sca-blackduck
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: Downloads and executes the Synopsys Detect setup script directly from the official vendor domain (
detect.synopsys.com). This is the standard, documented method for running the tool provided by the vendor. - [COMMAND_EXECUTION]: Executes shell commands and utilizes standard tools such as
curl,bash,docker, andgitto perform software dependency analysis and generate security reports. - [CREDENTIALS_UNSAFE]: Correctness of secret management is maintained through the use of environment variables and platform-integrated secret stores (e.g., GitHub Secrets, GitLab CI/CD Variables) rather than hardcoding credentials.
- [EXTERNAL_DOWNLOADS]: Fetches configuration and scanning logic from well-known infrastructure and references established security databases and guidelines from NIST, CISA, and OWASP.
Audit Metadata