"There are times when we receive alerts about seemingly important libraries, but then WhiteSource Prioritize will show us that our application isn’t actually using the vulnerable method.”
"We want Microsoft’s users to have access to the best industry solutions for open source management. That’s why we reached out to partner with WhiteSource. WhiteSource is a thought leader in the Rugged DevOps space and we are happy that this partnership will bring the confidence, time and money savings they deliver to their customers."
"What I like about this is that it runs in the background, and therefore doesn’t disrupt the developer's workflow. They can develop, but at the same time, as a manager, I can become aware of any potential issues, and have them resolved."
"We had many issues in our software supply chain that we couldn’t handle manually. We needed a faster, thorough, and more efficient solution that offered automated detection and remediation of vulnerabilities and threats."
"The dependency confusion issue made supply chain security very real and tangible for a lot of people. Dependency confusion became an industrywide issue as it was not just theoretical. So, proactively, we put more emphasis on standardization and automation of this security process."
"The biggest value that we get out of Mend is broad visibility into our open-source usage across the company, We partner with the development teams that utilize this tool and they have many different libraries and software stacks."
“We found that our banking application had been compromised,” said the company’s Product Security Architect. “Our root cause analysis showed a vulnerable library, leading to the conclusion we needed to deploy an SCA [Software Composition Analysis] solution to understand our open source software use and how to best mitigate our risk.”
“The legal industry is one of the most risk averse industries known to man for obvious reasons. We’re highly regulated but not necessarily by regulators, but by the industry itself. Everyone is looking and they expect us to be down to nearly zero vulnerabilities."
“We were completely in the dark as to what sorts of vulnerabilities we had, as well as their impact. It was a big gap we had to address in our app stack – and we also needed to understand where we were with open source licensing.”