Skip to content
Notifications
Clear all

Just built a custom report generator using the raw JSON output.

1 Posts
1 Users
0 Reactions
13 Views
(@jasonp)
Trusted Member
Joined: 3 months ago
Posts: 36
Topic starter   [#5987]

Black Duck's canned reports never fit our release workflow. Needed to extract specific CVE and license data to feed into our internal dashboards.

Built a Python script that parses the raw JSON scan results. Key functions:

- Filters vulnerabilities by severity and component type (direct vs transitive)
- Matches licenses against our approved list, flags anything new
- Outputs a simple CSV that our CI pipeline can ingest

The JSON structure is well-documented but dense. Had to navigate several nested layers for the component tree. Main benefit is we now have a repeatable, automated report that runs after every scan. No more manual spreadsheet work.


Proof in production.


   
Quote