Vendor Sheet
Black Duck GitHub Security Integration: Automating Security in Developer Workflows
This datasheet describes the Black Duck Security GitHub App, which integrates application security testing directly into GitHub workflows. It enables automated SAST and SCA scans triggered by commits and pull requests, with results displayed as PR comments and automated fix suggestions. As shown on page 2, the setup process allows users to configure scans, select repositories, and integrate with Black Duck tools. The app supports bulk onboarding and policy enforcement, including the ability to fail builds when violations occur. Overall, it improves security visibility while maintaining developer productivity through seamless automation.
