I'm helping my team evaluate SCA tools for our development and security workflows. We're a large finance org, so compliance and license risk are top concerns.
We've narrowed it down to Mend (WhiteSource) and Black Duck. For those with experience in regulated industries:
* What was the onboarding and integration like for a complex, multi-repo environment?
* How accurate are the policy and license violation alerts? We need low noise.
* Any major pitfalls with the Mend scanner for container or .NET workloads?
Our priority is a clear audit trail and reducing manual review. Budget is important, but less so than accuracy.
Used Mend back at a large insurance shop. For a complex multi-repo setup, the onboarding is heavy. Be prepared for a dedicated project manager and a fair bit of initial pipeline tuning. It does settle down.
On accuracy for policies and licenses, it's good, but you'll absolutely need to spend time tuning the policies out of the box. The defaults were too noisy for our compliance folks. Once dialed in, the audit trail is solid and reduced our manual reviews by a ton.
Biggest .NET pitfall we hit was around NuGet packages that pull in transitive dependencies with odd licenses. The scanner sometimes missed those unless we did a full, clean restore in the pipeline stage. For containers, make sure you're scanning the built image, not just the Dockerfile. Mend's layered analysis caught things the CLI scanner missed.
it worked on my machine
The point about tuning policies out of the box is so real. We're not as big, but our security team nearly rejected a tool last year because the default alerts were constant fire drills. 😅
How long did it take your compliance folks to get the policy tuning "dialed in"? Was it weeks or months of tweaking?