Code Sight with Black Duck SCA

欢迎来到 Code Sight

Synopsys Code Sight 提供了一种运行 Synopsys 扫描工具的便捷方式,有助于提高源代码的安全性和可靠性。

Code Sight 显示它在您正在使用的开发环境的界面中运行的扫描结果。

有关详细信息,请参阅以下部分:

Code Sight with Black Duck SCASynopsys is proud to announce Black Duck SCA (software composition analysis) tools in the Code Sight plug-in. These tools help maintain OSS security compliance by identifying known vulnerabilities in OSS components and policy violations.. Once installed, Black Duck SCA tools can work alongside Coverity tools to add coverage for vulnerable OSS components.. After installation, your first Black Duck scan will begin as soon as you open a file. The scan will run in the background to identify policy violations and vulnerable components listed in build configuration files.Click a component in the issue list.. This component shows 3 issues detected. There are 2 security vulnerabilities and 1 policy violation. Each can be expanded to provide more detail, such as descriptions and links to Black Duck KnowledgeBase entries.. The Fix It button provides access to instructions for the vulnerability. Once the vulnerability is fixed, you can Re-Scan to confirm your scan is up to date.Click Fix It.. Software component issues are typically resolved by upgrading to a newer component version, or switching to a different component. This is normally updated via the build configuration file.. When supported, you have the option to Auto-fix, otherwise manual advice is always provided to resolve the issue. Auto-fix will upgrade to the recommended component version and then re-scan.Click Fix and Rescan.. After a change is made to your configuration file and saved, you will see Black Duck running a new scan. This scan will check the current component versions and any no longer used versions will be removed from the issues list.. You have resolved this OSS issue and it has disappeared from the list. Nice work!. If you ever wonder how current your Black Duck SCA scan results are, you can check them in Status > Scans. Click Status.. The Scans view shows all of your recent scan results and current status. At the bottom, you can see that a Black Duck full scan just completed successfully.. The Code Sight plug-in with Black Duck SCA allows you to easily manage open source software components. It automatically finds policy violations, vulnerabilities in OSS components, and notifies you in the IDE so that they can be fixed immediately.. Thank you. You can find more information on Code Sight at the link below.https://sig-docs.synopsys.com/codesighthttps://www.iorad.com/player/1759098/Code-Sight-with-Black-Duck-SCA?#trysteps-3

Support MatrixThese tables show the IDEs, platforms, and Synopsys products that support the current release of Code Sight.https://sig-docs.synopsys.com/codesight/topics/support_matrix/r_code_sight_support_matrix.html

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值