Introducing G2.ai, the future of software buying.Try now
Endor Labs
Sponsored
Endor Labs
Visit Website
Product Avatar Image
Mend.io

By Mend

4.3 out of 5 stars

How would you rate your experience with Mend.io?

Endor Labs
Sponsored
Endor Labs
Visit Website
It's been two months since this profile received a new review
Leave a Review

Mend.io Reviews & Product Details

Profile Status

This profile is currently managed by Mend.io but has limited features.

Are you part of the Mend.io team? Upgrade your plan to enhance your branding and engage with visitors to your profile!

Value at a Glance

Averages based on real user reviews.

Time to Implement

2 months

Return on Investment

16 months

Mend.io Media

Mend.io Demo - Security Dashboard
The Mend Platform Security Dashboard provides a high‑level overview and analytics for SCA, SAST, and IMAGE scan findings across your entire Organization.
Mend.io Demo - Value Dashboard
The Value Dashboard provides clear remediation insights and tracks key security metrics like Mean Time to Remediate (MTTR) and overall Finding Reduction %, so teams can confidently demonstrate progress in securing their applications.
Mend.io Demo - Application List with AI Frameworks
A centralized view of applications across the organization and the AI frameworks they leverage, providing visibility into usage and potential security considerations.
Product Avatar Image

Have you used Mend.io before?

Answer a few questions to help the Mend.io community

Mend.io Reviews (112)

Reviews

Mend.io Reviews (112)

4.3
112 reviews

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Alex V.
AV
CTO
Small-Business (50 or fewer emp.)
"Makes keeping up with updates 1000x easier!"
What do you like best about Mend.io?

The customization and ability to self-host Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

A bit complicated to set up on Gitlab and occasional bugginess Review collected by and hosted on G2.com.

Sujith Q.
SQ
Azure Architect
Small-Business (50 or fewer emp.)
"First steps with renovate and Terraform"
What do you like best about Mend.io?

It works with a bare minimum of configuration Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

It took me quite a while to find out what that bare minimum was although there is documentation available. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Small-Business (50 or fewer emp.)
"Renovate Github Bot helps me to keep my repos up to date"
What do you like best about Mend.io?

I think the best about the Whitesource Products are the Integration with for example Github. The Github Apps are easy to install and provide a great user experience. For exmple the renovate bot automatically informs you about package updates. When updating packages packages from a monorepo are considered. Also changelogs are displayed in pull request messages from the renovate bot. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

I think there is nothing to dislike about the whitesource products. Review collected by and hosted on G2.com.

Christian D.
CD
Senior Java Analyst Programmer
Small-Business (50 or fewer emp.)
"Invaluable tool to keep your software safe"
What do you like best about Mend.io?

Summary: Whitesource shows us which libraries can be upgraded and which ones are vulnerable. This keeps our code up-to-date with other project's releases. Having an integration into our pipeline assures us we can follow this up easily.

Applying Whitesource to our projects has helped us tremendously in keeping our project secure. It would be more difficult for our developers to search around to try and find those vulnerabilities by themselves. Most projects do have hundreds of third-party libraries, and even more are downloaded transitively. By comparing the used libraries with known and reported vulnerabilities, we have everything we need in one place.

Each new branch with updated code, triggers a Whitesource build in our pipeline. The email reports are nice triggers for our developers to start looking into vulnerabilities and library updates. Whitesource gives useful resolution suggestions, such as how to avoid the vulnerabilities or which library version no longer has the issue.

Another useful feature is the check on licences. Most developers do not bother looking into which libraries are included in their projects. Whitesource gives a comprehensive list and overview of all licences used in a project. This allows early detection of any non-free library and gives the opportunity to find alternatives quickly. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

For each new branch we add to the project, a new product section is created. When our branches are then merged into the master branch, those products remain. Each email report will also include and compare them to the other branches, making the report less useful. This has triggered us to regularly and manually delete those product sections, and only keep the latest reports and branches. Review collected by and hosted on G2.com.

MH
Small-Business (50 or fewer emp.)
"Powerful tool to manage external libraries"
What do you like best about Mend.io?

Renovate is easy to setup and works with all VCS you can think of (also self-hosted). I was impressed by the amount of configuration that exists and it saves me quite some time keeping dependencies up-to-date.

Documentation is also really good. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

Although the first run was easy, configuring details was a bit of trial and error at first. I was unsure about what a global and what a project specific setting is. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Mid-Market (51-1000 emp.)
"Perfect product"
What do you like best about Mend.io?

The application gives you a really good overview of all the outdated dependencies, an overview of all the licenses used in all the dependencies, all the vulnerabilities coming out of the used dependencies, policy violations, and much more. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

The UI could be updated but for the EE it's suitable. Review collected by and hosted on G2.com.

Verified User in Program Development
UP
Small-Business (50 or fewer emp.)
"Works like a charm"
What do you like best about Mend.io?

Out of the box it's already helping a lot. When you dive into the configurations there's even more awesome things you can achieve. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

I didn't like the constant stream of emails from Github pull requests. Something you can easily manage with the right config settings. Review collected by and hosted on G2.com.

Dotan S.
DS
Chief Technology Officer
Small-Business (50 or fewer emp.)
"Great products, Renovate is a perfect fit for our open-source!"
What do you like best about Mend.io?

- Monorepo support

- Super fast responses

- Rebasing works great Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

- Adding it to an existing project might bloat the repo at first.

- Missing the ability to group all changes based on commits, in a single PR. (this way CI runs for each change, and you can get a daily overview) Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Mid-Market (51-1000 emp.)
"Whitesource Renovate was easy to set up, and very configurable"
What do you like best about Mend.io?

The configurability is great. I have tried other tools which only supported a tiny subset of certain programming languages and their package managers. Whitesource Renovate can be configured to update version for pretty much anything, as long as you can find a consistent place that lists versions, such as github releases, and you can regex yourself to the current version you are using.

This helped us set up version upgrades for Helm charts stored in ArgoCD Application files. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

It can be a bit unclear why a file isn't picked up and considered for version upgrades. If you have set up a regex, and no files match looks exactly the same as if files match but the contents doesn't. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Enterprise (> 1000 emp.)
"Positive experience while rolling out WhiteSource"
What do you like best about Mend.io?

WhiteSource has been very active helping us to get started and get the most out of the tool, this also helps resolves the "dislikes" to a great extent. WhiteSource has also been very willing to help out investigate incorrect attribution. Single Sign-on makes makes it easy to switch to the portal. The home-view is a good dashboard with an overview of the organization, product, or project status. There are many integration options, such as Jira, GitHub, Travis CI, Jenkins, TeamCity, Bamboo, Azure DevOps, Circle CI, AWS CodeBuild, Google Cloud Build, etc. Review collected by and hosted on G2.com.

What do you dislike about Mend.io?

The "Policies" are quite limited in their current form and only a single policy can trigger. This means a policy at the product level can prevent organization wide policy violations to trigger. This can be useful when making exceptions as the product level, but this also means a product level admin can overrule organization wide decisions. The products - projects model takes quite a bit of insight and help to be used effectively. Review collected by and hosted on G2.com.

Pricing Insights

Averages based on real user reviews.

Time to Implement

2 months

Return on Investment

16 months

Average Discount

12%

Perceived Cost

$$$$$

How much does Mend.io cost?

Data powered by BetterCloud.

Estimated Price

$$k - $$k

Per Year

Based on data from 6 purchases.

Mend.io Comparisons
Product Avatar Image
Snyk
Compare Now
Product Avatar Image
Black Duck
Compare Now
Product Avatar Image
SonarQube
Compare Now
Mend.io Features
Configuration Management
Reporting and Analytics
Issue Tracking
Static Code Analysis
Command-Line Tools
Compliance Testing
Language Support
Integration
Transparency