
October
27–29
2026
Meet Lexington Soft at the Intelligent Vehicle Expo
Novi, Michigan
Connect with ADAS engineers, AV developers, and automotive tech decision-makers.
BOOTH
AV722
Black Duck Software Composition Analysis (SCA)
Black Duck (SCA) helps organizations identify and manage security, license compliance, and code quality risks associated with open-source software containers, and third-party components.
Supports Cyber Resilience Act (CRA) Initiatives:
- Generate and maintain SBOMs throughout the software lifecycle
- Continuously monitor open-source vulnerabilities
- Gain visibility across source code, binaries, and containers
- Enforce security and open-source license policies
- Prioritize and remediate software vulnerabilities
- Produce evidence and reports for CRA conformity assessments
Complete the form below to request a evaluation
| Establish Visibility |
|---|
| Dependency analysis |
| Binary & container analysis |
| CodePrint™ & snippet analysis |
| C/C++ dependency analysis & AI model discovery |
| Manage Risk |
|---|
| Identify known vulnerabilities |
| Detect malicious components |
| Identify license conflicts |
| Prioritize remediation |
| Build Trust |
|---|
| Generate SBOMs (SPDX & CycloneDX) |
| Enforce security & license policiestd> |
| Support regulatory compliancetd> |
| Strengthen Software supply chain governance |
Strengthen Software Supply Chain Security
- Complete software dependency visibility
- Automated SBOM generation and lifecycle management
- Continuous monitoring of open-source vulnerabilities
- Open-source license compliance
- Policy-driven software governance
- AI and third-party component visibility
By providing comprehensive visibility into software dependencies, Black Duck enables teams to strengthen software supply chain security while accelerating secure software delivery.
Copyright © 2026 Lexington Soft. All rights reserved.




