Skip to content
Notifications
Clear all

WhiteSource or Black Duck for a Fortune 500 finance team

3 Posts
3 Users
0 Reactions
1 Views
(@eval_rookie_42)
Reputable Member
Joined: 4 months ago
Posts: 158
Topic starter   [#11315]

I'm helping my team evaluate SCA tools for our development and security workflows. We're a large finance org, so compliance and license risk are top concerns.

We've narrowed it down to Mend (WhiteSource) and Black Duck. For those with experience in regulated industries:

* What was the onboarding and integration like for a complex, multi-repo environment?
* How accurate are the policy and license violation alerts? We need low noise.
* Any major pitfalls with the Mend scanner for container or .NET workloads?

Our priority is a clear audit trail and reducing manual review. Budget is important, but less so than accuracy.



   
Quote
(@devops_dad)
Estimable Member
Joined: 5 months ago
Posts: 131
 

Used Mend back at a large insurance shop. For a complex multi-repo setup, the onboarding is heavy. Be prepared for a dedicated project manager and a fair bit of initial pipeline tuning. It does settle down.

On accuracy for policies and licenses, it's good, but you'll absolutely need to spend time tuning the policies out of the box. The defaults were too noisy for our compliance folks. Once dialed in, the audit trail is solid and reduced our manual reviews by a ton.

Biggest .NET pitfall we hit was around NuGet packages that pull in transitive dependencies with odd licenses. The scanner sometimes missed those unless we did a full, clean restore in the pipeline stage. For containers, make sure you're scanning the built image, not just the Dockerfile. Mend's layered analysis caught things the CLI scanner missed.


it worked on my machine


   
ReplyQuote
(@jessicam)
Trusted Member
Joined: 2 weeks ago
Posts: 51
 

The point about tuning policies out of the box is so real. We're not as big, but our security team nearly rejected a tool last year because the default alerts were constant fire drills. 😅

How long did it take your compliance folks to get the policy tuning "dialed in"? Was it weeks or months of tweaking?



   
ReplyQuote