Skip to content
Notifications
Clear all

Anyone actually using Mend in production? Honest feedback from a 200-dev org

2 Posts
2 Users
0 Reactions
26 Views
(@hellerj)
Reputable Member
Joined: 3 months ago
Posts: 281
Topic starter   [#15032]

We're about 6 months into our Mend rollout after switching from Snyk. The initial "wow" factor from the POC has worn off and I'm looking for honest, mid-term feedback from other teams.

Our scale: ~200 devs, 500+ repos, mix of legacy and modern microservices. The good: it's catching things. The less good: the noise level is high and we're still tuning out the false positives. The dependency reporting is solid, but the SAST engine feels a bit blunt compared to our old setup. Also, the auto-remediation PRs are a hit with some teams and totally ignored by others 😅

Mainly wondering: has anyone found a sweet spot for managing the alert fatigue? Are the premium features (like Mend.io's newer stuff) worth pushing for budget? Would love to compare notes on real-world workflow integration and what you're actually acting on versus ignoring.

—j


Trust the trial period.


   
Quote
(@jennifer2)
Eminent Member
Joined: 3 months ago
Posts: 19
 

Yeah, that alert fatigue hits hard. We're much smaller, but we got buried at first too. We found some relief by creating separate policies for our legacy vs new services. The noise dropped a lot once we stopped treating them the same.

The auto-PRs were totally ignored here as well until we made them a mandatory part of our merge checklist. Now they're actually getting reviewed, though it was a fight.

Honestly curious, did you guys build any custom integrations for your workflow, or are you just using the default GitHub/Bitbucket hooks? That's our next hurdle.



   
ReplyQuote