Centralized security monitoring has reduced false positives and improves dependency governance
What is our primary use case?
I have been using Mend.io and no longer work for that company after leaving a few months back. Mend.io has been used for probably three or four years and it was the best tool that we actually replaced. It was the best tool I ever saw for all the dependencies and all those things.
Everything that has to do with dependencies and third parties was ingested through Mend.io; we used the SaaS tool for a different purpose and then we used Mend.io for all dependencies.
We have been using some capabilities of Mend.io, particularly when AI started; we wanted to utilize some of the AI features, but AI is a gray area. If you want to use it specifically for AI, then that is something every organization must think about how much they should automate the processes. Other than AI, I think the automation is wonderful.
What is most valuable?
What I think about Mend.io is that it is very efficient, highly efficient, and it is the best scanning tool for SCA.
Mend.io stands against other SCA solutions on AI; I would say it is on the top compared to any other tool in the market.
The continuous monitoring capabilities in Mend.io aided our organization in maintaining a secure environment; that was wonderful. We automated processes and we actually created our own centralized platform where all the feeds were ingested, and we could see the SAST, DAST, IAST, and SCA everything in one single place. So we had to do some work, but we actually did custom centralization of efforts and were able to ingest everything into our own platform, our own centralized platform.
What needs improvement?
The only area for improvement I would say is that the false positives are nearly zero; everything is mostly like 99 to 99.99% or we can say 100% accurate.
There were a few areas for improvement just from the last time I saw; I think the user experience had a little problem. We wanted to have certain reports based on our kind of scenario, but the tool did not allow us to create custom reports. We had asked for some facility and some ability for us to create some custom reports. That would be awesome if they allow us to create custom reports the way we wanted.
There is one small area which I don't know whether we should call a tool limitation or a wish list; if I use a library and I don't use all the capabilities of the library but only a portion of it and that portion is not vulnerable, but there is a component which is outdated, that is a problem, even though I don't use that component. Mend.io will discover there is a problem in the whole library; that is correct. That's a valid discovery, but in my case, for example, if I don't use that particular portion, then it actually is not making sense for me, but that's not a limitation of Mend.io; I think that's a general problem with any tool in the market because no tool in the market will actually know what portion of the code I'm actually using from that particular library if it is vulnerable or not.
For how long have I used the solution?
Mend.io has been used for probably three or four years.
What do I think about the stability of the solution?
Mend.io is very stable; we did not have any issues. Being a SaaS product, they are not catering only to one company; they're catering to everyone who uses the tool.
How are customer service and support?
Regarding support, the people who were involved in the commercial side were the direct point of contact with Mend.io, but my understanding is Mend.io provides pretty good support. I did not hear any complaints from those teams that Mend.io is slow or the support is not good; I did not hear anything of that sort in my almost three or four years.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Previously, we used different tools; I actually was involved in the decision-making process. Once we onboarded to Mend.io, we saw a drastic improvement in the way Mend.io reported the SCA findings. Many people were also using SonarQube and some other tools for their internal processes, which was not official, but when they reported, they said the other tools were reporting a lot of false positives compared to Mend.io. No one complained that this is a false positive in Mend.io; we were actually able to see if Mend.io shows there is a problem here, and we used to ask the dev teams to go inside those directories and discover, and they actually said there is a problem.
How was the initial setup?
It is very simple to set up Mend.io, even for developers who had no experience and no exposure to tools in Mend.io; we simply provided some straightforward instructions. We had our own internal Wiki and we wrote those instructions on how to onboard; it was pretty straightforward.
I would say it was the easiest tool to onboard.
What other advice do I have?
Being in the industry of security plus AI, I actually specialize in AI and have written a few books on AI available on Amazon, so I am very cautious about AI, especially anything that includes AI, particularly security tools.
As for AI and other features, AI is a gray area and no tool in the industry is anything good in AI currently. They are evolving and it will probably take five to maybe ten years to be very good in AI. AI is an upcoming area; it is not even stabilized and is an evolutionary area. So anything we want to use, whether it is SCA, SAST, DAST, IAST, or any tool, we have to be very careful with AI.
The documentation is huge and awesome; it's huge.
Since it is a huge Wikipedia, some links might be a little outdated; what they do is point to the new location, and sometimes that new location becomes confusing because it auto-redirects. If we had to refer to some old documentation and we want to just for cross-references to what we had done, then the old links are not available because it redirects to the new location. I think that's the usual case with any other tool because even Synopsys had a similar thing where they had huge documentation, and whatever updates were there, they used to redirect those pages.
Overall, I cannot give a 10 to any tool in the market because no tool would be perfect. Except for the AI part, which I am very sensitive to in any tool in the market, otherwise, I would give a rating of nine; it is a very good tool to use. I have provided a rating of 9 for this review.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
good experience with mend.io
What do you like best about the product?
an easy-to-use and helpful tool for checking auto-updates and dependencies.
What do you dislike about the product?
not quite a good integration and is a bit too pricy.
What problems is the product solving and how is that benefiting you?
depedency check and updates, the remediation suggestions as well.
Useful tool
What do you like best about the product?
Enhances the application security and it's relatively easy to use and integrate.
What do you dislike about the product?
it might be helpful to separate pricing for each product
What problems is the product solving and how is that benefiting you?
Automated dependency updates benefits me a loot to keep the project secure and free of vulnerabilities.
Easy to use
What do you like best about the product?
Easy to use. Helpful. Support is very responsive.
What do you dislike about the product?
Needing to report to the security team that doesn't understand software.
What problems is the product solving and how is that benefiting you?
Keeps us up to date on any known vulnerabilities in the open source packages we leverage.
Mend has been an excellent tool, both for OSA and SAST
What do you like best about the product?
I really like the ability to integrate the tooling directly into our source code repository. This allows us to scan hundreds of repositories without needing to configure each of them separately. Onboarding is simple and the updated user interface is attractive and easy to use.
What do you dislike about the product?
SAST capabilities are new and still maturing. Documentation is good, but could use some improvement.
What problems is the product solving and how is that benefiting you?
Mend is helping us maintain an inventory of all of our open source components and is scanning every commit for open source vulnerabilities. Additionally, Mend is helping us identify potential security vulnerabilities in our source code.
Mend is an excellent SCA solution. The prioritize feature saves a lot of time.
What do you like best about the product?
The most helpful feature in Mend.io is the Prioritize feature. It is a fast scan that checks if a vulnerability is reacheable by your code. So you can fix the vulnerabilities that trully affects your application
What do you dislike about the product?
I miss some kind of PoC for the CVEs that mend identifies. Some times it's hard to verify if the vulnerability is a true positive
What problems is the product solving and how is that benefiting you?
The main problem that Mend.io is solving is about reducing the False Positives vulnerabilities and the non reachable vulnerabilities in the Software Composition Analysis
Mend is a key part of your development process.
What do you like best about the product?
It's scanning capabilities are more than useful. CSM and support teams are really helpful and reactive.
What do you dislike about the product?
Its integration with on-premise tools can be challenging.
What problems is the product solving and how is that benefiting you?
We want to identify and mitigate issues with vurnerabilities and those licenses .