Mend Logo

Mend

0
Commercial
Visit Website

Mend (formerly WhiteSource) is an application security platform that combines multiple security scanning and management capabilities: The platform integrates several key components: - Software Composition Analysis (SCA) for detecting vulnerabilities and license compliance issues in open source components - Static Application Security Testing (SAST) for analyzing proprietary source code - Container security scanning for identifying vulnerabilities in container images - Automated dependency updates to maintain current versions of dependencies - AI model risk analysis capabilities for assessing security risks in AI-generated code - SBOM (Software Bill of Materials) generation and management Key features include: - Repository integration with major development platforms - Real-time vulnerability detection during development - Reachability analysis to determine exploitable vulnerabilities - License compliance management for open source components - Centralized security policy management and configuration - Integration with CI/CD pipelines and development workflows - Vulnerability prioritization based on CVSS scores and exploitability - Container image analysis and security assessment - Automated dependency update management The platform provides separate interfaces and workflows for both development and security teams, allowing each group to work within their preferred environments while maintaining security oversight.

FEATURES

ALTERNATIVES

Cross-site scripting labs for web application security enthusiasts

A third-party Nginx module that prevents common web attacks by reading a small subset of simple rules containing 99% of known patterns involved in website vulnerabilities.

A Java API for searching and downloading Android applications from Google Play with additional check-in features for generating ANDROID-ID.

Instrumentation-based approach for resolving reflective calls in Android apps.

Reformat and re-indent bookmarklets, ugly JavaScript, and unpack scripts with options available via UI.

StaCoAn is a cross-platform tool for static code analysis on mobile applications, emphasizing the identification of security vulnerabilities.

A Burp extension for scanning JavaScript files for endpoint links

Technique used to forward one URL to another.

PINNED