Skip to content
Notifications
Clear all

Black Duck or Mend for a large enterprise with many proprietary licenses?

3 Posts
3 Users
0 Reactions
0 Views
(@bearclaw)
Reputable Member
Joined: 3 weeks ago
Posts: 217
Topic starter   [#24580]

Been through three enterprise license audits. Picked up the pieces after both tools.

Black Duck's license detection is more thorough if you have truly weird proprietary licenses. Mend's vulnerability matching is faster out of the box, but its license reporting feels like it was designed by lawyers who've never seen a build log.

The real question is your pipeline. Black Duck will make your builds weep if you don't tune the living daylights out of it.

```xml

./
node_modules,*.min.js
true

```

Mend integrates cleaner. But "cleaner" here just means the dashboard loads before you get a coffee.

Neither handles monorepos gracefully without significant scripting. You're buying a liability scanner, not a solution. Plan for a full-time person to manage the false positives either way.


Prove it.


   
Quote
(@crmsurfer_43)
Reputable Member
Joined: 5 months ago
Posts: 218
 

Yeah, the point about needing a full-time person to manage it really resonates. We went with Mend hoping for less overhead, but the license reporting gaps created more manual review work than we saved on the vuln side. It's a trade-off either way, like you said.

Has anyone on your team actually gotten the Black Duck build integration to run at a reasonable speed, or is it always a trade-off between thoroughness and pipeline meltdown?



   
ReplyQuote
(@blakev)
Estimable Member
Joined: 3 weeks ago
Posts: 138
 

Completely agree on the pipeline point. We run Black Duck in a nightly batch job instead of during builds - the integration is just too heavy for our CI. Even then, the "license detection is more thorough" line is a double-edged sword. You get amazing coverage on weird licenses, but you also get flagged for every single "see LICENSE file" mention in comments, which creates a ton of noise. Our legal team loves it, engineering hates it.

So your tuning example is spot on. But I'd add it's not just about file excludes, you have to become a pro at their policy rule builder to stop the alert fatigue.


Automate the boring stuff.


   
ReplyQuote