"There are times when we receive alerts about seemingly important libraries, but then WhiteSource Prioritize will show us that our application isn’t actually using the vulnerable method.”
"We want Microsoft’s users to have access to the best industry solutions for open source management. That’s why we reached out to partner with WhiteSource. WhiteSource is a thought leader in the Rugged DevOps space and we are happy that this partnership will bring the confidence, time and money savings they deliver to their customers."
"What I like about this is that it runs in the background, and therefore doesn’t disrupt the developer's workflow. They can develop, but at the same time, as a manager, I can become aware of any potential issues, and have them resolved."
"Simple tool for more visibility around our libraries (versions, security vulnerabilities, and bugs). With [Mend] we have now numbers of how many libraries are outdated or vulnerable. This visibility makes it easier to argue that a library need to be updated. But the main purpose of [Mend] is to see security vulnerabilities, the major benefit is that with [Mend] we have a list of libraries with - current version - newest version - vulnerabilities - known bugs."
"Great product and great support. The online interface looks nice and is easy to use and intuitive. [Mend] allows us to easily see all of our 3rd-party Java libraries at a glance and quickly tell which ones we need to fix- whether they conflict with our license, have security holes, or need to be updated. What used to be a manual process (as in no one ever really did it) is now a nice automated process. What really shines is their support- they are quick to meet with us and solve any issues we have. Even during the evaluation period, they made improvements to the product in areas we were concerned. It always pays to have awesome customer support. I know if we run into any other issues that they'll be quick to fix them."
"[Mend has] quick and easy setup. The trial was very quick to get up and running and the support through the trial process was excellent. The interface is simple and easy to get at the important information. Support has been quick and responsive."
"We needed a solution to approve licenses and identify vulnerabilities in the open source components within our software. Our previous form-based approval process took up to three months and required approval from multiple teams including IT security and legal.”
"Trust is everything in the security industry. Our customers trust Open Raven because we help prevent data breaches, but they also have to trust that the software we build is secure. For us it’s about doing the right thing, and WhiteSource helps us achieve that."
“With [Mend], we hit the ground running, and immediately got all the info and insights we needed to be able to ship our releases confident that our containerized applications were safe and compliant.”
“Vonage Engineering’s leadership team wanted consistent policies in place across the entire organization to address any existing issues and to ensure new vulnerabilities – both technical and legal – were not introduced.”
“The role of my organization is to get development teams to take a bigger ownership interest in the security of their products, so we are only integrating tools into their pipeline. We don’t maintain our own pipeline.”
“It was impressive that the scan could be started without any preparation and the results were obtained immediately. Because of this ease of use, I felt that [Mend] was a tool that could solve our problems and immediately decided to introduce it to my team.”
“Mend plays an integral part in helping us identify where we’re using potentially risky or insecure open source and getting that addressed as early as possible. We rely on Mend for great remediation guidance. Remediation guidance is extremely critical to helping developers fix the problem correctly the first time, every time.”
“Working with Mend has been the right decision. When we have the right set of recommendations, we feel more secure. Mend has been able to scale to our needs. It’s been able to scale to the ecosystems that we want to cover. Overall it’s been a great decision.”
“The biggest value we get out of Mend is the fast feedback loop, which enables our developers to respond rapidly to any vulnerability or license issues. When a vulnerability or a license is disregarded or blocked and there is a policy violation, they get the feedback directly.”