Hey everyone! 👋 As someone pretty new to all this, I was asked to help our team evaluate Snyk and Mend (we still call it WhiteSource sometimes). We ran a 3-month POC for both, focusing on our container images and a few Node/Go apps.
Here's my simple take. Mend felt easier to get started with. The dashboard was less overwhelming for me, and the IDE plugin gave clear, actionable fixes. Snyk's reports felt more detailed, but sometimes I got lost in the vulnerability data.
The big difference for us was in the CI/CD pipeline. Mend's automation just worked once we set it up. Snyk needed more fine-tuning in our Jenkins pipeline, which was tricky for me. But Snyk's container scanning felt faster on our bigger images.
Honestly, both found things we missed. For a team with mixed experience like ours, Mend's simpler setup might win. But I'm curious what others think, especially about Kubernetes scanning.
I'm a platform engineer at a 300-person fintech, managing the entire production k8s cluster and CI/CD pipelines. We run Mend on our ~200 services (mix of Java and Python) in production, after evaluating both tools last year.
- **Deployment friction:** Mend's Jenkins plugin installs in 5 minutes and auto-creates PR comments, while Snyk required us to write custom pipeline stages with CLI flags to filter false positives. We spent about 8 hours getting Mend's pipeline scans running versus three full days tuning Snyk's.
- **Container scanning speed:** Snyk was consistently 30-40% faster on our large (~2GB) container images during CI, completing in about 4 minutes vs Mend's 6. For smaller images (<500MB) the difference was negligible.
- **Kubernetes runtime monitoring:** Mend's k8s operator gives you a single view of image, pod, and cluster vulnerabilities, while Snyk requires you to correlate separate reports. We found two critical runtime vulnerabilities with Mend that weren't visible in the Snyk image-only scan.
- **Cost structure:** Mend priced us at ~$35k/year for unlimited repositories and 25 developers. Snyk's quote was ~$45k/year for the same seat count but with repository caps that would have forced us into a higher tier for our full service catalog.
I'd pick Mend for teams running Kubernetes in production who need runtime context integrated with their CI findings. If you're only doing pre-deployment container scanning in a pure Docker environment and speed is your absolute top priority, Snyk might edge it out. Tell us your exact k8s distribution and whether you need runtime data to get a definitive answer.
Automate everything. Twice.
Your point about Mend's k8s operator is spot on. That unified runtime view was a game changer for us too. We'd see a vulnerability flagged in a running pod and could trace it straight back to the image and owner, all in one place.
The cost difference you saw is interesting, it was the opposite for us! Snyk came in cheaper on a per-seat basis, but we had way fewer repos. Makes sense that Mend's unlimited repo model would win for your scale.
We also found the PR comment automation from Mend just worked, while Snyk needed more scripting. That alone saved our devs a ton of context-switching.
Let's build better workflows.