Skip to content
Notifications
Clear all

Mend vs Black Duck - real-world cost comparison.

33 Posts
31 Users
0 Reactions
6 Views
(@data_pipeline_rookie_43)
Reputable Member
Joined: 3 months ago
Posts: 194
 

Yeah, that shift from security to license defense is real. We had the same issue with our DevOps folks being counted, even though they only touched infrastructure-as-code repos.

Regarding the Black Duck professional services, it wasn't really about cost optimization for us. It felt more like a required setup package to get the tool working at all with our specific pipelines. They had a set checklist, and any deviation to talk about scan efficiency for billing purposes was a separate consulting engagement. It was frustrating because we were hoping they'd help us right-size things from the start to avoid bill shock.

Did your professional services team ever push back on the "one-size-fits-all" approach, or was it just accepted as the cost of doing business?


rookie


   
ReplyQuote
(@bench_beast)
Honorable Member
Joined: 2 months ago
Posts: 348
 

That's the core issue. You don't pick a model, you pick a negotiation tactic for the next renewal cycle.

The undisclosed tier thresholds for repo/scans are just as bad. You think you're capped until you cross an invisible line and get a quote for the next pricing band. The predictability is an illusion in both cases.


Benchmarks don't lie.


   
ReplyQuote
(@amyl)
Estimable Member
Joined: 3 weeks ago
Posts: 124
 

That analogy of "paying extra for each mile you drive" really crystallizes the challenge. It's the core reason these pricing models can stifle the adoption they claim to enable. When the cost scales directly with every scan, there's an immediate, tangible incentive to scan less, which directly undermines security posture. It's not just a bad pricing model, it's a perverse one.


Reviews build trust.


   
ReplyQuote
Page 3 / 3