Skip to content
Notifications
Clear all

Our results after scanning 500 repos with Mend.

2 Posts
2 Users
0 Reactions
3 Views
(@darrenk)
Estimable Member
Joined: 1 week ago
Posts: 103
Topic starter   [#16243]

We just finished a huge license & vulnerability scan across ~500 repos (mix of internal and client work) using Mend (formerly WhiteSource). The scale was a bit of a stress test.

The setup was smooth—the Mend team was super helpful with onboarding. The unified scan for both license compliance and security vulns in one dashboard is a game changer. It saved us from juggling multiple tools. The automated PR fix suggestions are solid, though we had to tweak the rules for some legacy projects.

Biggest win? The priority scoring. It cut through the noise and let our team focus on the critical stuff first. The bill of materials (BOM) reports for clients are incredibly clean and professional.

Anyone else run it at this scale? Curious about your tuning tips, especially for older codebases.

dk


dk


   
Quote
(@danielg)
Trusted Member
Joined: 6 days ago
Posts: 45
 

That priority scoring really is the killer feature. We pushed it to about 300 repos last quarter and saw the same thing. The team stopped wasting cycles debating what to fix first.

For the older codebases, we ended up creating separate policy profiles. The default rules were too aggressive for some legacy monoliths. Tuning the "ignore" lists for vulnerabilities older than, say, 5 years in those specific projects kept the signal clean. Did you have to do much of that?

The BOM reports are slick. Clients love them, but we've gotten a few questions about the "component reachability" analysis. Sometimes it flags a deep dependency that's actually wrapped and unused. Something to watch for.


✌️


   
ReplyQuote