AppSecNews
ASPM Commercial Established

Software Risk Manager

by Black Duck (originally Code Dx)

A correlation and triage platform, descended from Code Dx, that normalizes output from many analysis tools and merges overlapping findings into a single review queue.

Visit blackduck.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Software Risk Manager in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Current connector catalog and bundled scanning capability: verify against vendor documentation
  • SaaS availability alongside self-hosted deployment: confirm with vendor

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Software Risk Manager is the continuation of Code Dx, a product built to solve the correlation problem: you run several analysis tools, they overlap, they disagree, and they use different severity scales and weakness taxonomies. It ingests results from a long list of commercial and open source tools, normalizes findings to CWE, and merges detections of the same underlying weakness into one finding backed by evidence from each tool that reported it. Where two tools agree, that agreement is itself signal, and the platform surfaces it.

Beyond normalization it provides the triage machinery a review process needs: assignment, status, filters, saved views, comments, false positive and mitigation dispositions that persist across rescans so a decision made once does not have to be made again. It supports correlating static and dynamic results against the same application, and it produces compliance-oriented reporting mapped to frameworks and weakness taxonomies, which matters for teams with formal assurance obligations.

Where it fits

This is a security team platform that receives scan output from CI jobs and from manual runs, sitting after detection and before ticketing. It is commonly deployed self-hosted, which suits organizations that need findings data to stay inside their own boundary. The prerequisite is a real multi-tool estate: if you run one scanner, correlation has nothing to correlate, and its own dashboard will serve you better.

Strengths

  • Correlation across overlapping tools is the product's original purpose and it is handled with more care than in platforms where aggregation was bolted on later.
  • Triage dispositions persisting across scans is the single feature that makes repeated scanning survivable, and it works properly here.
  • Self-hosted deployment keeps vulnerability data in your environment, which is often a hard requirement in regulated sectors.
  • CWE-based normalization gives a consistent taxonomy for reporting regardless of which tools produced the findings.

Limitations

  • It is a consolidation layer, so it improves nothing about detection quality. Poor scanner configuration upstream produces a well-organized pile of noise.
  • Self-hosting means you own the deployment, upgrades and database growth, and the operational load is not trivial for a large finding volume.
  • It sits inside a larger vendor portfolio, and there is a natural pull toward that vendor's own analysis tools, so evaluate how well it treats competing scanners as first-class inputs.

Who it suits

Right for enterprises running a mixed portfolio of analysis tools, with a formal application security review process and a reason to keep findings data on their own infrastructure. It is a poor fit for small teams with a single scanner, and for organizations that want prioritization driven by runtime or reachability context, which is not where this product's strengths lie.

Used Software Risk Manager? Recommend it under your own name and title.

Recommend this tool