Reviews from AWS Marketplace
0 AWS reviews
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
Easy to use
What do you like best about the product?
Easy to use. Helpful. Support is very responsive.
What do you dislike about the product?
Needing to report to the security team that doesn't understand software.
What problems is the product solving and how is that benefiting you?
Keeps us up to date on any known vulnerabilities in the open source packages we leverage.
- Leave a Comment |
- Mark review as helpful
Mend has been an excellent tool, both for OSA and SAST
What do you like best about the product?
I really like the ability to integrate the tooling directly into our source code repository. This allows us to scan hundreds of repositories without needing to configure each of them separately. Onboarding is simple and the updated user interface is attractive and easy to use.
What do you dislike about the product?
SAST capabilities are new and still maturing. Documentation is good, but could use some improvement.
What problems is the product solving and how is that benefiting you?
Mend is helping us maintain an inventory of all of our open source components and is scanning every commit for open source vulnerabilities. Additionally, Mend is helping us identify potential security vulnerabilities in our source code.
Mend is an excellent SCA solution. The prioritize feature saves a lot of time.
What do you like best about the product?
The most helpful feature in Mend.io is the Prioritize feature. It is a fast scan that checks if a vulnerability is reacheable by your code. So you can fix the vulnerabilities that trully affects your application
What do you dislike about the product?
I miss some kind of PoC for the CVEs that mend identifies. Some times it's hard to verify if the vulnerability is a true positive
What problems is the product solving and how is that benefiting you?
The main problem that Mend.io is solving is about reducing the False Positives vulnerabilities and the non reachable vulnerabilities in the Software Composition Analysis
Mend is a key part of your development process.
What do you like best about the product?
It's scanning capabilities are more than useful. CSM and support teams are really helpful and reactive.
What do you dislike about the product?
Its integration with on-premise tools can be challenging.
What problems is the product solving and how is that benefiting you?
We want to identify and mitigate issues with vurnerabilities and those licenses .
Great Product
What do you like best about the product?
It is easy to navigate and to find vulnerabilities and violations.
What do you dislike about the product?
I know there is a newer version coming, but it could have a bit more functionality.
What problems is the product solving and how is that benefiting you?
Mend is helping us contain vulnerabilities and licensing.
Mend Implementation and Review with other tools
What do you like best about the product?
Mend is one of the good tool and we can use the tool SCA, SAST and container scans and results are good compared to other tools
What do you dislike about the product?
More false positives, difficult intagration, lot of issue in scanner updations and configuration
What problems is the product solving and how is that benefiting you?
It helps to identify the vulnerablities at the early stage,help us by providing all the details about the Code.
Leader in the field
What do you like best about the product?
Mend has several strengths. First, the company behind it is relatively transparent, helpful, and straightforward. I appreciated that they didn't oversell the product the way several competitors did. The software integrates nicely with Microsoft development tools. Customer support is good and responsive as well.
What do you dislike about the product?
This isn't really a knock, but as a point in time, they are integrating the SCA and the, I think, acquired SAST solutions together into a common platform. Obviously, that's a large effort, and once that is done, it will be even better.
What problems is the product solving and how is that benefiting you?
Mend simplifies the reporting and auditing aspect of documenting that vulnerabilities have been managed properly.
Streamlined Integration for Compliance with Open-Source Licenses & Vulnerability Detection
What do you like best about the product?
One of the strengths of Mend.io lies in the simplicity of integrating their unified agent into our Continuous Integration pipeline. This streamlined process, with its commendable support system and verbose documentation, has reduced setup times. We're now efficiently detecting open-source license violations. Coupled with the integration with JIRA, it ensures that open vulnerabilities are promptly and systematically recorded, streamlining our response and tracking processes.
What do you dislike about the product?
While the platform functions efficiently, there's scope for modernising the user interface. It would be beneficial to see Mend.io adopt a more contemporary design. However, it's worth noting that this aesthetic aspect doesn't detract from the product's overall usability.
What problems is the product solving and how is that benefiting you?
Mend addresses the challenges associated with open-source license compliance and vulnerability detection in our codebase. Efficiently identifying and alerting us about any license violations ensures that our software remains compliant, reducing potential legal risks. Additionally, its vulnerability detection capabilities enable us to swiftly pinpoint and rectify security vulnerabilities, enhancing our applications' overall safety and integrity.
The integration of Mend.io with JIRA facilitates a systematic recording and tracking of these vulnerabilities, ensuring a structured and effective response from our team. As a result, we maintain a higher standard of code quality and save significant time and resources, allowing us to focus on further development and innovation. This has been crucial for us, especially in the demanding environment of Continuous Integration.
The integration of Mend.io with JIRA facilitates a systematic recording and tracking of these vulnerabilities, ensuring a structured and effective response from our team. As a result, we maintain a higher standard of code quality and save significant time and resources, allowing us to focus on further development and innovation. This has been crucial for us, especially in the demanding environment of Continuous Integration.
Mend - Fixing What I Didn't Know Was Broken
What do you like best about the product?
Using the CLI unified agent is a breeze and the syntax is easy to understand/follow. The web UI is not only easy on the eyes but the user experience makes it easy to find what you're looking for.
What do you dislike about the product?
Currently, at least in my use of the product, there are two different portals depending on which product I'm using, SAST vs SCA, which is kind of awkward to bounce between.
What problems is the product solving and how is that benefiting you?
Mend takes the reigns on most of the heavy lifting around the Static Code Analysis needs, considering it is much quicker and effecient at scanning the nearly 400,000 lines of code I'm throwing at it than I would be if doing it by hand like a caveman.
best SCA and SAST tool
What do you like best about the product?
It is a great tool to scan our binaries, we have been using it for a while now and have liked the solution. It is good to have sbom as a part of SCA scanning portal but I would like to see SAST also intergrated there.
What do you dislike about the product?
As of today, we do not see any major issues from mend, one of the concerns we have is that recently support team has not replied back to our tickets for weeks and we have had to escalte it via our partners to get it resolved.
What problems is the product solving and how is that benefiting you?
Mend has helped us with a tool which has reduced our overhead as a devops team by intergrating it to our ci/cd pipelines and increased our velocity. it has also helped us with a single point of presence for SBOMS
showing 1 - 10