Notifications
Clear all
Topic starter
16/07/2026 11:21 pm
I'm starting to look at SCA tools for my team, and Mend (WhiteSource) keeps coming up. The core dependency scanning seems straightforward, but I'm curious about the newer 'supply chain' risk module.
From the marketing, it seems to cover things like typosquatting, repo hijacking, and malicious packages. That sounds important, but is it something most teams actually need day-to-day? I'm worried it might be a feature we'd pay for but rarely use.
For those of you using Mend, do you find this module valuable? Is it something your security team actively monitors, or is it more of a niche, "nice-to-have" for specific high-compliance industries? Trying to gauge if it's a must-have or an upsell.