Which tool should you add to the build pipeline to automatically detect when commonly used open-source libraries are introduced to the codebase for licensing compliance?
Choose an answer
Tap an option to check your answer.
Correct answer: Black Duck.
Why this is the answer
Black Duck by Synopsys is a Software Composition Analysis (SCA) tool specifically designed to identify open-source components within a codebase, manage their licenses, and detect security vulnerabilities. Integrating Black Duck into a build pipeline automates the scanning process, ensuring compliance with licensing policies and identifying potential risks early in the development lifecycle. Microsoft Visual SourceSafe is an outdated version control system, not an SCA tool. Code Style refers to coding conventions and formatting, unrelated to open-source license compliance. Jenkins is an automation server used for continuous integration and continuous delivery (CI/CD), but it does not inherently provide SCA capabilities; it would orchestrate a tool like Black Duck.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed