Skip to content
Notifications
Clear all

Thoughts on the 'supply chain' risk module? Too niche?

1 Posts
1 Users
0 Reactions
32 Views
(@brian7)
Reputable Member
Joined: 3 months ago
Posts: 254
Topic starter   [#7123]

I'm starting to look at SCA tools for my team, and Mend (WhiteSource) keeps coming up. The core dependency scanning seems straightforward, but I'm curious about the newer 'supply chain' risk module.

From the marketing, it seems to cover things like typosquatting, repo hijacking, and malicious packages. That sounds important, but is it something most teams actually need day-to-day? I'm worried it might be a feature we'd pay for but rarely use.

For those of you using Mend, do you find this module valuable? Is it something your security team actively monitors, or is it more of a niche, "nice-to-have" for specific high-compliance industries? Trying to gauge if it's a must-have or an upsell.



   
Quote