TrustRadius: an HG Insights company

Black Duck Software Composition Analysis (SCA) vs. SonarQube for IDE

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    Black Duck Software Composition Analysis (SCA)

    Score10 out of 10
    N/ABlack Duck is a software composition analysis tool acquired and now supported by Synopsys since 2017.N/A

    SonarQube for IDE

    Score8.1 out of 10
    N/ASonarQube for IDE is a free IDE plugin that helps developers by detecting and highlighting issues in their code in real time. Like a spell checker, SonarLint detects Bugs, code smells, and Security Vulnerabilities as code is written, and offers guidance.

    $0

    Pricing
    Black Duck Software Composition Analysis (SCA)SonarQube for IDE
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    Black Duck Software Composition Analysis (SCA)SonarQube for IDE
    Free Trial
    NoYes
    Free/Freemium Version
    NoYes
    Premium Consulting/Integration Services
    YesNo
    Entry-level Setup FeeOptionalNo setup fee
    Additional DetailsContact the Synopsys Software Integrity Group (SIG) Sales team at https://www.synopsys.com/software-integrity/contact-sales.html for more detailed pricing information.
    More Pricing Information
    User Ratings
    Black Duck Software Composition Analysis (SCA)SonarQube for IDE
    Likelihood to Recommend
    10.0
    (5 ratings)
    8.0
    (1 ratings)
    Usability
    8.0
    (1 ratings)
    -
    (0 ratings)
    Support Rating
    8.2
    (2 ratings)
    -
    (0 ratings)
    User Testimonials
    Black Duck Software Composition Analysis (SCA)SonarQube for IDE
    Likelihood to Recommend
    Black Duck Software
    If you are using a lot of open-source libraries, which is most likely, this is a must-have to ensure no known vulnerabilities slip into production
    Incentivized
    Read full review
    SonarSource Sarl
    No answers on this topic
    Pros
    Black Duck Software
    • Quick inventory scan: Black Duck helps us scan the code repositories in no time. And quickly list the components and I now really know what is in my code.
    • Security and License risk management: Black Duck being rich in its knowledge base about the vulnerabilities and license issues of open source components, quickly compares the identified inventory to the Black Duck knowledge base and lists all the vulnerabilities and license issues in the code.
    • Integration for automatic scanning: Black Duck is part of devops which provides us automatic scanning. Black Duck is not just for devops but also SecOps.
    Incentivized
    Read full review
    SonarSource Sarl
    • SonarLint highlights all the issues in our codes and also displays the severity of each issue.
    • SonarLint also provides suggestions for how to fix those code issues which are highlighted.
    • SonarLint starts the processing of the file as soon as it is opened and highlights all the issues which it found.
    • When we fix the issue, we don't even need to create a new build or generate fresh code quality report, as soon as we save the file with the changes, it does the processing again and shows the result if the issue is fixed or not.
    • SonarLint saves a lot of time and effort by saving us from doing fresh build every time and generating new code quality report every time, thus increasing the efficiency and output which is in return beneficial for the client.
    Incentivized
    Read full review
    Cons
    Black Duck Software
    • License model based on usage is costly.
    • Documentation is extensive, but often confusing.
    • Black Duck Hub could use some feature improvements for more robust governance capabilities
    Incentivized
    Read full review
    SonarSource Sarl
    • Sometimes, SonarLint does not highlight the issues in the code correctly.
    • The severity of the issues highlighted is according to the default rules set, we should also be given authority to set the severity of the issues.
    • The default fixes which SonarLint provides should be more enhanced and there should be more fixes available.
    • Sometimes it takes a lot of time for processing of the file when any new file is loaded or changes are saved in a file.
    Incentivized
    Read full review
    Usability
    Black Duck Software
    If you don’t know how to scan for the language, it isn’t entirely user friendly
    Incentivized
    Read full review
    SonarSource Sarl
    No answers on this topic
    Support Rating
    Black Duck Software
    Support seems very responsive.
    Incentivized
    Read full review
    SonarSource Sarl
    No answers on this topic
    Alternatives Considered
    Black Duck Software
    Black Duck is an obvious choice, with its versatility, integration, best enterprise support and on top of the list the knowledge base Black Duck has. Vega or Grabber also scans the application and tells about vulnerabilities. But it can never be compared with the feature set of Black Duck. Black Duck can also generate reports.
    Incentivized
    Read full review
    SonarSource Sarl
    SonarLint works along with SonarQube
    Incentivized
    Read full review
    Return on Investment
    Black Duck Software
    • It is hard to measure ROI since Black Duck Hub saves us from costly legal battles that have thankfully never had to happen.
    Incentivized
    Read full review
    SonarSource Sarl
    • SonarLint helps in achieving all the business requirements in a more efficient way.
    • It reduces the manual and redundant work which we would have to do else every time if we did not use SonarLint.
    • SonarLint helps in maintaining code quality, and thus also highlights the loopholes for the cyber attacks and phishing attacks.
    • SonarLint makes work easy and helps the developer to invest less time in manual work thereby increasing their capacity to deliver the maximum output to the client.
    Incentivized
    Read full review
    ScreenShots

    Black Duck Software Composition Analysis (SCA) Screenshots

    Screenshot of Black Duck helps you find and fix your highest-priority vulnerabilitiesScreenshot of Use Black Duck to comply with open source license obligations and to verify compliance with all open source license  termsScreenshot of Black Duck automatically creates tickets in your activity tracking applications like Jira for both policy violations and vulnerabilitiesScreenshot of Black Duck's vulnerability ImpactAnalysis indicates whether a vulnerability is actually being called by your applicationScreenshot of The Black Duck security advisory gives the information you need to address security risks and make the fixScreenshot of Black Duck generates a Bill of Materials which gives you a complete and detailed inventory of all open source identified in your codebase

    SonarQube for IDE Screenshots

    Screenshot of where SonarQube for IDE identifies and highlights issues in a Java project within VS Code. It also explains why this is an issue, how to fix it, and offers more educational content to help developers grow. SonarLint uncovers issues in over 30 languages, frameworks and IaC platforms. SonarLint is available for VS Code, Visual Studio, Eclipse and JetBrains IDEs.Screenshot of how when connected to either SonarCloud or SonarQube the developer can leverage  SonarQube for IDE to identify complex bugs, share code quality expectations with their team, perform deeper issue analysis, enjoy smart notifications, and unlock additional language analysis opportunities. Connecting is easy and guided for a rapid setup, as seen here in the image.