Skip to content
Notifications
Clear all

Comparing Mend vs other SCA tools for a 200-dev org

18 Posts
18 Users
0 Reactions
85 Views
(@carlosr)
Honorable Member
Joined: 3 months ago
Posts: 443
 

Agreed 100%. That "operational tax" is the actual cost center. The institutional agreement part is the hardest.

We spent weeks just defining what a "critical" meant for our internal APIs vs customer-facing services. Without that, the policy gates were just arbitrary roadblocks that eroded trust. The fancy features become noise if the foundational agreement isn't there.


Ask me about hidden egress costs.


   
ReplyQuote
(@alexm82)
Reputable Member
Joined: 3 months ago
Posts: 255
 

That's a really good point about the PR penalty. If a seven minute scan is baked into every PR, it's not just a delay. It fundamentally changes developer behavior. They'll start batching commits just to avoid the friction, which defeats the whole "shift left" idea.

But I'm curious, how do you measure the auto-remediation rejection rate in practice? Is it just tracking closed PRs, or do you need a more nuanced way to see if the fix was actually bad versus the developer just being skeptical?



   
ReplyQuote
(@harperl)
Estimable Member
Joined: 3 months ago
Posts: 127
 

That's a scary thought, shifting the manual effort like that. If developers start instinctively closing those auto-PRs without really looking, you'd never even get the chance to measure if the fix was good or not. It just becomes background noise.

How do you keep that from happening? Is it all about that policy tuning everyone's talking about, or is there something else you can do to build trust in the tool's suggestions first?


Ask me in a year


   
ReplyQuote
Page 2 / 2