The integration with Azure DevOps was good.
The results and the dashboard they provide are good.
It was pretty straightforward for me.
The integration with Azure DevOps was good.
The results and the dashboard they provide are good.
It was pretty straightforward for me.
I would like to see the static analysis included with the open-source version. That would be good.
I used the trial version of WhiteSource for a month. We chose to work with Veracode instead.
It's was pretty stable. I don't have any complaints about the stability of WhiteSource.
I did not have any contact with the technical support. I did not have any issues in the time that I used this solution.
It was approximately $2,000 per year or per month, I don't recall exactly.
When compared with Veracode, Veracode was very very expensive. It was approximately $200,000.00 per year for the whole Suite.
WhiteSource is much more affordable than Veracode.
We are evaluating Veracode.
It was pretty good. I would rate WhiteSource an eight out of ten.
The inventory management as well as the ability to identify security vulnerabilities has been the most valuable for our business.
The turnaround time for upgrading databases for this tool as well as the accuracy could be improved.
It would be good if containerization could be included under the current licensing but this is not something I have looked into.
I have been using this solution for four years.
This is a stable solution.
This is a scalable solution.
This solution offers good support which we have used multiple times.
Positive
The initial setup of this solution was straightforward and easy.
This is an expensive solution.
When setting up this solution, it is important to have clear cut planning and to define the automation rules.
I would recommend using WhiteSource. It has an edge over other tools in the market and is a faster solution.
WhiteSource is easy to integrate with the CICD pipeline and runs standalone scans as it is a SaaS deployment. Integration of this solution does not require much time or knowledge.
I would rate this solution a nine out of ten.
To my knowledge, we are using the latest, SaaS, version.
The solution boasts a broad range of features and covers much of what an ideal SCA tool should. It covers the containers. One can create his teams and, should he encounter an issue, send an alert to the team's DL.
I am quite happy with WhiteSource. It is very good and provides many things, including extensive reports involving vulnerabilities.
I am not clear if WhiteSource provides on-premises service. I know that its competitors provide on-premises and SaaS-based services for the same licensing fee and model, but I am not sure if this applies to WhiteSource, as well. I believe it does not.
It is preferable to use on-cloud services, although on-premises one should equally be an option, if I would prefer to not go for SaaS-based hosting. The licensing model should be the same for the different options.
The initial setup could be simplified.
I have been using WhiteSource for more than a year.
The solution is very stable.
It is a preferequisite that the solution is scalable, as it is SaaS-based.
I have not had experience with customer support.
The initial setup was of an intermediate complexity. It was neither complex, nor straightforward. It could have been easier. Understandably, it involved a certain amount of configuration.
I cannot comment on billing, as this was handled by other departments in my previous organization.
As we were using an SaaS-based service, the solution must be scalable, although my understanding is that this is based on the licensing model one is using.
The reason I logged into the IT Central Station web site is because I was looking for crisp documentation so that I may compare WhiteSource with Black Duck. I did not find what I was looking for. All I found was a conglomerate of user experiences, not the research reports I was searching for.
I am currently using both of these products.
I rate Whitesource as an eight out of ten.
I use the solution for free and open source scanning.
The solution lacks the code snippet part. I plan to raise this issue with those at WhiteSource.
I have been using WhiteSource for more than a year.
The solution is scalable.
The solution is stable.
The technical support is good, although not the best. It could be more customer friendly.
The initial setup was straightforward.
Installation took no more than five minutes.
CI/CD integration required the use of a consultant.
We did not require much technical team for this. The team consists of four people.
The solution involves a yearly licensing fee.
There were only two products at this point in time which we evaluated, the solution being one of these. We plan to reevaluate its use.
The solution is only cloud-based, not on-premises.
It is user-friendly.
There are around 50 people currently using it in our organization.
I rate WhiteSource as an eight out of ten.
The license management of WhiteSource was at a good level. As compared to other tools that I have used, its functionality for the licenses for the code libraries was quite good. Its UI was also fine.
We have ended our relationship with WhiteSource. We were using an agent that we built in the pipeline so that you can scan the projects during build time. But unfortunately, that agent didn't work at all. We have more than 500 projects, and it doubled or tripled the build time. For other projects, we had the failure of the builds without any known reason. It was not usable at all. We spent maybe one year working on the issues to try to make it work, but it didn't in the end.
We should be able to integrate it with ID and Shift Left so that the developers are able to see the scan results without waiting for the build to fail.
I have used this solution for one year.
I wouldn't call it stable because we could not build it into the pipeline, and it caused failures.
They were quite responsive, but in the end, they couldn't help with anything to make it work. For any feature requests that we had on our side, they always claimed that they were part of the roadmap, but after that, nothing happened.
It was quite straightforward. It was intended to be done on the DevOps side. It was nothing special. It didn't work after the setup. It caused build failures.
I would rate WhiteSource a three out of ten considering the fact that we couldn't use it while we were paying for it. It had good features, but we couldn't use it.
Its ease of use and good results are the most valuable.
It would be good if it can do dynamic code analysis. It is not necessarily in that space, but it can do more because we have too many tools.
Their partner relationship support is a little bit confusing. They haven't really streamlined the support process when we buy through a reseller. They should improve their process.
I have been using this solution for one month. I am using its latest version.
We are still implementing it. We haven't gone through scalability, but we don't expect any problem.
Their support is average. Their partner relationship support is a little bit confusing. They haven't really streamlined the support process when we buy through a reseller.
The initial setup was pretty straightforward. The deployment took about three weeks.
We did it ourselves.
I would rate WhiteSource a nine out of ten. It is a good product.
We use this solution for scanning NodeJS and Maven projects during the CI/CD processes. We have hundreds of scans per day for any project that runs on our CI and passes the release build.
This means that any release build runs the WhiteSource scan before deployment to production clusters, which ensures that we are pretty covered in terms of licenses for open source dependencies.
We are running on top of hundreds of microservices and thousands of daily builds, of which part of them are moving to production deployment eventually.
In general, we are covered for open source licensing issues and CVE errors on particular versions for open source dependencies. Moreover, we have covered ourselves for security auditing by stating that we are users of WhiteSource.
The most valuable feature is the unified JAR to scan for all langs (wss-scanner jar). It helps us to scan easily and is agnostic to the technology.
The dashboard UI and UX are problematic. This solution looks like a 1995 web site and it's very hard to understand what the issue is and why it failed.
I have been using WhiteSource for almost five years.
The stability is great.
Our account manager is the best!
This is my first open-source scanning solution.
The setup was performed independently.
I didn't choose it but I saw a demo of Synk.
Improve the UI please... developers cannot find themselves in this dashboard.
We use WhiteSource mainly to:
WhiteSource is very easy to run and use. It reduced significantly the time our developers used to spend on issues in open-source libraries. We used a free tool before and the number of alerts was too high to handle.
We recently implemented WhiteSource on our Github account.
It provides our developers with better visibility into open source libraries within their code environment, which helps the company in ensuring dev adoption.
When it comes to open-source licenses, it really simplified reporting as it provides an inventory list in a simple report. Before WhiteSource it was almost impossible, mostly due to transitive dependencies.
The most valuable features for us are:
The changes that we would like to see are mostly usability issues.
The UI can be slow once in a while, and we're not sure if it's because of the amount of data we have, or it is just a slow product, but it would be nice if it could be improved.
The UI is also too crowded. I believe that less information, or a different data summary, can be more readable. I know this is something they’re currently working on, but not sure where it stands.
Reporting could be easier, as it does not export filtered-down lists. It would be really valuable to add the ability to customize options in the reports.
We have been using WhiteSource for one and a half years.
Stable.
Didn't have any problems related to scale so far.
No
I can easily generate reports and get a quick overview of my status.
Yes, Snyk
