Hi [[ session.user.profile.firstName ]]

Black Duck Software

  • Date
  • Rating
  • Views
  • Black Duck MasterClass - Open Source Security for Containers and Applications
    Black Duck MasterClass - Open Source Security for Containers and Applications Tim Mackey, Senior Technology Evangelist, Black Duck Recorded: Sep 19 2017 56 mins
    Managing container infrastructure in a production environment is challenged by problems of scale. One of the biggest problems is trust—specifically trust of the application. To put it another way, can you trust that all containers in your Kubernetes or OpenShift cluster are performing the tasks you expect of them? We know that containerization has increased the pace of deployment, but has trust kept pace? If a container becomes compromised in some fashion, how many other containers are at risk and how far has trust been broken?

    Tim Mackey explores the nature of data center threats, why threat models fail, how malicious attackers design their attacks, when the threat risk increases prior to attack and why information flow matters, and how traditional defenses are inadequate for container workloads. Tim then shares measures you can take to proactively identify risks, including OpenShift integrated tooling to identify container images with increased risk.
  • Black Duck Hub 4.0: Ready for the Enterprise
    Black Duck Hub 4.0: Ready for the Enterprise Pat Durante, Senior Director Education Services; John Beaudoin, Senior Instructional Designer Recorded: Aug 10 2017 58 mins
    Join our upcoming Black Duck Customer Webinar exploring the new functionalities in Hub 4.0. Learn how the Hub is delivering additional value to enterprise customers who want to run the Hub at scale and within their existing IT infrastructure. We’ll demo new features including an improved user experience, more comprehensive reporting, security and license risk management and recent updates to our Hub integrations.

    Explore These Hub 4.0 UX Advancements:
    Executive Dashboard
    Report Database
    Enterprise Improvements
    Security Risk Management
    License Compliance Management
    Cloud Platform and Docker Inspector Integrations
  • Healthcare and Open Source – Balancing Innovation Against Risk
    Healthcare and Open Source – Balancing Innovation Against Risk Jim DeGraw, Partner, Ropes & Gray; Mike Pittenger, VP Security Strategy, Black Duck Recorded: Aug 8 2017 59 mins
    More and more innovation in the healthcare industry is powered by open source software, whether it’s for a new pacemaker or the latest Electronic Medical Records (EMR) platform.

    A recent study of more than 1,000 commercial software applications found that open source components comprised 46% of the code in commercial applications for healthcare-related industries. But with innovation comes risk. The same research uncovered high-risk open source security vulnerabilities in 47% of the healthcare applications studied.

    A focused approach to managing open source risk is essential as HIPAA and the European Union’s General Data Protection Regulation (GDPR) put new pressures on healthcare providers and technology companies to protect patient data privacy and security.

    If you're concerned with healthcare application security, learn why open source management is essential for your overall security strategy.
  • GDPR and Open Source: Best Practices for Security and Data Protection
    GDPR and Open Source: Best Practices for Security and Data Protection Daniel Hedley, Partner, Irwin Mitchell; Matt Jacobs, VP and General Counsel, Black Duck Software Recorded: Jul 25 2017 60 mins
    Legislators in Europe continue to expand the scope of the laws governing information security and personal data protection. As a result, organizations serving consumers and businesses in the region need to understand the implications these laws will have on their use of open source to build software applications.

    During this educational webinar led by Dan Hedley, Partner, IT and Commercial from Irwin Mitchell, we’ll provide guidance on the General Data Protection Regulation (GDPR) and why a comprehensive approach to open source security management is essential for GDPR observance. In addition, we’ll review open source management best practices in context of other industry-specific developments like the Network and Information Services Directive and the Electronic Identification Regulation.
  • Container Security – Best Practices for Government Agencies
    Container Security – Best Practices for Government Agencies Jamie Duncan, Cloud Solutions Architect, Red Hat; Tim Mackey, Sr. Technology Evangelist, Black Duck Recorded: Jul 13 2017 64 mins
    Local and Federal government agencies are increasingly turning to container environments to meet the demand for faster, more agile software development. However, containers present a new array of security challenges, including how to properly manage open source security risk.

    Join experts from Red Hat and Black Duck for an educational webinar on securing open source in your containers.

    · Why container environments present new application security challenges, including those posed by open source
    · How to scan applications running in containers to identify open source and map against known vulnerabilities
    · Best practices and methodologies for deploying secure containers
  • 3 Pro Tips for Black Duck Hub & Ask the Experts
    3 Pro Tips for Black Duck Hub & Ask the Experts Black Duck Product and Implementation Team Recorded: Jun 27 2017 46 mins
    Join our next customer webinar where YOU are the star of the show! Our Ask the Experts panel features Hal Hearst, Principal Product Manager; Utsav Sanghani, Product Manager; and Don Mulrenan, Manager Implementation Services. They’ll present their top three tips for scanning your code, helping you use Black Duck Hub’s features most effectively. We’ll leave plenty of time for Q&A with the panel. Submit your questions now by emailing jenny@blackducksoftware.com, or ask them during the webinar. We’re excited to have this opportunity to answer your questions and hear your feedback about Black Duck Hub. Register today.
  • The Results Are In: Open Source 360 Survey
    The Results Are In: Open Source 360 Survey Tim Mackey, Sr. Technology Evangelist, Black Duck; Bob Canaway, CMO, Black Duck Recorded: Jun 22 2017 60 mins
    Today, open source drives technology and development, and its worldwide adoption ranges from companies with a single employee to large corporations like Microsoft and Apple. All of these organizations rely on open source to innovate, reduce development costs, and speed time to market. Recent research reports point out that open source comprises 80% to 90% of the code in a typical application. Our Open Source 360° survey provides an update on the rapid evolution of open source development, use and management.

    The 2017 Open Source 360° survey was conducted through Black Duck’s Center for Open Source Research & Innovation (COSRI), focusing on four important areas of open source – usage, risk, contributions and governance/policies. Our respondents include input from new players, established leaders, and influencers across vertical markets and communities. This range of respondents drives broad industry awareness and discussions of these key issues.

    Please join Technology Evangelist Tim Mackey (@timintech) and CMO Bob Canaway (@bobcanaway) to review the results from the Open Source 360 Survey. Please bring your questions! 

    Follow the conversation on Twitter, using the hashtag #OSS360.
  • Prepping for Tech M&A – What Buyers and Sellers Need to Know
    Prepping for Tech M&A – What Buyers and Sellers Need to Know Steven S. Fang Sr. Counsel Kastner Huggins Reddien Gravelle LLP; Phil Odence VP & General Manager Black Duck Software Recorded: Jun 13 2017 58 mins
    In potential tech M&A transactions, both buyers and sellers are focused on the IP quality and security of the most valuable asset – software. Both are extremely important to the sellers, who are looking for the best price, and to acquirers, who want to ensure a future return on their investment.

    During this webinar, open source experts from Black Duck and the Austin legal firm KHRG will discuss best practices as well as pitfalls to avoid to protect IP quality and security. The session will include:

    - Security and license compliance issues to consider when using open source
    - Best practices for ensuring ongoing management of open source licenses and security
    - Latest trends in open source software use by developers
    - Examples of how improper code management has impacted software acquisitions
    - Anatomy of the M&A technical due diligence process and how best to prepare
  • Why Software Composition Analysis is Critical to Secure DevOps
    Why Software Composition Analysis is Critical to Secure DevOps Amy DeMartine, Forrester Principal Analyst; Patrick Carey, Black Duck Recorded: May 16 2017 37 mins
    Open source software is the lifeblood of today’s enterprise applications, comprising 80%-90% of the code. However, open source use comes with significant security and IP risks that both enterprise and smaller organizations are ill-prepared to address.

    As development teams increasingly automate the software development lifecycle (SDLC) through the use of agile DevOps tools and practices, the need to mitigate these risks through integration of Software Composition Analysis (SCA) into the DevOps tool chain has become critical.

    In this 60-minute webinar, guest speaker, Forrester Principal Analyst Amy DeMartine, and Black Duck Director of Product Marketing Patrick Carey, will discuss findings from the recent report: The Forrester Wave™: Software Composition Analysis, Q1 2017 and why SCA should be a key part of your Secure DevOps strategy.

    The discussion topics will include:
    - Why you need a software composition analysis (SCA) solution
    - How SCA solutions help you manage open source vulnerability, compliance, and component quality risks
    - Criteria to consider when selecting an SCA solution
    - Why it's important to integrate SCA into your automated DevOps environment
  • Leveraging Reporting Improvements and Docker Scanning using Hub 3.6
    Leveraging Reporting Improvements and Docker Scanning using Hub 3.6 Pat Durante, Senior Director Education Services; John Beaudoin, Senior Instructional Designer Recorded: May 11 2017 54 mins
    Please join us for the next Black Duck Customer Success Webinar and learn about the features and enhancements in the latest Hub release – version 3.6. It includes new usability and project management improvements as well as administration and integration enhancements.

    We’ll discuss:

    - Leveraging the new Hub Reporting Database to programmatically access project, project version, component version, and component license data for custom data reporting and analysis.
    - Taking advantage of the new Print View option which displays the Bill of Materials in a format suitable for easy printing or exporting.
    - Adding subprojects to your Bill of Materials. For example, if you have projects used by other applications, you can add them to a BOM so that the BOM accurately reflects the elements in your application.
    - Using the updated Hub 3.6 Scan Client to scan Docker Images. We’ve introduced a new script, bundled with the Hub Scanner, to scan your Docker images for open source.

Embed in website or blog