Our relationship with Black Duck
The technology analyzes. Vibe puts the analysis inside the pipeline.
For Vibe, application security analysis is not an external audit that arrives at the end of the project. It is a stage of engineering, run as often as the code is written and integrated.
The technology belongs to Black Duck. Vibe's role is to integrate that analysis into the client's development cycle and take each finding to the people who are able to fix it.
What we deliver
SCA
Composition analysis: open source dependencies and licenses used by the application.
SAST
Static analysis of source code, run in the development pipeline.
IAST
Interactive analysis of the application at runtime, seen from the inside.
DAST
Dynamic testing of the running application, seen from the outside.
MAST
Mobile application security.
Related Vibe solutions
Analysis tools find issues. The team that writes the code is the one that fixes them.
Vibe brings software engineering and security analysis together.
This avoids the scenario in which a company buys the tool, receives hundreds of findings and cannot turn them into fixes, because no one owns the list.
The gains appear when the analysis runs in the pipeline and the result reaches the developer with enough context to become a code change.