Reviews from AWS Marketplace
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews

External reviews are not included in the AWS star rating for the product.
Industry-leading SCA, work in progress
What do you like best about the product?
Quick and accurate scanning, multiple plug-ins for various different build and ci/cd platforms. Prioritize, Whitesource for developers
What do you dislike about the product?
hard to get some features working like
eua, and integration this Jira was challenging
eua, and integration this Jira was challenging
What problems is the product solving and how is that benefiting you?
Quick and accurate scanning, multiple plug-ins for various different build and ci/cd platforms. Prioritize, Whitesource for developers
- Leave a Comment |
- Mark review as helpful
Makes easy to manage your 3rd party libraries
What do you like best about the product?
The scans are quick, and a detailed report is provided.
Easy to manage.
Easy to manage.
What do you dislike about the product?
The dashboard/UI would be improved and made more user-friendly.
What problems is the product solving and how is that benefiting you?
It helps us to scan the libraries before the release. Is also a part of CI/CD pipeline.
Keep your dependency up to date
What do you like best about the product?
A unique feature that was offered by Mend Renovate for Github is the support for the Gradle version catalog. This is a very useful feature for big mono repo, to keep your java dependencies managed by gradle up-to-date and vulnerability free.
In the middle of 2022(when our organization was moved to Github), gradle version catalog was not supported by Github Dependabot, so natural Mend Renovate was a natural choice for us.
In the middle of 2022(when our organization was moved to Github), gradle version catalog was not supported by Github Dependabot, so natural Mend Renovate was a natural choice for us.
What do you dislike about the product?
As Mend Renovate for Github is a free tool, offered functionality is more than enough. A nice add-on would be integration with JIRA that allows tracking vulnerabilities with synchronization on the both side.
What problems is the product solving and how is that benefiting you?
Mend Renovate for GitHub help us keep our dependencies up to date, which causes fewer vulnerabilities in the final Product. The time required to update dependency was significantly decreased.
Mend makes security issue fixing and reporting really simple.
What do you like best about the product?
Mend's integration with source control systems and IDEs is simply outstanding.
What do you dislike about the product?
Nothing I dislike as of now. But I wish mend had a chat feature or something for quick resolution of small issues without needing to open support cases.
What problems is the product solving and how is that benefiting you?
Mend is simplifying the whole process of addressing security issues and helps us generate reports to present to our customers on how secure our applications are.
Fast and Reliable
What do you like best about the product?
IntelliJ Plugin - The analysis is really quick
What do you dislike about the product?
Viewing the report. I feel overwhelmed when I log in to Mend. The landing page should just contain the project I'm interested in and the related reports. Similar to tools like Fortify and Sonar.
What problems is the product solving and how is that benefiting you?
Helping our product to stay compliant by analyzing and reporting the security vulnerabilities in time.
Good
What do you like best about the product?
For Commerical Use Helpful this is the Best But Some Slow Conditions is that
What do you dislike about the product?
nothingthis is the Best But Some Slow Conditions is that
What problems is the product solving and how is that benefiting you?
Slow
Easy integration with CI/CD and powerful shift-left approach
What do you like best about the product?
It makes it very easy to break down and analyze all the open source packages that are in client's code with reports and dashboards to easily identify Critical, Highs, Med and Low risks. I also like that it easily integrates with Github and Azure DevOps to the point that I don't have to login to another site or console and I can see issues right on my platform for tracking and remediation
What do you dislike about the product?
The commonality with a lot of SAST tools is the amount of false positives.
What problems is the product solving and how is that benefiting you?
Client developers need data to patch the applications right from the start and with Mend we can do pre-commit and PR triggers that fix before we are shipping to production for better security.
Good tool but UI is clunky
What do you like best about the product?
The information about vulnerabilities is generally up to date.
What do you dislike about the product?
The UI is very clunky. Doesn't integrate well into development workflow. as we need to come to this tool to audit the findings. Would be nice to have it as a github plugin from where we can directly audit the findings.
What problems is the product solving and how is that benefiting you?
The main challenge it solves is that it scans our dependencies for vulnerabilities.
Being integrated in our corporate toolchain means, that we don't have to justify the value multiple times to stakeholders.
Being integrated in our corporate toolchain means, that we don't have to justify the value multiple times to stakeholders.
Make it easy for your development team to address open source risk
What do you like best about the product?
Mend is a very intuitive tool that has integrations with many typical pipelines and repos. We have found it to be very good at identifying vulnerable components with a low false positive rate. It provides good recommendations for the best fix version of a library.
What do you dislike about the product?
Mend is starting to build out full support for exporting results in standard SBOM formats, but generating these outputs currently requires running separate Python scripts.
What problems is the product solving and how is that benefiting you?
Mend is used to address open source risk by evaluating for vulnerabilities, license risk, and code quality. It supports the enforcement of policies.
Good tool for SCA
What do you like best about the product?
1. Seemless integration with SCM.
2. License management for open source repositories.
2. License management for open source repositories.
What do you dislike about the product?
It would be great if an auto dependency resolution/management is provided for any finding.
What problems is the product solving and how is that benefiting you?
Implementing shift left strategy
showing 21 - 30