Which automated tool should you add to the build pipeline to detect common open-source libraries and address licensing compliance concerns?
Choose an answer
Tap an option to check your answer.
Correct answer: WhiteSource Bolt.
Why this is the answer
WhiteSource Bolt is a Software Composition Analysis (SCA) tool specifically designed to identify open-source components, their licenses, and potential vulnerabilities within your codebase. Integrating it into a build pipeline automates the process of ensuring licensing compliance and managing open-source risks. OWASP ZAP is a dynamic application security testing (DAST) tool, focusing on finding vulnerabilities in running web applications, not open-source license compliance. Jenkins is a general-purpose automation server used for continuous integration and continuous delivery (CI/CD), but it doesn't inherently perform SCA or license checks; it would orchestrate a tool like WhiteSource Bolt. Code Style tools enforce coding standards but do not address open-source licensing.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed