[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-0-en-105":3,"doc-seo-138067-105":59,"doc-detail-138067-en":130},{"code":4,"msg":5,"data":6},0,"success",[7,13,18,23,28,33,38,43,48,51,55],{"id":8,"doc_module":4,"doc_module_name":9,"category_name":10,"show_sort_weight":11,"slug":12},1,"Document","Story & Novel",90,"story-novel",{"id":14,"doc_module":4,"doc_module_name":9,"category_name":15,"show_sort_weight":16,"slug":17},2,"Literature",80,"literature",{"id":19,"doc_module":4,"doc_module_name":9,"category_name":20,"show_sort_weight":21,"slug":22},4,"Exam",70,"exam",{"id":24,"doc_module":4,"doc_module_name":9,"category_name":25,"show_sort_weight":26,"slug":27},5,"Comic",60,"comic",{"id":29,"doc_module":4,"doc_module_name":9,"category_name":30,"show_sort_weight":31,"slug":32},6,"Technology",50,"technology",{"id":34,"doc_module":4,"doc_module_name":9,"category_name":35,"show_sort_weight":36,"slug":37},7,"Healthcare",40,"healthcare",{"id":39,"doc_module":4,"doc_module_name":9,"category_name":40,"show_sort_weight":41,"slug":42},8,"Research & Report",30,"research-report",{"id":44,"doc_module":4,"doc_module_name":9,"category_name":45,"show_sort_weight":46,"slug":47},9,"Religion & Spirituality",20,"religion-spirituality",{"id":46,"doc_module":4,"doc_module_name":9,"category_name":49,"show_sort_weight":46,"slug":50},"World Cup","world-cup",{"id":52,"doc_module":4,"doc_module_name":9,"category_name":53,"show_sort_weight":52,"slug":54},10,"Lifestyle","lifestyle",{"id":56,"doc_module":4,"doc_module_name":9,"category_name":57,"show_sort_weight":24,"slug":58},19,"General","general",{"code":4,"msg":60,"data":61},"ok",{"site_id":62,"language":63,"slug":64,"title":65,"keywords":66,"description":67,"schema_data":68,"social_meta":123,"head_meta":125,"extra_data":127,"updated_unix":129},105,"en","nexus-intelligence-vs-black-duck-open-source-security-intelligence-side-by-side-comparison-december-2018","Nexus Intelligence vs Black Duck - Open Source Security Intelligence Side-by-Side Comparison - December 2018","","Large-utility security and application architecture teams evaluated open source risk management tooling by running side-by-side scans on a production application using Sonatype Nexus Intelligence and Black Duck. The comparison quantified component identification and vulnerability accuracy, highlighting tradeoffs between true positives and false positives/false negatives. Results show both tools found nearly all true positives, while Black Duck produced false positives and duplicate vulnerability noise and missed more version-precise detections, reducing actionable remediation focus across the SDLC.",{"@graph":69,"@context":122},[70,84,105],{"@type":71,"itemListElement":72},"BreadcrumbList",[73,77,79,82],{"item":74,"name":75,"@type":76,"position":8},"https://docshare.wps.com","Home","ListItem",{"item":78,"name":9,"@type":76,"position":14},"https://docshare.wps.com/document/",{"item":80,"name":40,"@type":76,"position":81},"https://docshare.wps.com/document/research-report/",3,{"item":83,"name":65,"@type":76,"position":19},"https://docshare.wps.com/document/nexus-intelligence-vs-black-duck-open-source-security-intelligence-side-by-side-comparison-december-2018/138067/",{"url":83,"name":65,"@type":85,"image":86,"author":91,"headline":65,"publisher":94,"fileFormat":97,"inLanguage":63,"description":67,"dateModified":98,"datePublished":99,"encodingFormat":97,"isAccessibleForFree":100,"interactionStatistic":101},"DigitalDocument",{"url":87,"@type":88,"width":89,"height":90},"https://docshare.wps.com/thumbnails/nexus-intelligence-vs-black-duck-open-source-security-intelligence-side-by-side-comparison-december-2018/138067.png","ImageObject",300,407,{"name":92,"@type":93},"Felix Montgomery","Person",{"url":74,"name":95,"@type":96},"DocShare","Organization","application/pdf","2026-09-19","2026-08-23",true,{"@type":102,"interactionType":103,"userInteractionCount":52},"InteractionCounter",{"@type":104},"ViewAction",{"@type":106,"mainEntity":107},"FAQPage",[108,114,118],{"name":109,"@type":110,"acceptedAnswer":111},"What was the utility company trying to achieve with the tool evaluation?","Question",{"text":112,"@type":113},"The team needed a solution to automatically manage security risk for open source software components across the SDLC. It aimed to rapidly identify and remediate application security risks when new public vulnerabilities were disclosed.","Answer",{"name":115,"@type":110,"acceptedAnswer":116},"How did Nexus Intelligence and Black Duck compare on true positives and total components?",{"text":117,"@type":113},"The scan identified 154 components with Nexus Intelligence and 159 with Black Duck. Both tools correctly identified 148 true positives, indicating similar effectiveness at recognizing real vulnerable conditions.",{"name":119,"@type":110,"acceptedAnswer":120},"Why did the company consider Black Duck’s results less actionable?",{"text":121,"@type":113},"Black Duck reported vulnerabilities falsely, including duplicates presented as entirely new issues and version mismatches. These false positives and duplicates would drive developers to spend time investigating and upgrading components that were not actually a threat.","https://schema.org",{"og:url":83,"og:type":124,"og:title":65,"og:site_name":95,"og:description":67},"article",{"robots":126,"canonical":83},"index,follow",{"doc_id":128,"site_id":62},138067,1787473938,{"code":4,"msg":5,"data":131},{"doc_id":128,"user_id":132,"nickname":92,"user_avatar":133,"doc_module":4,"category_id":39,"category_name":40,"doc_title":65,"doc_description":67,"doc_content":134,"file_id":135,"file_url":136,"file_type":137,"file_size":138,"view_count":52,"is_deleted":4,"is_public":8,"is_downloadable":8,"audit_status":8,"page_count":139,"language":140,"language_code":63,"site_id":62,"html_lang":63,"table_of_contents":141,"faqs":142,"seo_title":143,"seo_description":67,"update_tm":129,"read_time":144},549768064778,"https://ap-avatar.wpscdn.com/davatar_6f874abed73319feea01a86fa6f0fab8","Open Source Security Intelligence is NOT Created Equal  \nA SIDE-BY-SIDE COMPARISON OF  \nCOMPETITORS VS. NEXUS  \nThe Challenge  \nThe application architecture team within a large publicly traded utility company was investigating tools to help them automatically manage security risk associated with open source software components and third-party libraries. Specifically, the company wanted a solution that could help them rapidly identify and remediate application security risks across their entire SDLC whenever new open source vulnerabilities are publicly disclosed.  \nTo evaluate potential partners, the company invited Sonatype and Black Duck to participate in a technical proof of concept by scanning one of their production applications. The company then compared the results of the scans side-by-side in order to determine which technology provided the most accurate results.  \nThis document provides a detailed summary of what the company found when comparing the accuracy of Nexus Intelligence versus Black Duck.  \nSummary Report Card:  \nNexus Intelligence vs Black Duck – December 2018  \n\n|  | Nexus Intelligence | Black Duck |\n| --- | --- | --- |\n| Total Components Identified | 154 | 159 |\n| Correctly Identified (True Positives) | 148 | 148 |\n| Vulnerabilities Falsely Identified (False Positives) | 0 | 7 |\n| Vulnerabilities Not Recognized (False Negatives) | 0 | 20 |\n| Final Grade | A+ | D |\n\nThe Result  \nIn an initial comparison of Sonatype’s scan to the Black Duck scan, the number of components identified were nearly equal. However, upon a closer look, the utility company discovered material differences in the vulnerabilities reported and, most importantly, the overall quality of data.  \nThe category of the differences fell into two categories:  \nA competitor scan versus Nexus Lifecycle  \n2  \n1. False Positives – most related to the same vulnerability.  \nFalse positives are common in many security tools, and the bane of software engineers and security. False positives are reports of vulnerabilities where none exist. In open source security, this occurs most often when the vendor poorly matches components and misidentifies a secure component as a similar (vulnerable) component or incorrectly identifies which versions of a component were subject to a vulnerability.  \nThe Black Duck scan did find seven vulnerabilities that were not highlighted in the Sonatype scan. Initially, the utility company felt that by not identifying the same list of potential vulnerabilities Black Duck did, Sonatype had somehow failed to report something meaningful.  \nHowever, digging past the surface, the case wasn’t that Sonatype failed to identify those potential vulnerabilities, they came up in the scan. However, they were noise at the version level the utility company was using and therefore, were left out of the software Bill of Materials. Further to the point, Sonatype noted that five of the seven vulnerabilities reported on the Black Duck scan were duplicate copies of vulnerability CVE-2017-7525 and were listed in an attempt to cover all use cases. While this is useful for research, it is important to note that with more precise data, it’s possible to report only the correct version range and classes, creating more actionable and focused scan results. The bottom line? Sonatype found the same potential vulnerabilities, but precise data applied to the utility company’s specific code base eliminated noise from the Nexus scan.  \nUnfortunately, with duplicate false positives that are presented as entirely new vulnerabilities, the utility company’s developers would likely spend their valuable time researching and attempting to upgrade components that did not actually pose a threat, in this case, five times over. More inconceivably, the development team may be asked to chase down duplicate false positives when real threats (false negatives) exist in the code base but were not detected by the Black Duck scan.  \nIn contrast, as a result of Sonatype’s curated, a","cbCaifFi0nrHoUnW","https://ap.wps.com/l/cbCaifFi0nrHoUnW","pdf",1900601,11,"English","# The Challenge\n## Proof of Concept Setup\n# Summary Report Card\n## Results at a Glance\n# The Result\n## Component and Vulnerability Accuracy\n## False Positives and Version Precision\n# Broad Scope and False Recognition\n## Breakdown of Black Duck False Positives","[{\"question\":\"What was the utility company trying to achieve with the tool evaluation?\",\"answer\":\"The team needed a solution to automatically manage security risk for open source software components across the SDLC. It aimed to rapidly identify and remediate application security risks when new public vulnerabilities were disclosed.\"},{\"question\":\"How did Nexus Intelligence and Black Duck compare on true positives and total components?\",\"answer\":\"The scan identified 154 components with Nexus Intelligence and 159 with Black Duck. Both tools correctly identified 148 true positives, indicating similar effectiveness at recognizing real vulnerable conditions.\"},{\"question\":\"Why did the company consider Black Duck’s results less actionable?\",\"answer\":\"Black Duck reported vulnerabilities falsely, including duplicates presented as entirely new issues and version mismatches. These false positives and duplicates would drive developers to spend time investigating and upgrading components that were not actually a threat.\"}]","Nexus Intelligence vs Black Duck - Open Source Security Intelligence Side-by-Side Comparison - December 2018 | PDF",28]