The platform integrates into existing workflows, allowing developers to identify and remediate supply chain vulnerabilities without leaving their environment. The Mend team has been incredibly responsive and quick to remediate any issues we encountered. Automated tools for dependency updates significantly reduce the manual effort required to maintain a secure and up-to-date software supply chain. We also found that they beat other vendors to include new critical zero-day vulnerabilities in their database.
February 27, 2026
Response times and required follow-ups from the Vendor are sometimes slow for priority ticket requests. Documentation can be hard to follow or out-of-date. Transitive dependency scanning requires a lot of manual effort. Some functionality requires deeper validation than the initial Vendor claims. Knowledge, pro-activeness and awareness of deprecated features of third party integrations with Mend is not up-to-date e.g Deprecation of PAT tokens in Azure DevOps
February 25, 2026