Skip to content
Notifications
Clear all

Mend review after 12 months - what it catches and misses

1 Posts
1 Users
0 Reactions
2 Views
(@jordyn23)
Eminent Member
Joined: 7 days ago
Posts: 24
Topic starter   [#12906]

Been using Mend for a year now across a few mid-sized web projects. It’s solid for the basics—flagging high-severity CVEs in direct dependencies is its bread and butter. The automatic pull requests for updates are a lifesaver and have definitely kept us compliant.

Where it feels a bit thin is on the actionable insights front. The reports can be noisy, and it sometimes misses deeper license conflicts in transitive dependencies that other tools we've trialed caught. For a pure security gate, it's great. For a holistic view of your supply chain health, you might need to supplement. Anyone else find the same? 👋



   
Quote