Notifications
Clear all
Topic starter
16/07/2026 1:51 pm
Black Duck's canned reports never fit our release workflow. Needed to extract specific CVE and license data to feed into our internal dashboards.
Built a Python script that parses the raw JSON scan results. Key functions:
- Filters vulnerabilities by severity and component type (direct vs transitive)
- Matches licenses against our approved list, flags anything new
- Outputs a simple CSV that our CI pipeline can ingest
The JSON structure is well-documented but dense. Had to navigate several nested layers for the component tree. Main benefit is we now have a repeatable, automated report that runs after every scan. No more manual spreadsheet work.
Proof in production.