Reviews from AWS Marketplace
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
Keep your dependency up to date
What do you like best about the product?
A unique feature that was offered by Mend Renovate for Github is the support for the Gradle version catalog. This is a very useful feature for big mono repo, to keep your java dependencies managed by gradle up-to-date and vulnerability free.
In the middle of 2022(when our organization was moved to Github), gradle version catalog was not supported by Github Dependabot, so natural Mend Renovate was a natural choice for us.
In the middle of 2022(when our organization was moved to Github), gradle version catalog was not supported by Github Dependabot, so natural Mend Renovate was a natural choice for us.
What do you dislike about the product?
As Mend Renovate for Github is a free tool, offered functionality is more than enough. A nice add-on would be integration with JIRA that allows tracking vulnerabilities with synchronization on the both side.
What problems is the product solving and how is that benefiting you?
Mend Renovate for GitHub help us keep our dependencies up to date, which causes fewer vulnerabilities in the final Product. The time required to update dependency was significantly decreased.
- Leave a Comment |
- Mark review as helpful
Mend makes security issue fixing and reporting really simple.
What do you like best about the product?
Mend's integration with source control systems and IDEs is simply outstanding.
What do you dislike about the product?
Nothing I dislike as of now. But I wish mend had a chat feature or something for quick resolution of small issues without needing to open support cases.
What problems is the product solving and how is that benefiting you?
Mend is simplifying the whole process of addressing security issues and helps us generate reports to present to our customers on how secure our applications are.
Fast and Reliable
What do you like best about the product?
IntelliJ Plugin - The analysis is really quick
What do you dislike about the product?
Viewing the report. I feel overwhelmed when I log in to Mend. The landing page should just contain the project I'm interested in and the related reports. Similar to tools like Fortify and Sonar.
What problems is the product solving and how is that benefiting you?
Helping our product to stay compliant by analyzing and reporting the security vulnerabilities in time.
Good
What do you like best about the product?
For Commerical Use Helpful this is the Best But Some Slow Conditions is that
What do you dislike about the product?
nothingthis is the Best But Some Slow Conditions is that
What problems is the product solving and how is that benefiting you?
Slow
Easy integration with CI/CD and powerful shift-left approach
What do you like best about the product?
It makes it very easy to break down and analyze all the open source packages that are in client's code with reports and dashboards to easily identify Critical, Highs, Med and Low risks. I also like that it easily integrates with Github and Azure DevOps to the point that I don't have to login to another site or console and I can see issues right on my platform for tracking and remediation
What do you dislike about the product?
The commonality with a lot of SAST tools is the amount of false positives.
What problems is the product solving and how is that benefiting you?
Client developers need data to patch the applications right from the start and with Mend we can do pre-commit and PR triggers that fix before we are shipping to production for better security.
Good tool but UI is clunky
What do you like best about the product?
The information about vulnerabilities is generally up to date.
What do you dislike about the product?
The UI is very clunky. Doesn't integrate well into development workflow. as we need to come to this tool to audit the findings. Would be nice to have it as a github plugin from where we can directly audit the findings.
What problems is the product solving and how is that benefiting you?
The main challenge it solves is that it scans our dependencies for vulnerabilities.
Being integrated in our corporate toolchain means, that we don't have to justify the value multiple times to stakeholders.
Being integrated in our corporate toolchain means, that we don't have to justify the value multiple times to stakeholders.
Make it easy for your development team to address open source risk
What do you like best about the product?
Mend is a very intuitive tool that has integrations with many typical pipelines and repos. We have found it to be very good at identifying vulnerable components with a low false positive rate. It provides good recommendations for the best fix version of a library.
What do you dislike about the product?
Mend is starting to build out full support for exporting results in standard SBOM formats, but generating these outputs currently requires running separate Python scripts.
What problems is the product solving and how is that benefiting you?
Mend is used to address open source risk by evaluating for vulnerabilities, license risk, and code quality. It supports the enforcement of policies.
Good tool for SCA
What do you like best about the product?
1. Seemless integration with SCM.
2. License management for open source repositories.
2. License management for open source repositories.
What do you dislike about the product?
It would be great if an auto dependency resolution/management is provided for any finding.
What problems is the product solving and how is that benefiting you?
Implementing shift left strategy
Better code.
What do you like best about the product?
Scanning for the vulnerabilities is always updated and the research team is doing an amazing job keeping everything up-to-date and not missing any vulnerability.
What do you dislike about the product?
I feel that the dashboard's UI can look nicer and more readable. eg better views, more modern design, easier access to products and related projects with a tree view.
What problems is the product solving and how is that benefiting you?
Security vulnerabilities, avoiding/fixing them to get a more secure product that satisfies the higher-ups and the clients together which increased the business performance
Effective and easy to use OSS scanning
What do you like best about the product?
Scanning is simple with an easy-to-use agent.
Reports are easy to read providing useful insight.
Reports are easy to read providing useful insight.
What do you dislike about the product?
The Mend Portal can be slow on occassion.
Some parts of the interface are not as intuitive as they could be.
Some parts of the interface are not as intuitive as they could be.
What problems is the product solving and how is that benefiting you?
I have some maven based build issues. Mend Support is providing effective and swift guidance on how to solve these issues.
showing 21 - 30