Tool integration

Mend SCA Integration Guide

Enterprise SCA platform (formerly WhiteSource) with licence and policy enforcement

Get a Free API Key

Integrate Mend SCA with Vulnetix. Use the Mend CLI to scan dependencies and export SARIF, CycloneDX, or SPDX SBOMs for centralised vulnerability management.

SaaS platformSARIFCycloneDXSPDX

Run Mend SCA in CI

Scan on every push and upload the report as a workflow artifact:

- name: Install Mend CLI
  run: |
    curl -LJO https://downloads.mend.io/production/unified/latest/linux_amd64/mend
    chmod +x mend && sudo mv mend /usr/local/bin/

- name: Run Mend SCA
  run: mend dep --format sarif --filename dep-results.sarif
  env:
    MEND_URL: https://saas.mend.io
    MEND_EMAIL: ${{ secrets.MEND_EMAIL }}
    MEND_USER_KEY: ${{ secrets.MEND_USER_KEY }}

- name: Upload report
  uses: actions/upload-artifact@v6
  with:
    name: mend-sca
    path: dep-results.sarif
    if-no-files-found: warn

Then one publish job hands every artifact in the run to Vulnetix, recorded under Mend SCA's own name and version. Written once per workflow, however many scanners you run:

publish:
  name: Publish to Vulnetix
  runs-on: ubuntu-latest
  needs: [scan]        # every scanner job, or its report is never published
  if: always()         # or one failing scanner suppresses all the others
  permissions:
    contents: read
    actions: read      # required to list the run's artifacts
  env:
    VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
    VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
  steps:
    - uses: actions/checkout@v5
    - name: Install Vulnetix CLI
      run: |
        curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
        echo "$HOME/.local/bin" >> "$GITHUB_PATH"
    - name: Publish scanner reports
      env:
        GITHUB_TOKEN: ${{ github.token }}
      run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --json

After the run, vulnetix gha status reports what was actually recorded.

How Vulnetix compares: better together

Vulnetix does not replace Mend SCA. Keep running it. Vulnetix sits on top of Mend SCA (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

Mend SCA is strongest at its core category and also carries features in SAST, Container & Image Scanning, IaC & Cloud Configuration, License Compliance, SBOM Generation, just as Vulnetix spans categories.

CapabilityVulnetixMend SCA
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentationMend SAST scans 25 languages with taint analysis and an MCP server
SCA / dependencies40+ ecosystems, transitive graphCore SCA over direct and transitive dependencies with organizational policy enforcement (mend dep CLI)
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine
Container & imageImage CVEs, base image, Dockerfile~ Scans container images and OS packages across image layers
IaC / misconfigurationTerraform, k8s, CloudFormation~ Scans Kubernetes configurations and IaC files feeding the same inventory
Secret scanning1,000+ rules, source + binary + git history
Cloud / CSPMCloud-posture findings, compliance tab
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policyIdentifies component licenses and flags policy conflicts and incompatible combinations
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signableExports SPDX and CycloneDX SBOMs from a unified inventory across scan types
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzer
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEVIncorporates EPSS exploitability data and CVSS 4.0 severity to prioritize
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semanticCall-graph reachability flags and deprioritizes unreachable vulnerabilities
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe versionRenovate-based automated remediation with merge-confidence scoring
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What Mend SCA does well

Where Vulnetix adds to it: Vulnetix ingests Mend's SCA/SAST/container findings and dedups them with the rest of the stack into one queue, adding CISA KEV + Coalition ESS + CWSS + Vulnetix LEV alongside Mend's EPSS, plus immutable versioned VEX, SSVC and EOL policy. Better together: Mend keeps driving Renovate-based fixes and taint-analysis SAST while Vulnetix is the org-wide ASPM layer above it.

No migration, no rip-and-replace. Mend SCA keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise Mend SCA results in Vulnetix

Upload Mend SCA SARIF, CycloneDX, SPDX output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

Mend SCA documentation ↗

Wire Mend SCA into your CI/CD pipeline →