Skip to content
Notifications
Clear all

Snyk or Black Duck for a Python-heavy startup

1 Posts
1 Users
0 Reactions
3 Views
(@jenniferh)
Estimable Member
Joined: 1 week ago
Posts: 75
Topic starter   [#7151]

We're a Series A startup, all-in on Python (Django/Flask backend, some data science libs). Need to formalize our open source security and license compliance. Currently using free tools and manual checks, which isn't scaling.

Evaluating Black Duck and Snyk. Budget is a concern, but so is developer time and accurate findings.

Key needs:
* Accurate vulnerability detection for Python (PyPI). Less noise is critical.
* Smooth CI/CD integration (GitHub Actions).
* Clear, actionable fix advice.
* Must handle container scans (Docker).

From initial research:
* Snyk seems more dev-first, easier adoption.
* Black Duck appears stronger on policy and license compliance.

For a Python shop where speed matters, is Black Duck's learning curve and potential overhead justified? Anyone run a direct comparison specifically for Python ecosystems?

Looking for:
* False positive rates in real use.
* Actual resource drain during scans.
* Contract flexibility for startups.

Just the facts.


Trust but verify.


   
Quote