Black Duck analyzes open source code for compliance, validation

Opinion
Mar 28, 20052 mins

* Black Duck ProtexIP/OnDemand

Black Duck software this week will launch a service aimed at software developers and programmers who employ large chunks of open source code in their work. The aim is to give coders a snapshot of how their code complies with the various licenses that control the re-use and distribution of open source code.

The ProtexIP/OnDemand open source software compliance and validation service can give programmers a tool for checking their code against more than 450 open source licenses. The goal of the service is to protect programmers who may be integrating open source code governed by one license with either proprietary code, or code governed by another, exclusive open source license. Checking for this kind of compliance can be a chore for integrators, small application vendors and other firms that tie together existing open source applications when building systems for resale, Black Duck says.

The ProtexIP/OnDemand service works by allowing Black Duck a secure tunnel into a corporate database of source code. The Black Duck service scans the code and matches it to “code prints” – like fingerprints – from thousands of open source projects that Black Duck tracks in its base. After the scanning, reports are compiled and delivered to programmers.

Previously, the Waltham, Mass., Black Duck sold its code print database and analysis application as a hardware/software product, running on a server. The new service-based model should be more attractive to users interested in a one-time compliance check, the vendor says. 

Pricing for this service is basedon how much code is analyzed, on a per-megabyte basis. Up to 10M bytes of code can be scanned for $3,000, up to 100M bytes of code for $25,000. The service is available now.