No more typing reviews! Try our Samantha, our new voice AI agent.

Which code scanning solution is scanning MuleSoft?

BS
Application Security Manager at IDB BAnk
  • 4
  • 268
PeerSpot user

2 Answers

Last answered Jul 11, 2023
SS
Principal Architect at ModusBox
User
Jul 11, 2023
Real User
Jul 20, 2023

So, regarding your question, it was at clientX that I had the chance to first see these two tools into action, at least partially since we haven't gone fully live during that project. Mend.io is something I even proposed us to use here at newClient, since it does a Software Composition Analysis (SCA) and generates what's called a SBOM, Software Bill of Materials. It basically scans the pom.xml (before the package is built, not after) and generates a report with the dependencies and any known vulnerabilities, along with the CVE details/score, along with a proposed fix (if it exists). FOD can also be used for the same thing, and at clientX that was the intent, having it complementing the first scan made by mend.
As you described, there are these two concepts in the software security space, SCA and SAST. My feeling is that even though we can use the SCA capabilities of these tools (either Mend or FOD) for the SBOM generation, making sure we're not introducing a vulnerable component, for SAST (which is more focused on the code analysis) we're still very limited (mostly due to the nature of our Mule applications, totally XML based). I've never seen anything for the proprietary DW language either. Here at newClient we do use SonarQube loaded with a variation of the mule-sonarqube-plugin that is implemented in our pipelines to also generate a report and interrupt the build process if anything critical (we use it mostly to enforce internal standards via xpath rules) is found. If you need any assistance let me know steve.scott@apipeople.com - we are a Mule partner, expert and work in community bank/cu space on Fiserv, JHA, FIS etc.

PeerSpot user
Search for a product comparison
Rohit Sircar - PeerSpot reviewer
Integration Solutions Lead | Digital Core Transformation Service Line at Hexaware Technologies Limited
Vendor
Jul 10, 2023
reviewer2560476 - PeerSpot reviewer
Director at INtegralzone
User
Sep 24, 2024

Please have a look at Falcon Suite (https://integralzone.com/falco...), a product built exclusively for MuleSoft project Governance, Auditing and Compliance. It addresses all of the above requirements and more.

PeerSpot user
Learn what your peers think about MuleSoft API Manager. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
892,678 professionals have used our research since 2012.
MuleSoft API Manager offers a user-friendly platform with comprehensive integration capabilities, strong security, and scalable architecture. It's designed to streamline API management and development processes through robust analytics and a rich interface.MuleSoft API Manager stands out with its lightweight design, offering extensive connector libraries and ease of applying policies via drag-and-drop functionality. Its robust analytics enhance operational efficiency. Users can implement...
Download MuleSoft API Manager ReportRead more