October

27–29

2026

Meet Lexington Soft at the Intelligent Vehicle Expo

Novi, Michigan

Connect with ADAS engineers, AV developers, and automotive tech decision-makers.

BOOTH

AV722

Black Duck Software Composition Analysis (SCA)

Black Duck (SCA) helps organizations identify and manage security, license compliance, and code quality risks associated with open-source software containers, and third-party components.

Supports Cyber Resilience Act (CRA) Initiatives:

  • Generate and maintain SBOMs throughout the software lifecycle
  • Continuously monitor open-source vulnerabilities
  • Gain visibility across source code, binaries, and containers
  • Enforce security and open-source license policies
  • Prioritize and remediate software vulnerabilities
  • Produce evidence and reports for CRA conformity assessments

Complete the form below to request a evaluation

    Establish Visibility
    Dependency analysis
    Binary & container analysis
    CodePrint™ & snippet analysis
    C/C++ dependency analysis & AI model discovery
    Manage Risk
    Identify known vulnerabilities
    Detect malicious components
    Identify license conflicts
    Prioritize remediation
    Build Trust
    Generate SBOMs (SPDX & CycloneDX)
    Enforce security & license policiestd>
    Support regulatory compliancetd>
    Strengthen Software supply chain governance

    Strengthen Software Supply Chain Security

    • Complete software dependency visibility
    • Automated SBOM generation and lifecycle management
    • Continuous monitoring of open-source vulnerabilities
    • Open-source license compliance
    • Policy-driven software governance
    • AI and third-party component visibility

    By providing comprehensive visibility into software dependencies, Black Duck enables teams to strengthen software supply chain security while accelerating secure software delivery.

    1a
    1a
    2b
    3c
    4d
    5d
    previous arrow
    next arrow