Secure and manage open source risks in applications and containers with Black Duck SCA | Synopsys

Поділитися
Вставка
  • Опубліковано 8 вер 2024

КОМЕНТАРІ • 2

  • @miguelcamacho3381
    @miguelcamacho3381 Рік тому +5

    BlackDuck does not recognize the rc versions declared in the pom.xml?
    I scan project with Jackson Databind - 2.14.0-rc1 but BlackDuck recognize as version 2.13.0

    • @arturoruiz6274
      @arturoruiz6274 3 місяці тому

      Mitigating all the false positives it yields from scans is one of the mainly efforts you'll have to focus when using this tool. Also, match types are not clear. There is no context provided in regards to a "file modified", "exact match" or the like. It simply does not really look into source code or other files.