I was just setting up a new Black Duck project to track some container images, and the UI kept asking me to create a "version" inside it. Coming from a cloud cost background where we tag resources by project and environment, this got me thinking—how are these two concepts distinct in Black Duck? After poking around, here's my breakdown.
Think of a **Project** as the overall container for your application or service. It's the highest-level logical grouping. For example, you'd have a single project named "customer-portal-api."
A **Version** is a specific snapshot or release of that project. Under the "customer-portal-api" project, you'd have versions like:
* `1.0.0`
* `2.1.0`
* `main` (for your active development branch)
Why does this separation matter? From a FinOps perspective, it's about granularity and history. You can track the bill of materials (BOM) and associated policy violations for each release independently. This lets you see if a new vulnerability was introduced in version 2.1.0 that wasn't in 1.0.0, which is crucial for understanding risk (and potential future "cost" of remediation) over time.
In practice, when you use the API or automation scripts, you often target a specific version for scans. The project acts more as an organizer. Here's a simplified curl example targeting a version:
```bash
curl -X POST "https://your-blackduck/api/projects/customer-portal-api/versions/2.1.0/codelocations"
```
So, project = the *what* (the application). Version = the *when* or *which iteration* (the release). You need both to get a precise fix on your open source components.