T' from TEL_Fxxx. TAINTED_STRING Coverity to warn for uses of tainted data, data that might be controlled by an attacker. This may lead to data corruption, code injection, SQL injection, directory traversal, PW.PRINTF_ARG_MISMATCH - * precision or * size vs. size_t or ptrdiff_t parameters 64 bits builds or scans - The C-Standard states that the * precision or size are of type int. This is generally 4 bytes. On 64 bits builds size_t and ptrdiff_t are 8 bytes. If I had submitted a fix yesterday, today’s Coverity Connect continue to report the defect. Review collected by and hosted on G2.com.

Questions about Black Duck Polaris Platform? Ask real users or explore answers from the community

Get practical answers, real workflows, and honest pros and cons from the G2 community or share your insights.

Sabeer B.
SB
Sabeer Bijapur
•
Last activity over 6 years ago

Where we can find documentation of each defensics protocol fuzzing ?

GU
Guest User

What is Coverity used for?

0 Upvotes
0
Join the conversation

Pricing Insights

Averages based on real user reviews.

Time to Implement

4 months

Return on Investment

18 months

Perceived Cost

$$$$$
Black Duck Polaris Platform Comparisons
Black Duck Polaris Platform Features
API / Integrations
Extensibility
Real-Time Analytics
Issue Tracking
Static Code Analysis
Command-Line Tools
Manual Testing
Test Automation