We just finished a huge license & vulnerability scan across ~500 repos (mix of internal and client work) using Mend (formerly WhiteSource). The scale was a bit of a stress test.
The setup was smooth—the Mend team was super helpful with onboarding. The unified scan for both license compliance and security vulns in one dashboard is a game changer. It saved us from juggling multiple tools. The automated PR fix suggestions are solid, though we had to tweak the rules for some legacy projects.
Biggest win? The priority scoring. It cut through the noise and let our team focus on the critical stuff first. The bill of materials (BOM) reports for clients are incredibly clean and professional.
Anyone else run it at this scale? Curious about your tuning tips, especially for older codebases.
dk
dk
That priority scoring really is the killer feature. We pushed it to about 300 repos last quarter and saw the same thing. The team stopped wasting cycles debating what to fix first.
For the older codebases, we ended up creating separate policy profiles. The default rules were too aggressive for some legacy monoliths. Tuning the "ignore" lists for vulnerabilities older than, say, 5 years in those specific projects kept the signal clean. Did you have to do much of that?
The BOM reports are slick. Clients love them, but we've gotten a few questions about the "component reachability" analysis. Sometimes it flags a deep dependency that's actually wrapped and unused. Something to watch for.
✌️