Browse Software
List Your Product
Loading...
WhiteSource Reviews

User Rating

4.5/5 (Based on 56 Ratings)

Rating Distribution

  • Excellent

    55.4%
  • Very Good

    39.3%
  • Average

    5.4%
  • Poor

    0%
  • Terrible

    0%

User Sentiments

Accurate Vulnerability Detection, Extensive Integrations, Comprehensive License Compliance, Developer-Friendly Tools

Occasional False Positives, Outdated User Interface, Inconsistent Support Responsiveness, Limited Language Support

Do You Use WhiteSource?

Write a Review

Review Summary

Overall, users praise WhiteSource for its user-friendly interface, comprehensive features, and excellent customer support. They highlight its effectiveness in identifying and resolving open source vulnerabilities, ensuring code security and compliance. Users appreciate its ability to automate security checks, reducing manual effort and improving efficiency. However, some users mention the potential for false positives and occasional performance issues. Additionally, a few users suggest room for improvement in the reporting and customization capabilities.

Pros

  • Proactively identifies open source security vulnerabilities and license compliance issues.
  • Integrates seamlessly with various software development tools and continuous integration/continuous delivery (CI/CD) pipelines.
  • Provides detailed vulnerability reports and remediation guidance, enabling developers to address issues quickly.
  • Offers flexible deployment options, including onpremises, cloud, and hybrid environments.

Cons

  • Some users have reported occasional performance issues and latency when scanning large codebases.
  • Limited support for certain programming languages and frameworks, which may require additional customization or workarounds.
  • Pricing may be a concern for smaller organizations or teams with limited budgets.
  • Steep learning curve for new users, requiring some time and effort to fully utilize all features and capabilities.

AI-Generated from the text of User Reviews

Reviews
JC

John C

November 19, 2023 Source: G2.com
"Industry-leading SCA, work in progress"
What do you like best about Mend.io (formerly WhiteSource)?

Quick and accurate scanning, multiple plug-ins for various different build and ci/cd platforms. Prioritize, Whitesource for developers

What do you dislike about Mend.io (formerly WhiteSource)?

hard to get some features working like

eua, and integration this Jira was challenging

What problems is Mend.io (formerly WhiteSource) solving and how is that benefiting you?

Quick and accurate scanning, multiple plug-ins for various different build and ci/cd platforms. Prioritize, Whitesource for developers

Read more
CM

Christopher M

September 15, 2023 Source: G2.com
"Streamlined Integration for Compliance with Open-Source Licenses & Vulnerability Detection"
What do you like best about Mend.io (formerly WhiteSource)?

One of the strengths of Mend.io lies in the simplicity of integrating their unified agent into our Continuous Integration pipeline. This streamlined process, with its commendable support system and verbose documentation, has reduced setup times. We're now efficiently detecting open-source license violations. Coupled with the integration with JIRA, it ensures that open vulnerabilities are promptly and systematically recorded, streamlining our response and tracking processes.

What do you dislike about Mend.io (formerly WhiteSource)?

While the platform functions efficiently, there's scope for modernising the user interface. It would be beneficial to see Mend.io adopt a more contemporary design. However, it's worth noting that this aesthetic aspect doesn't detract from the product's overall usability.

What problems is Mend.io (formerly WhiteSource) solving and how is that benefiting you?

Mend addresses the challenges associated with open-source license compliance and vulnerability detection in our codebase. Efficiently identifying and alerting us about any license violations ensures that our software remains compliant, reducing potential legal risks. Additionally, its vulnerability detection capabilities enable us to swiftly pinpoint and rectify security vulnerabilities, enhancing our applications' overall safety and integrity.

The integration of Mend.io with JIRA facilitates a systematic recording and tracking of these vulnerabilities, ensuring a structured and effective response from our team. As a result, we maintain a higher standard of code quality and save significant time and resources, allowing us to focus on further development and innovation. This has been crucial for us, especially in the demanding environment of Continuous Integration.

Read more
AU

Anonymous User

July 18, 2023 Source: G2.com
"Industry Leading SCA Tool"
What do you like best about Mend.io (formerly WhiteSource)?

Streamlined approach to SCA makes integration easy and informative. New features being added that have incredible value for what you are paying.

What do you dislike about Mend.io (formerly WhiteSource)?

It seems as though sometimes features are released without having much documentation published about it.

What problems is Mend.io (formerly WhiteSource) solving and how is that benefiting you?

SBOM, SCA, Supply Chain Risk Managment.

Read more
DS

Dhananjay S

July 12, 2023 Source: G2.com
"Very helpful and supporting to Detect Open Source Vulnerabilities"
What do you like best about Mend.io (formerly WhiteSource)?

The quality report & recommendations.

User friendly Interface

What do you dislike about Mend.io (formerly WhiteSource)?

Sometimes rigid process, difficulties in cutomization

What problems is Mend.io (formerly WhiteSource) solving and how is that benefiting you?

Sharing OpenSource Licencing details to customers

Resolve security challenges due to older versions of OSS

Read more
AU

Anonymous User

January 13, 2023 Source: G2.com
"Mend makes security issue fixing and reporting really simple."
What do you like best about Mend.io (formerly WhiteSource)?

Mend's integration with source control systems and IDEs is simply outstanding.

What do you dislike about Mend.io (formerly WhiteSource)?

Nothing I dislike as of now. But I wish mend had a chat feature or something for quick resolution of small issues without needing to open support cases.

What problems is Mend.io (formerly WhiteSource) solving and how is that benefiting you?

Mend is simplifying the whole process of addressing security issues and helps us generate reports to present to our customers on how secure our applications are.

Read more
SM

Sonal M

September 2, 2022 Source: G2.com
"Best Open Source Analysis (OSA) at this moment."
What do you like best about Mend.io (formerly WhiteSource)?

Best Open Source analysis with their In-house and other multiple sources of software vulnerabilities. Also one of the few companies in the market which will give you license & policy violations alert as well.

Pipeline integration of this tools is greatly helpful for the software which are shipped out securely & safely.

Also, Whitesource is a software as a service (SAAS) offering, so there is no need to physically maintain any server at your end or your data center for any implementation.

Mostly such things are helpful in today's world as most of your administration is offloaded to them.

What do you dislike about Mend.io (formerly WhiteSource)?

No downside of using this software in OSA and DEVOPS Pipeline.

Support Team's response is sometimes delayed but sometimes it's prompt.

Need to define an SLA

Recommendations to others considering Mend.io (formerly WhiteSource):

Best valuation for the price point in the market right now, go for it.

Other Opensource tools are available, but they aggregate their data from open source websites such as NVD or CVE web sites, they are good to a certain extent, however a paid products gives you more insight into multiple data sources for vulnerability and their in-house research and development team also enhances their product to give you optimum use of white source.

What problems is Mend.io (formerly WhiteSource) solving and how is that benefiting you?

Open Source software which are used in almost all of software products needs to be evaluated for vulnerabilities and secure products should be shipped in market.

The JAR file which is their unified agent can easily be run in a JAVA based environment on any base operating system.

There is no file which is being uploaded to WhiteSource, instead all your open source software's SHA1 values are being sent to whiteSource securely and then Whitesource does their analysis on their side.

Whitesource's R&D team is also working diligently to improve their vulnerability DB.

Also, this tool can be incorporated in DevSecOps pipeline as well.

Read more
rs

rahul s

August 29, 2022 Source: G2.com
"Great platform and team is always working on improving the product"
What do you like best about Mend.io (formerly WhiteSource)?

Overall I feel that Mend is a good platform and what I love most is that they are always working on continued improvements.

Moreover features like prioritize etc make it the best

What do you dislike about Mend.io (formerly WhiteSource)?

frankly it's a good tool. Still, if i have to list the cons,i would say .so , .a file types support should be added. Also, prioritize should include support for more and more package maangers .

What problems is Mend.io (formerly WhiteSource) solving and how is that benefiting you?

all our deployment compliance, license violation issues, library management, vulnerability management , in house patterns/libraries and policy violation are trusted to Mend .

Read more
JM

Jérémie M

October 1, 2020 Source: G2.com
"Renovate is a must-have"
What do you like best?

Renovate is a time saver, more specifically, saving precious engineering time and brings peace of mind as we automated our application dependencies updating.

What do you dislike?

Nothing really. The Renovate tool is part of the toolchain for every applications. And is now free!

What problems are you solving with the product? What benefits have you realized?

Automate everything! Instead of a manual process to update our dependencies and relying on a benevolent engineer to keep track of the necessary updates, Renovate does it automatically and with a lot of different configuration options.

We are now confident that our application is not falling behind.

By automating dependency management updates, we can reallocate engineers hours to more value adding projects.

Read more
UR

User in Retail

August 27, 2020 Source: G2.com
"Indispensable"
What do you like best?

Turns keeping your software up to date from a chore into something you don’t even need to think about.

What do you dislike?

Faster creation of MRs - perhaps a database of who uses what dependency so as soon as a new release is created they can all be updated, rather than each repo polling their dependencies individually.

Recommendations to others considering the product:

Focus on building a good test suite so you can turn on auto merging. Also an automatic semantic release pipeline makes things even smoother.

What problems are you solving with the product? What benefits have you realized?

Keeping a large number of repos up to date with internal and external dependency changes. It had made it much easier for us to split our own libraries up into smaller pieces.

Read more
UT

User in Telecommunications

August 6, 2020 Source: G2.com
"Whitesource is an excellent tool for ensuring adequate security for third party software packages"
What do you like best?

The licensing/copyright check is a major time saver.

What do you dislike?

For Nodejs the npm packages run deep, and currently it is not easy to determine the root package for some of the vulnerabilities.

Recommendations to others considering the product:

I would recommend integrating the scan process into your devOps pipeline.

What problems are you solving with the product? What benefits have you realized?

Whitesource automates the listing of third party packages, checks the liceensing/copyright info, and displays any CVEs within these packages.

Read more

We understand SaaS better

SaaSworthy helps stakeholders choose the right SaaS platform based on detailed product information, unbiased reviews, SW score and recommendations from the active community.

icon

Buyers

Looking for the right SaaS

We can help you choose the best SaaS for your specific requirements. Our in-house experts will assist you with their hand-picked recommendations.

icon

Makers

Want more customers?

Our experts will research about your product and list it on SaaSworthy for FREE.

Get Listed