APIs for Black Duck products

Integrations finder

Version
latest

This table summarizes API reference documentation for Black Duck products, including locations and key capabilities.

Product Location of API reference documentation Capabilities
Black Duck Binary Analysis

API reference documentation is available only in the application.

From any page, click the Help button (“?”) and choose API documentation.

Capabilities include:

  • Automate nightly uploads and scans.

  • Perform Business Logic Assessment.

  • Manage the Continuous Dynamic appliance.

Black Duck SCA

API reference documentation is available only in the application.

To view the documentation, do one of the following:

  • From the Help menu (“?”) located on the top navigation bar in the Black Duck UI, select REST API Developers Guide.

  • Go to https://<Black Duck Server URL>/api-doc/public.html.

Capabilities include:

  • Generate and download a notices file or SBOM.

  • Collate component copyright information.

  • Automatically assign issues to developers.

  • Add comments to Pull requests with Black Duck data.

There are two ways to explore Black Duck SCA APIs:

  • Access the REST API documentation found in Black Duck SCA by opening the Help menu from the top navigation bar and selecting REST API Developers Guide.

  • Visit the REST API documentation directly at https://<Black Duck Server URL>/api-doc/public.html.

(See Black Duck SCA Integrations and APIs)

Continuous Dynamic Use the Continuous Dynamic Developer Portal.

  • Add and manage assets.

  • Schedule scans.

  • Access vulnerability reports programmatically.

  • Manage users and groups.

See detailed information about the available APIs here.

Coverity on Polaris

API reference documentation is available only in the application.

To open the reference documentation from any page in the application, choose API Reference from the left-hand navigation menu.

All the functionality of the Coverity on Polaris application is available through APIs, however the recommended usages are these:

  • Retrieve information about issues.

  • Retrieve triage status.

For a detailed listing, see Coverity on Polaris API services.

Coverity on Polaris Reporting Platform

API reference documentation is available only in the application.

To open the reference documentation from any page in the application, choose API Reference from the left-hand navigation menu.

Coverity on Polaris Reporting Platform provides a set of REST APIs that you can use to automate certain administration tasks.

For detailed information see Coverity on Polaris Reporting Platform APIs.

Coverity

Capabilities include:

  • Configure Coverity Connect.

  • Retrieve issues from the Coverity Connect database.

  • Retrieve and manage existing Coverity Connect views.

Defensics

Available in the application directory, when Defensics is running in server mode.

For details about accessing the documentation, see HTTP API V2 Integration.

The API can be used to run defensics headlessly, using a secure HTTPS connection.

Capabilities include:

  • Configure the fuzzer.

  • Run the fuzzer.

  • Track test progress.

  • Export test reports.

Polaris Polaris Developer Portal

Capabilities include:

  • Retrieve the latest issue data by specifying a test, a project, or an application.

  • Filter for relevant results. For example, high severity or OWASP Top 10 issues.

  • Retrieve a complete list of issues, a count of issues, or a count of certain kinds of issues.

  • Triage issues or assign them to developers.

  • Create an Azure DevOps or Jira ticket for a Polaris issue.

Seeker

Available in the Seeker application or on the documentation portal.

In the documentation, see Seeker API reference.

You can also directly access the Seeker API specification file through the web application, by navigating to {SEEKER_SERVER_URL}/rest/swagger.json.

Capabilities include:

  • Manage projects.

  • Export vulnerabilities.

  • Create a diagnostic dump.

Software Risk Manager Software Risk Manager API Guide

Capabilities include:

  • Start an analysis.

  • Configure SRM.

  • Manage issues.

  • Perform triage.

  • Generate reports.

  • Manage users and groups.

  • Manage webhooks.