$npx skillfedfor your agent

blackduck

Package for using the Synopsys Black Duck Hub REST API.

With conditionsPyPI Quality AssuranceReleased Apr 2024518.4K downloads / moApachePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — blackduck-1.1.3-py3-none-any.whl
v1.1.3 · released 2024-04-19 · Python >=3.6.0 · 2 runtime deps: requests, python-dateutil

Yes, if you need to integrate Black Duck Hub into Python automation or tooling. The package is actively maintained, has low install friction, and the Client class provides modern session and paging support required for Black Duck v2022.2 and later. Avoid if you are still on older Black Duck versions and cannot migrate code to the Client interface, as the deprecated HubInstance will not work with current server releases.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires a Black Duck Hub instance with a valid API token; base URL and authentication credentials must be provided at initialization.
  • Low friction install with only two runtime dependencies (requests and python-dateutil).
  • Actively maintained with repository last commit on 2026-05-29 and 100 stars.

License · maintenance · safety

Apache (permissive) — Licensed under Apache (permissive), allowing commercial and private use with minimal restrictions. Suitable for integration into proprietary or open-source projects.

last release 2024-04-19 (847 days) · last repo commit 2026-05-29 · 100 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 518,366 downloads/mo, #6,223 on PyPI

Verify before relying

pip3 install blackduck

from blackduck import Client
import os

bd = Client(
    token=os.environ.get('blackduck_token'),
    base_url="https://your.blackduck.url"
)

for project in bd.get_resource(name='projects'):
    print(project.get('name'))
  • Whether the deprecated HubInstance interface remains functional in current Black Duck server versions despite the v2022.2 paging changes.
  • Current test coverage and whether pytest suite passes against modern Black Duck releases.
  • Whether automatic bearer token renewal works reliably across long-running sessions.
  • Compatibility with Black Duck versions prior to v2022.2 and migration path complexity.
Same gist for agents: .md · .json

What it is and what it does

blackduck is a Python client library for querying and managing Black Duck Hub, Synopsys's software composition analysis platform. It wraps the Hub REST API with a modern Client class that handles session persistence, automatic pagination, and token lifecycle management—features essential for working with Black Duck v2022.2 and later, which enforce maximum page sizes on API responses.

The package is built on requests and python-dateutil and targets Python 3.6 and later. It provides a generator-based interface for traversing paginated resources, making it practical for scanning large component inventories or project lists. The older HubInstance interface remains available for backward compatibility but does not support the new paging model and is no longer maintained; the documentation explicitly recommends migrating to the Client class.

Use it for

  • Automate security scans and retrieve vulnerability data for software components across multiple projects in Black Duck.
  • Build CI/CD pipeline integrations to fetch component analysis results and fail builds based on policy violations.
  • Export Black Duck project and component inventories to external systems or reporting tools via the REST API.
  • Monitor license compliance by querying component license data and generating compliance reports programmatically.
  • Manage Black Duck users, roles, and project assignments through API-driven administration workflows.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need to integrate Black Duck Hub into Python automation or tooling.

The package is actively maintained, has low install friction, and the Client class provides modern session and paging support required for Black Duck v2022.2 and later. Avoid if you are still on older Black Duck versions and cannot migrate code to the Client interface, as the deprecated HubInstance will not work with current server releases.

Install

blackduck on PyPI

Before you install

Low friction install with only two runtime dependencies (requests and python-dateutil). Actively maintained with repository last commit on 2026-05-29 and 100 stars.

Requires a Black Duck Hub instance with a valid API token; base URL and authentication credentials must be provided at initialization.

License in practice

Licensed under Apache (permissive), allowing commercial and private use with minimal restrictions. Suitable for integration into proprietary or open-source projects.

Quickstart

pip3 install blackduck

from blackduck import Client
import os

bd = Client(
    token=os.environ.get('blackduck_token'),
    base_url="https://your.blackduck.url"
)

for project in bd.get_resource(name='projects'):
    print(project.get('name'))

Verify before relying

  • Whether the deprecated HubInstance interface remains functional in current Black Duck server versions despite the v2022.2 paging changes.
  • Current test coverage and whether pytest suite passes against modern Black Duck releases.
  • Whether automatic bearer token renewal works reliably across long-running sessions.
  • Compatibility with Black Duck versions prior to v2022.2 and migration path complexity.

Package facts

LicenseApache permissive
Python supportSupports the current Python release >=3.6.0
Install frictionLow. Pure-Python wheel
Runtime dependencies
2 packages
requestspython-dateutil
MaintenanceActively maintained 847 days since the last release
Last repo commit
First released
Downloads518,366 / month, #6,223 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: Apache Software LicenseProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.6Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPy

Evidence: blackduck-1.1.3-py3-none-any.whl

Tags

Capabilities
black duck api pythonsynopsys hub rest api clientsoftware composition analysis apicomponent vulnerability scanningrest api python bindingsblack duck integrationhub rest api wrapper
Topics
security-scanningapi-clientsca
PyPI keywords
api

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “black duck api python”

  • blackduckPython bindings for the Synopsys Black Duck Hub REST API, providing a…
  • typishTypish provides runtime type checking and introspection functions for…
  • mdformat-blackA plugin for mdformat that automatically formats Python code blocks…

Give your agent the search over MCP, or paste the wish link into any chat.

More Quality Assurance packages

coverage Worth it
PyPI · Testing · released Aug 2026

Coverage.py measures which lines of Python code are executed during test runs, reporting coverage percentages and identifying untested code paths.

Install it if you want to measure test completeness or enforce coverage thresholds in your project.

permissive licensepure Python · 3.10+
335.8Mdownloads / mo
ruff Worth it
PyPI · Python Modules · released Aug 2026

Ruff is a Python linter and code formatter written in Rust that combines linting, formatting, and code fixing into a single tool, replacing Flake8, Black, isort, and related utilities.

MITcompiled wheel · 3.7+
316.1Mdownloads / mo
pexpect With conditions
PyPI · Software Development · released Nov 2023

Pexpect spawns and controls interactive console applications by sending input and matching output patterns, automating tasks that would otherwise require manual interaction.

ISCpure Pythonaging
200.8Mdownloads / mo
black Worth it
PyPI · Python Modules · released May 2026

Black reformats Python source code to a consistent style by parsing entire files and rewriting them according to an opinionated, deterministic set of rules, eliminating manual formatting decisions.

MITpure Python · 3.10+
179.9Mdownloads / mo
pytest-xdist Worth it
PyPI · Utilities · released Jul 2025

pytest-xdist distributes pytest tests across multiple CPU cores or machines to speed up test execution, with the simplest usage being `pytest -n auto` to spawn workers equal to available CPUs.

Install it if your test suite takes long enough that parallelization would save meaningful time.

MITpure Python · 3.9+
177.1Mdownloads / mo
cfn-lint Worth it
PyPI · Quality Assurance · released Aug 2026

Validates AWS CloudFormation templates in YAML or JSON format against resource provider schemas and best practices, checking property values and configuration correctness.

Install it if you work with CloudFormation templates.

MIT-0pure Python
114.9Mdownloads / mo

See also kiteconnect · prompthub-py · jellyfin-apiclient-python · sambanova · azure-iot-hub · ibm-cloud-sdk-core · PyFunceble-dev · httpdbg · pip-system-certs · pyprusalink