Black Duck Polaris integration
Get an exploitability verdict with evidence for Black Duck Polaris SCA findings and Coverity SAST findings.
Integration details
Primary category
Software Composition Analysis
Sync direction
Black Duck → Konvu
Konvu imports Polaris findings once a day through its on-prem broker with a read-only token. Verdicts go out as fix pull requests, Slack alerts, and through the Konvu API.
Status
Available
Which Polaris findings need a fix, and which can be closed?
Black Duck Polaris reports known vulnerabilities in the open source components you ship, plus Coverity findings in your own code. Konvu imports those findings, checks whether each one can be exploited in your application, and returns a verdict with the evidence behind it. Verdicts go where your team works: fix pull requests in GitHub or GitLab, Slack, and ArmorCode if your Polaris findings flow through it.
SCA findings from Black Duck at a software company with more than 100,000 employees. Figures as reported in the case study.
96%
of assessed findings were false positives, each with written reasoning
4x
faster remediation on the findings proved exploitable
Black Duck findings Konvu analyzes
SCA
Black Duck SCA in Polaris
Open source component vulnerabilities, assessed when Polaris records the repository and branch the finding came from.
SAST
Coverity in Polaris
Static analysis findings in your own code. New findings are queued for investigation as soon as they are imported.
Not imported today
- Black Duck SCA deployments outside Polaris
- Standalone Coverity Connect
- DAST, container, and IaC findings
Access and setup
A read-only Polaris API token and your Polaris region. Findings reach Konvu through its on-prem broker. Self-hosted deployments can keep the token in the broker instead of in Konvu.
To read findings
- A read-only Polaris API token
- Your Polaris region
To write back
No write access is needed.
- Konvu reads your code through your GitHub or GitLab connection, not through Polaris.
How Konvu investigates Black Duck findings
What Konvu receives
For SCA: the component, version, and vulnerability, plus the repository and branch Polaris scanned. For SAST: the Coverity issue and its location in your code.
What Konvu checks
- Whether the vulnerable component is loaded by the application, and whether the configuration it needs is present.
- Whether the vulnerable code is reachable from your code, and whether input an attacker controls can get to it.
- For Coverity findings, whether validation or framework behavior already neutralizes the flagged path.
What decides the verdict
Konvu returns exploitable, false positive, or inconclusive, with the reasoning behind it: the code it read, the conditions it tested, and what settled the call. When the answer depends on something only your team knows, Konvu asks a question instead of guessing.
Illustrative example
A jackson-databind finding from Polaris
A made-up service, written to show how an investigation reads. Not a customer result.
- 1
Scanner finding
Polaris reports CVE-2020-36179 against jackson-databind 2.9.10.5 in a Java service. It belongs to a family of deserialization gadget issues fixed in 2.9.10.8.
- 2
Application context
Exploiting it needs two things: the application must turn on polymorphic default typing when it reads untrusted JSON, and the gadget class named in the advisory must be on the classpath.
- 3
Investigation
Konvu reads how the service configures its ObjectMapper instances. None calls enableDefaultTyping or activateDefaultTyping, and no field uses @JsonTypeInfo with class names taken from input. The library that provides the gadget class is not among the service's dependencies.
- 4
Verdict
False positive. Neither condition holds, so untrusted JSON cannot select the gadget class.
- 5
Evidence
The ObjectMapper configurations Konvu read, the typing settings it looked for, and the dependency list without the gadget library.
- 6
Where it ends up
The verdict and evidence stay on the finding in Konvu for the team to review. Konvu does not write to Polaris, so the team updates the Polaris issue there if they want the two to match.
Writeback and controls
Where results go
- Exploitable dependency findings can become a fix pull request in GitHub or GitLab, opened automatically if you turn that on for the repository.
- If your Polaris SCA findings also reach you through ArmorCode, Konvu can dismiss them there and add its assessment as a comment and tag.
- Exploitable findings can be posted to Slack, so the team hears about them without opening Konvu.
- Every verdict and its evidence can be pulled into your own tools through the Konvu API or CLI.
Who triggers it
Konvu imports findings on its daily schedule and queues new Coverity findings for investigation automatically. What to do with a verdict is up to your team.
What stays with your team
- Triage in Polaris, including closing findings Konvu assessed as false positives.
Customer results with Black Duck
Global enterprise software
SCA findings from Black Duck at a software company with more than 100,000 employees. Figures as reported in the case study.
- 96%
- of assessed findings were false positives, each with written reasoning
- 4x
- faster remediation on the findings proved exploitable
Fortune 500 retail
SCA findings from Black Duck Polaris at a Fortune 500 retailer. Figures as reported in the case study.
- 93%
- smaller SCA triage queue, within weeks
- 15+
- hours saved per week
Evaluation questions
The technical detail
More integrations
View allArnica
Add exploitability verdicts with evidence to Arnica SCA and SAST findings, and send approved SCA dismissals back to Arnica.
- SCA
- SAST
- ASPM
Checkmarx
Send Checkmarx One SCA and SAST results to Konvu for an exploitability verdict with evidence, through the Konvu API or a report upload.
- SAST
- SCA
GitHub
Prioritize GitHub CodeQL and Dependabot alerts by adding exploit context to each finding.
- SAST
- SCA
- Ticketing & Messaging
GitLab
Add exploitability analysis to GitLab's built-in SAST and SCA pipeline findings.
- SCA
- SAST
- Ticketing & Messaging
Semgrep
Find out which Semgrep Supply Chain and Semgrep Code findings are exploitable, with the evidence behind each verdict.
- SAST
- SCA
Snyk
Find out which Snyk Open Source and Snyk Code findings are exploitable in your code, with the evidence behind each verdict.
- SCA
- SAST
- Container Security