Integrate Black Duck with Vulnetix. Use Synopsys Detect CLI to scan projects and export CycloneDX or SPDX SBOMs from the Black Duck platform for upload to Vulnetix.
Run Black Duck in CI
Scan on every push and upload the report as a workflow artifact:
- name: Run Black Duck Detect
uses: blackduck-inc/black-duck-security-scan@v2
with:
url: ${{ secrets.BLACKDUCK_URL }}
api_token: ${{ secrets.BLACKDUCK_API_TOKEN }}
github_token: ${{ secrets.GITHUB_TOKEN }}
- name: Upload report
uses: actions/upload-artifact@v6
with:
name: blackduck
path: blackduck-bom.cdx.json
if-no-files-found: warn
env:
VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}Then one publish job hands every artifact in the run to Vulnetix, recorded under Black Duck's own name and version. Written once per workflow, however many scanners you run:
publish:
name: Publish to Vulnetix
runs-on: ubuntu-latest
needs: [scan] # every scanner job, or its report is never published
if: always() # or one failing scanner suppresses all the others
permissions:
contents: read
actions: read # required to list the run's artifacts
env:
VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
steps:
- uses: actions/checkout@v5
- name: Install Vulnetix CLI
run: |
curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Publish scanner reports
env:
GITHUB_TOKEN: ${{ github.token }}
run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --jsonAfter the run, vulnetix gha status reports what was actually recorded.
How Vulnetix compares: better together
Vulnetix does not replace Black Duck. Keep running it. Vulnetix sits on top of Black Duck (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
Black Duck is strongest at its core category and also carries features in License Compliance, Container & Image Scanning, SBOM Generation, just as Vulnetix spans categories.
| Capability | Vulnetix | Black Duck |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✓ Enterprise SCA via Synopsys/Black Duck Detect with dependency, snippet and binary analysis |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ~ Black Duck Binary Analysis scans Docker/OCI containers and can fetch images from registries by name/label |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✓ Deep license identification, obligation and policy management across the KnowledgeBase |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✓ Exports and imports CycloneDX (to 1.6) and SPDX (to 2.3) SBOMs |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ~ Binary analysis and BDSA contextual tagging surface 'malicious code identified' components |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✓ BDSA adds temporal scores, exploit-availability flags, vulnerability age and CISA KEV notation |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ~ Java-only reachability analysis demotes findings in unreachable code paths |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ~ VEX supported to track vuln status across versions and manage exceptions |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ~ BDSA remediation guidance (fixed versions, patches, workarounds); Polaris adds automated remediation, not full fix-PR automation across ecosystems |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What Black Duck does well
- Snippet-level and binary matching detects copied/AI-generated open-source code and components in binaries and firmware that manifest-based scanners miss
- KnowledgeBase indexes millions of open-source projects and components across tens of thousands of forges for deep, accurate component identification
- Black Duck Security Advisories (BDSA), curated by its research center, deliver earlier/richer advisories than NVD with fixed versions, exploits, workarounds and CISA KEV flags
- Mature open-source license governance and policy enforcement built for complex enterprise compliance
Where Vulnetix adds to it: Vulnetix consumes Black Duck's SBOMs, BDSA findings and license data and dedups them with SAST/secrets/IaC/cloud results into a single prioritised queue. Better together: Black Duck's snippet/binary matching and KnowledgeBase remain the deep-scan engine while Vulnetix adds cross-scanner EPSS/KEV/ESS/LEV prioritisation, Safe Harbour autofix PRs and SSVC policy on top.
No migration, no rip-and-replace. Black Duck keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise Black Duck results in Vulnetix
Upload Black Duck CycloneDX, SPDX output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.