{"slug":"black-duck","name":"Black Duck","domain":"blackduck.com","verdict":"As of 2026-07-14, ChatGPT, Claude, Gemini, Grok collectively rank Black Duck #5 of 9 for dependency sca scanner for open-source risk. Source: https://modelsagree.com/product/black-duck (modelsagree.com, CC BY 4.0).","best_rank":5,"categories":1,"brief":{"category":"best-dependency-sca-scanner-for-open-source-risk","title":"Best dependency SCA scanner for open-source risk","rank":5,"of":9,"top":"Snyk","day":"2026-07-19","why":[{"t":"license governance and compliance audits","m":["ChatGPT","Gemini"],"q":"Unmatched depth in license compliance audits"},{"t":"deep binary analysis","m":["ChatGPT","Gemini"],"q":"deep binary signature analysis"},{"t":"audit-ready enterprise risk reporting","m":["ChatGPT","Gemini"],"q":"audit-ready reporting for large regulated enterprises"}],"gap":[{"t":"developer experience and deep workflow integration","m":["ChatGPT","Claude","Gemini","Grok"],"q":"Best overall developer experience"},{"t":"proprietary vulnerability intelligence","m":["ChatGPT","Claude","Gemini"],"q":"strong proprietary vulnerability intelligence"},{"t":"automated fix PRs with reachability analysis","m":["ChatGPT","Claude","Gemini","Grok"],"q":"automated fix PRs"}],"fix":[{"t":"speed up scanning times","m":["ChatGPT","Gemini"],"q":"Drastically speed up scanning times"},{"t":"streamline CI/CD integration complexity","m":["ChatGPT","Gemini"],"q":"streamline the CI/CD integration complexity"},{"t":"modernize remediation and developer workflows","m":["ChatGPT"],"q":"Modernize and streamline scanning, remediation, and developer workflows"}]},"entries":[{"slug":"best-dependency-sca-scanner-for-open-source-risk","title":"Best dependency SCA scanner for open-source risk","rank":5,"of":9,"score":3,"appearances":2,"modelRanks":{"ChatGPT":4,"Gemini":5},"reason":"Best-in-class software inventory and license governance, strong binary and snippet analysis, broad component identification, mature policy controls, and audit-ready reporting for large regulated enterprises","reasons":[{"model":"ChatGPT","reason":"Best-in-class software inventory and license governance, strong binary and snippet analysis, broad component identification, mature policy controls, and audit-ready reporting for large regulated enterprises"},{"model":"Gemini","reason":"Unmatched depth in license compliance audits, deep binary signature analysis, and comprehensive M&A security risk reporting."}],"fixes":[{"model":"ChatGPT","fix":"Modernize and streamline scanning, remediation, and developer workflows to reduce complexity and feedback time"},{"model":"Gemini","fix":"Drastically speed up scanning times and streamline the CI/CD integration complexity."}],"updated":"2026-07-14","rank_history":{"days":["2026-06-29","2026-06-30","2026-07-08","2026-07-09","2026-07-10","2026-07-14"],"ranks":[4,4,4,5,4,null]},"reasoning_shift":[{"model":"Gemini","from":"2026-06-30","to":"2026-07-08","added":[{"t":"deep binary signature analysis","q":"deep binary signature analysis"},{"t":"faster scanning times","q":"Drastically speed up scanning times"},{"t":"streamline CI/CD integration complexity","q":"streamline the CI/CD integration complexity"}],"dropped":[{"t":"enterprise policy governance","q":"enterprise policy governance"},{"t":"partial snippet detection","q":"partial snippet detection"},{"t":"developer-centric user experience","q":"Redesign the user experience to be faster and developer-centric rather than a slow, security-gatekeeper tool"}]}],"api":"https://modelsagree.com/api/v1/best/best-dependency-sca-scanner-for-open-source-risk.json"}],"page":"https://modelsagree.com/product/black-duck","check":"https://modelsagree.com/check?q=Black%20Duck","updated":"2026-08-10T18:18:45.051Z","attribution":"modelsagree.com, CC BY 4.0"}