Secure and Manage Open Source Software Black Duck helps organizations identify and mitigate open source security, license compliance and code- quality risks across application and container portfolios. Black Duck Hub and its plugin for Team Foundation Server (TFS) allows you toautomatically find and fix open source security vulnerabilities during the build process, so you can proactively manage risk. The integration allows you to receive alerts and fail builds when any Black Duck Hub policy violations are met. Note: WhiteSourcewould also be a good answer, but it is not an option here. Reference: https://marketplace.visualstudio.com/items?itemName=black-duck-software.hub-tfs