Integrate Mend SCA with Vulnetix. Use the Mend CLI to scan dependencies and export SARIF, CycloneDX, or SPDX SBOMs for centralised vulnerability management.
Run Mend SCA in CI
Scan on every push and upload the report as a workflow artifact:
- name: Install Mend CLI
run: |
curl -LJO https://downloads.mend.io/production/unified/latest/linux_amd64/mend
chmod +x mend && sudo mv mend /usr/local/bin/
- name: Run Mend SCA
run: mend dep --format sarif --filename dep-results.sarif
env:
MEND_URL: https://saas.mend.io
MEND_EMAIL: ${{ secrets.MEND_EMAIL }}
MEND_USER_KEY: ${{ secrets.MEND_USER_KEY }}
- name: Upload report
uses: actions/upload-artifact@v6
with:
name: mend-sca
path: dep-results.sarif
if-no-files-found: warnThen one publish job hands every artifact in the run to Vulnetix, recorded under Mend SCA's own name and version. Written once per workflow, however many scanners you run:
publish:
name: Publish to Vulnetix
runs-on: ubuntu-latest
needs: [scan] # every scanner job, or its report is never published
if: always() # or one failing scanner suppresses all the others
permissions:
contents: read
actions: read # required to list the run's artifacts
env:
VULNETIX_ORG_ID: ${{ secrets.VULNETIX_ORG_ID }}
VULNETIX_API_KEY: ${{ secrets.VULNETIX_API_KEY }}
steps:
- uses: actions/checkout@v5
- name: Install Vulnetix CLI
run: |
curl -fsSL https://cli.vulnetix.com/install.sh | sh -s -- --install-dir "$HOME/.local/bin"
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Publish scanner reports
env:
GITHUB_TOKEN: ${{ github.token }}
run: vulnetix gha upload --org-id "$VULNETIX_ORG_ID" --jsonAfter the run, vulnetix gha status reports what was actually recorded.
How Vulnetix compares: better together
Vulnetix does not replace Mend SCA. Keep running it. Vulnetix sits on top of Mend SCA (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
Mend SCA is strongest at its core category and also carries features in SAST, Container & Image Scanning, IaC & Cloud Configuration, License Compliance, SBOM Generation, just as Vulnetix spans categories.
| Capability | Vulnetix | Mend SCA |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✓ Mend SAST scans 25 languages with taint analysis and an MCP server |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✓ Core SCA over direct and transitive dependencies with organizational policy enforcement (mend dep CLI) |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ~ Scans container images and OS packages across image layers |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ~ Scans Kubernetes configurations and IaC files feeding the same inventory |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✓ Identifies component licenses and flags policy conflicts and incompatible combinations |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✓ Exports SPDX and CycloneDX SBOMs from a unified inventory across scan types |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✗ |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ✗ |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✓ Incorporates EPSS exploitability data and CVSS 4.0 severity to prioritize |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✓ Call-graph reachability flags and deprioritizes unreachable vulnerabilities |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✓ Renovate-based automated remediation with merge-confidence scoring |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What Mend SCA does well
- Automated remediation built on Renovate with merge-confidence scoring that predicts build compatibility from aggregated CI data across millions of updates
- Unified AppSec platform bundling SCA, SAST (25 languages with taint analysis), container and IaC under one developer subscription
- Reachability analysis on call graphs deprioritizes unreachable vulnerable functions to cut noise
- Strong license compatibility engine that detects incompatible-license combinations, not just per-component licenses
Where Vulnetix adds to it: Vulnetix ingests Mend's SCA/SAST/container findings and dedups them with the rest of the stack into one queue, adding CISA KEV + Coalition ESS + CWSS + Vulnetix LEV alongside Mend's EPSS, plus immutable versioned VEX, SSVC and EOL policy. Better together: Mend keeps driving Renovate-based fixes and taint-analysis SAST while Vulnetix is the org-wide ASPM layer above it.
No migration, no rip-and-replace. Mend SCA keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise Mend SCA results in Vulnetix
Upload Mend SCA SARIF, CycloneDX, SPDX output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.