Back to integrations
    SCASAST

    Black Duck Polaris integration

    Get an exploitability verdict with evidence for Black Duck Polaris SCA findings and Coverity SAST findings.

    Integration details

    Primary category

    Software Composition Analysis

    Sync direction

    Black Duck → Konvu

    Konvu imports Polaris findings once a day through its on-prem broker with a read-only token. Verdicts go out as fix pull requests, Slack alerts, and through the Konvu API.

    Status

    Available

    Which Polaris findings need a fix, and which can be closed?

    Black Duck Polaris reports known vulnerabilities in the open source components you ship, plus Coverity findings in your own code. Konvu imports those findings, checks whether each one can be exploited in your application, and returns a verdict with the evidence behind it. Verdicts go where your team works: fix pull requests in GitHub or GitLab, Slack, and ArmorCode if your Polaris findings flow through it.

    SCA findings from Black Duck at a software company with more than 100,000 employees. Figures as reported in the case study.

    96%

    of assessed findings were false positives, each with written reasoning

    4x

    faster remediation on the findings proved exploitable

    Read the Global enterprise software case study

    Black Duck findings Konvu analyzes

    SCA

    Black Duck SCA in Polaris

    Open source component vulnerabilities, assessed when Polaris records the repository and branch the finding came from.

    SAST

    Coverity in Polaris

    Static analysis findings in your own code. New findings are queued for investigation as soon as they are imported.

    Not imported today

    • Black Duck SCA deployments outside Polaris
    • Standalone Coverity Connect
    • DAST, container, and IaC findings

    Access and setup

    A read-only Polaris API token and your Polaris region. Findings reach Konvu through its on-prem broker. Self-hosted deployments can keep the token in the broker instead of in Konvu.

    To read findings

    • A read-only Polaris API token
    • Your Polaris region

    To write back

    No write access is needed.

    • Konvu reads your code through your GitHub or GitLab connection, not through Polaris.

    How Konvu investigates Black Duck findings

    What Konvu receives

    For SCA: the component, version, and vulnerability, plus the repository and branch Polaris scanned. For SAST: the Coverity issue and its location in your code.

    What Konvu checks

    • Whether the vulnerable component is loaded by the application, and whether the configuration it needs is present.
    • Whether the vulnerable code is reachable from your code, and whether input an attacker controls can get to it.
    • For Coverity findings, whether validation or framework behavior already neutralizes the flagged path.

    What decides the verdict

    Konvu returns exploitable, false positive, or inconclusive, with the reasoning behind it: the code it read, the conditions it tested, and what settled the call. When the answer depends on something only your team knows, Konvu asks a question instead of guessing.

    Illustrative example

    A jackson-databind finding from Polaris

    A made-up service, written to show how an investigation reads. Not a customer result.

    1. 1

      Scanner finding

      Polaris reports CVE-2020-36179 against jackson-databind 2.9.10.5 in a Java service. It belongs to a family of deserialization gadget issues fixed in 2.9.10.8.

    2. 2

      Application context

      Exploiting it needs two things: the application must turn on polymorphic default typing when it reads untrusted JSON, and the gadget class named in the advisory must be on the classpath.

    3. 3

      Investigation

      Konvu reads how the service configures its ObjectMapper instances. None calls enableDefaultTyping or activateDefaultTyping, and no field uses @JsonTypeInfo with class names taken from input. The library that provides the gadget class is not among the service's dependencies.

    4. 4

      Verdict

      False positive. Neither condition holds, so untrusted JSON cannot select the gadget class.

    5. 5

      Evidence

      The ObjectMapper configurations Konvu read, the typing settings it looked for, and the dependency list without the gadget library.

    6. 6

      Where it ends up

      The verdict and evidence stay on the finding in Konvu for the team to review. Konvu does not write to Polaris, so the team updates the Polaris issue there if they want the two to match.

    Writeback and controls

    Where results go

    • Exploitable dependency findings can become a fix pull request in GitHub or GitLab, opened automatically if you turn that on for the repository.
    • If your Polaris SCA findings also reach you through ArmorCode, Konvu can dismiss them there and add its assessment as a comment and tag.
    • Exploitable findings can be posted to Slack, so the team hears about them without opening Konvu.
    • Every verdict and its evidence can be pulled into your own tools through the Konvu API or CLI.

    Who triggers it

    Konvu imports findings on its daily schedule and queues new Coverity findings for investigation automatically. What to do with a verdict is up to your team.

    What stays with your team

    • Triage in Polaris, including closing findings Konvu assessed as false positives.

    Customer results with Black Duck

    Global enterprise software

    SCA findings from Black Duck at a software company with more than 100,000 employees. Figures as reported in the case study.

    96%
    of assessed findings were false positives, each with written reasoning
    4x
    faster remediation on the findings proved exploitable
    Read the case study

    Fortune 500 retail

    SCA findings from Black Duck Polaris at a Fortune 500 retailer. Figures as reported in the case study.

    93%
    smaller SCA triage queue, within weeks
    15+
    hours saved per week
    Read the case study

    Evaluation questions