
I like that Black Duck SCA makes it easy to identify vulnerable open-source dependencies and keeps track of newly discovered security issues. The reports are clear, and the CI/CD integration fits well into the development workflow. It also helps with license compliance, which is a big plus. The AI-powered insights are useful for understanding and prioritizing risks. The only downside is the pricing—it can be expensive, especially for smaller teams, but the features and visibility it provides make it worthwhile for larger organizations. Review collected by and hosted on G2.com.
One thing I don't like is the pricing—it can be quite expensive, especially for smaller teams. The initial setup and configuration also take some time, and the interface can feel a bit overwhelming for new users. Occasionally, there are false positives that need manual review, and I'd like to see faster scans and more intuitive reporting and dashboards. Overall, it's a solid tool, but there's definitely room to improve usability and cost. Review collected by and hosted on G2.com.