We performed a comparison between JFrog Xray and Mend based on real PeerSpot user reviews.
Find out what your peers are saying about GitLab, Snyk, Sonatype and others in Software Composition Analysis (SCA)."The solution is stable and reliable."
"Good reporting functionalities."
"I would say that this solution has helped our organization by allowing us to automate a lot of the processes."
"The inventory management as well as the ability to identify security vulnerabilities has been the most valuable for our business."
"There are multiple different integrations there. We use Mend for CI/CD that goes through Azure as well. It works seamlessly. We never have any issues with it."
"I am the organizational deployment administrator for this tool, and I, along with other users in our company, especially the security team, appreciate the solution for several reasons. The UI is excellent, and scanning for security threats fits well into our workflow."
"Mend has reduced our open-source software vulnerabilities and helped us remediate issues quickly. My company's policy is to ensure that vulnerabilities are fixed before it gets to production."
"The solution boasts a broad range of features and covers much of what an ideal SCA tool should."
"The dashboard view and the management view are most valuable."
"We set the solution up and enabled it and we had everything running pretty quickly."
"WhiteSource helped reduce our mean time to resolution since the adoption of the product."
"Since we have been using the solution via APIs, there are some limitations in the APIs."
"Lacks deeper reporting, the ability to compare things."
"I think that the user interface should be expanded to provide customers with a better dashboard for reviewing their feedback regarding their images and the vulnerabilities that are associated with the images."
"They're working on a UI refresh. That's probably been one of the pain points for us as it feels like a really old application."
"I rated the solution an eight out of ten because WhiteSource hasn't built in a couple of features that we would have loved to use and they say they're on their roadmap. I'm hoping that they'll be able to build and deliver in 2022."
"We have been looking at how we could improve the automation to human involvement ratio from 60:40 to 70:30, or even potentially 80:20, as there is room for improvement here. We are discussing this internally and with Mend; they are very accommodating to us. We think they openly receive our feedback and do their best to implement our thoughts into the roadmap."
"The solution lacks the code snippet part."
"The only thing that I don't find support for on Mend Prioritize is C++."
"The initial setup could be simplified."
"WhiteSource only produces a report, which is nice to look at. However, you have to check that report every week, to see if something was found that you don't want. It would be great if the build that's generating a report would fail if it finds a very important vulnerability, for instance."
"I would like to see the static analysis included with the open-source version."
Enjoy a free DevOps platform cloud subscription
JFrog Xray is ranked 9th in Software Composition Analysis (SCA) with 3 reviews while Mend is ranked 4th in Software Composition Analysis (SCA) with 13 reviews. JFrog Xray is rated 8.0, while Mend is rated 8.2. The top reviewer of JFrog Xray writes "Reasonably priced with good scanning and reporting capabilities". On the other hand, the top reviewer of Mend writes "Easy to use, great for finding vulnerabilities, and simple to set up". JFrog Xray is most compared with Black Duck, Snyk, Fortify Static Code Analyzer, Veracode Software Composition Analysis and Sonatype Nexus Firewall, whereas Mend is most compared with SonarQube, Black Duck, Snyk, Veracode and Veracode Software Composition Analysis.
See our list of best Software Composition Analysis (SCA) vendors.
We monitor all Software Composition Analysis (SCA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.