Mend is fine at listing licenses. But the alerting is unusable noise. It drowns you in false positives and trivialities.
* Getting an alert for a `GPL-2.0` license in a `devDependency` of a build tool that never ships.
* Constant "policy violation" alerts for `MIT` packages because someone didn't fill a custom field.
* No way to intelligently route alerts based on real risk (e.g., production vs. test, library type).
The default setup creates alert fatigue instantly. You either turn them all off or ignore them. Example of a useless default policy alert:
```
Component: left-pad@1.3.0
License: MIT
Violation: "Approved License List" - Missing attribution text in project file.
Severity: HIGH
```
Now you have a "HIGH" severity ticket for an MIT license with no actual legal risk. The signal-to-noise ratio is broken. You spend more time configuring Mend to be quiet than actually reviewing real issues.
Simplicity is the ultimate sophistication
Yeah, this is the exact kind of thing I was worried about when we started looking at SCA tools. That alert about left-pad being a "HIGH" severity for missing attribution text sounds painfully familiar from our trial.
It makes me wonder, if you have to spend all your time tuning out the noise, are you actually more vulnerable because real issues get buried? Like, when a truly problematic license like a strict GPL variant pops up in a core runtime dependency, will you even see it after you've conditioned yourself to ignore the alerts?
What's your workaround? Did you just turn off the policy alerts entirely and run license reports manually, or did you find a way to make the filtering actually work?
You nailed it. The "HIGH" severity for an MIT attribution text is classic Mend.
I tried to fix it. Spent a week building granular policies to distinguish dev vs. prod, runtime vs. tooling. The result? A labyrinth of rules that broke every time someone updated a package or we added a new project type. The noise just came back through a different pipe.
So yeah, the workaround is to disable all the automated policy alerts. We run a manual compliance report every quarter and actually *look* at it. The irony is we catch more real issues now because we're not constantly distracted by their "HIGH" priority tickets for left-pad.
been there, migrated that
Completely agree about the policy labyrinth. The moment you start creating those granular rules, you become a full-time Mend administrator.
I tried the manual report route too. We do it monthly, but added one step: we run a targeted scan on any pull request to `package.json` in our main application repos. Catches the real runtime license issues at the gate, ignoring all the dev tool noise. It's a hack, but it works.
Makes you wonder why the tool's smartest use case is to mostly turn it off, doesn't it?
Spreadsheets > marketing slides.