En savoir plus sur WhiteSource

WhiteSource is the leading solution for agile open source security and license compliance management. It integrates with your development environments and DevOps pipeline to detect open source libraries with security or compliance issues in real-time. WhiteSource doesn’t only alert on issues, it also provides actionable, validated remediation paths to enable quick resolution and automated policy enforcement to speed up time-to-fix. It also helps you focus on what matters by prioritizing remediation based on whether your code is actually using a vulnerable method or not, and guaranteeing zero false positives. WhiteSource offers support for over 200 programming languages, and continuous tracking of multiple open source vulnerabilities databases including the NVD, security advisories, peer-reviewed vulnerability knowledge bases and open source projects issue trackers.
WhiteSource Logiciel - 1
WhiteSource Logiciel - 2
WhiteSource Logiciel - 3
WhiteSource Logiciel - 4
WhiteSource Logiciel - 1 - aperçu
WhiteSource Logiciel - 2 - aperçu
WhiteSource Logiciel - 3 - aperçu
WhiteSource Logiciel - 4 - aperçu

WhiteSource - Prix

WhiteSource n'est pas disponible en version gratuite mais propose un essai gratuit. La version payante de WhiteSource est disponible à partir de 4 000,00 $US.

À partir de :
4 000,00 $US
Prix :
Starting at $4,000 a year, based on contributing developers, get our pricing here: https://whitesourcesoftware.com/pricing
Version gratuite :
Non
Version d'essai gratuite :
Oui

Produits similaires à WhiteSource

Trend Micro Cloud One

0
Trend Micro Cloud One is a compliance and computer security solution that helps businesses streamline processes related...

Alloy Navigator

Alloy Navigator is an IT service and asset management solution that enables organizations of all sizes to manage their...
Jira Software est un outil de développement logiciel utilisé par les équipes Agile en vue de planifier, de suivre et de...

Caspio

Caspio is a cloud-based, no-code, application development solution for organizations of all sizes. The platform is...

Syxsense

Syxsense Manage is a cloud-based IT management and MSP software that allows administrators to configure and access...

TOPIA

TOPIA est un logiciel de gestion des vulnérabilités qui aide les entreprises à analyser, détecter et corriger les...

WhiteSource - Avis

Évaluation des fonctionnalités

Rapport qualité-prix
3
Fonctionnalités
3,5
Simplicité
4
Support client
4,5
5 avis sur 6 Afficher tous les avis
Elyes C.
  • Secteur d'activité : Services et technologies de l'information
  • Taille de l'entreprise : 1 001-5 000 employés
  • Logiciel utilisé tous les mois pendant 6 à 12 mois
  • Provenance de l'avis
Rapport qualité-prix
5
Fonctionnalités
4
Simplicité
5
Support client
4

5
Publié le 07/12/2021

WhiteSource Review

Avantages

WhiteSource give you the ability to scan open source packages within your source code.
The ability to integrate it with Azure pipelines is a huge plus

Inconvénients

Duplicated result for same packages and within the same project

Udi M.
  • Provenance de l'avis
Rapport qualité-prix
0
Fonctionnalités
0
Simplicité
4
Support client
5

5
Publié le 10/11/2015

FOSS lifecycle management with Whitesource

Using Whitesource to manage the process of analysing FOSS for a large product with hundreds of opensource dependencies.
Makes life much easier and helps you cover all dependencies much more accurately.

Some processes are still a bit course (though improved dramatically over the past 18 months)
Refresh performance might be a bit slow when there are very large dependency lists.

Best product out there for FOSS lifecycle management

Don T.
  • Logiciel utilisé Autre pendant 1 à 5 mois
  • Provenance de l'avis
Rapport qualité-prix
1
Fonctionnalités
3
Simplicité
3
Support client
4

2
Publié le 07/06/2018

Tons of false positives, prepare to spend hours fixing it manually

After much manual configuration, a nicely formatted output that looks reputable. I could have just made my own in excel a lot faster.

Avantages

Fast, quick reviews of your code. They do a good job of putting all the relevant reports and dashboards in front of you quickly. Once you manually fix everything, it can look really good.

Inconvénients

The false positives are awful. I had to spend hours and hours manually fixing everything it mis-identified - dozens of libraries and thousands of source files. If you use a library not in its database... too bad. You can make a support request and wait for them to enter it for you, whenever they get around to it.
The search is pretty awful. There is some kind of syntax to using it but when I asked our account rep, she couldn't give me any documentation on it. You will frequently see results like "openssl-v0_9_8" in your search, but if you type "openssl" it will vanish and not come up. Don't ever both trying to search for a version, it doesn't work. This results in a lot of time scrolling through very large lists. Naming schemes are random and follow no established pattern.
For a good half of all libraries, they have not assigned a license. Guess who gets to go google search them all? You, the user! Isn't the point of this tool to help me identify the licensing?
UI navigation is challenging. Back button will take you to a different place than you were almost every time. You'll love the dashboard... because you have to go back to it roughly every 5 minutes and start over.
No great system for notes/todos/reminders. When you have to fix 60 libraries, it's hard to remember what you want to do with each one.

Shaul S.
  • Provenance de l'avis
Rapport qualité-prix
0
Fonctionnalités
0
Simplicité
4
Support client
5

4
Publié le 10/11/2015

work with it for a long time still place to improve.

It aggregates my licenses in one centralized place. The software helps me to generate the reports for many requests that I have inside my organization. It also helps me to identify the changes between versions and compare them.

John mcintire
  • Provenance de l'avis
Rapport qualité-prix
0
Fonctionnalités
0
Simplicité
0
Support client
0

5
Publié le 28/05/2013

Easy to use. Saves tons of time.

We used to document it all manually. Now its done easily and effectively. Not to mention that we missed many things, so with this we were able to fix some small issues before they become big issues....

Avantages

easy
inexpensive
very comprehensive
no more hassle

Catégories connexes