New Features and Updates
(SAST) A Project Risk Factors widget containing high-level Contextual Project Classification information is now available in the Project Summary dashboard.
(IaC) The Infrastructure as Code (IaC) engine now includes the ability to suppress or mark findings as "In Review".
(Container) Minor improvements to the Malicious Package management user experience.
(SCA) Mend.io now seamlessly integrates into the Port.io platform, allowing developers to monitor application security findings within their familiar environment and access the corresponding issue details without a context switch.
Resolved Issues
Fixed an issue where workflow violation email notifications were not sent to administrators following a Mend CLI scan. This was caused by a failure in the violations lookup process during email generation. The fix ensures that administrators correctly receive email alerts for workflow violations as expected.
Fixed an issue where assigning an additional role to an existing user group at the application scope would not persist after saving. The system now correctly saves and retains multiple roles for user groups, ensuring consistent access management.
Fixed an issue where user display names were incorrectly populated with email addresses during SAML SSO login, under specific conditions. The system now correctly respects custom attribute mappings, ensuring that the display name reflects the configured claim value from the identity provider.
(SCA) Fixed an issue where exporting a Dependencies Risk Report at the project level in Full PDF format incorrectly generated a PDF overview accompanied by separate CSV files. The report now correctly exports as a single, comprehensive PDF document containing all relevant details.
New Features and Updates
Mend now supports source-level coverage in SBOM exports and imports for both SPDX and CycloneDX standards. Users can export SBOMs at the granular file level, including unmatched source files, along with associated CVEs, licenses, and copyrights. Additionally, importing SBOMs with file-level components now triggers asynchronous matching to identify source libraries and unmatched files, ensuring comprehensive visibility and compliance for non-package-managed codebases.
Mend.io now seamlessly integrates into the Port.io platform, allowing developers to monitor application security findings within their familiar environment and access the corresponding issue details without a context switch.
Resolved Issues
Fixed an issue where exporting a Dependencies Risk Report at the project level in Full PDF format incorrectly generated a PDF overview accompanied by separate CSV files. The report now correctly exports as a single, comprehensive PDF document containing all relevant details.
Fixed an issue where empty JavaScript files containing only a newline character were incorrectly identified as the simplepeer-5.11.6.min.js library. This misidentification led to inaccurate security alerts, such as CVE-2021-41248, being flagged for projects containing these files. The detection logic has been updated to ensure that empty or near-empty files are no longer incorrectly matched with known libraries.
New Features and Updates
Minor improvements in the AI-based Triage capability in the Developer Platform.
(Open Beta) Scala support is now in open beta, supporting a wider breadth of CWEs compared to the closed beta phase. Customers can now analyze Scala projects to further reduce security risk.
Scala detection is disabled by default. Please reach out to your CSM at Mend.io to enable it.
Improved the accuracy of the JavaScript hardcoded-password rule by refining the detection logic for identifiers, ensuring more reliable security findings.
The Suppression Requests CSV export now includes a direct link to each finding in the platform. This new column allows for immediate navigation from the exported file to specific findings, eliminating the need for manual searches and significantly streamlining the bulk review and triage process.
Resolved Issues
Improved performance when loading secrets detection findings in minified JavaScript files.
Fixed a bug where clicking the Compliance Standards drill-down on the project Summary page would open the Code Findings view with zero findings displayed. The drill-down now correctly navigates to the findings view with the appropriate filters.
Fixed an issue where the SAST engine incorrectly flagged the use of `NSURL` in Swift as a CWE-676 (External URL Access) vulnerability.
Fixed an issue where C/C++ vulnerabilities were not properly detected when using low-probability (LP) sources. The analysis engine now correctly identifies these findings by treating file open and read operations as valid taint sources, ensuring comprehensive security coverage for complex C/C++ codebases.
New Features and Updates
Introducing an Echo integration for managing hardened images in the Mend Platform. The integration allows users to connect their Echo environments to the Mend Platform, facilitating automated security scanning and centralized management of container image vulnerabilities, including VEX data and dedicated risk factor chips in the UI.
Minor improvements to the Malicious Package management user experience.
New Features and Updates
(Premium / Core) Introducing System Prompt Risk (open beta), a new detection and remediation offering by Mend AI, for mitigating risks posed by system prompts used in conversational AI interfaces.
A new System Prompt Risk table inventories system prompts and provides quick export/sharing and deep-link side panel for prompt context.
System Prompt Risks are integrated into the existing AI Security Risk Factors across Projects and Applications. The classification appears as a Conversational Interface chip, is filterable, and automatically participates in dashboards and workflows.
Remediation in the form of a hardened system prompt is available in the System Prompt side panel, providing clear, copy-ready remediation guidance for AppSec engineers and developers.
The AI Security Dashboard has been enriched with system prompt risk data.
System prompt risk data is also available via API.
New Features and Updates
The Mend SAST CLI console summary has been enhanced to provide better clarity when using multiple scanning engines. The updated printout now includes a dedicated "Detector" field to distinguish between different scan types. Additionally, the "Language" field now correctly reflects the scanned programming language rather than the engine, and results are sorted alphabetically by language, ensuring a more intuitive and organized view of scan results across different detectors.
Resolved Issues
Fixed an issue where workflow violation email notifications were not sent to administrators following a Mend CLI scan. This was caused by a failure in the violations lookup process during email generation. The fix ensures that administrators correctly receive email alerts for workflow violations as expected.
Resolved Issues
Fixed an issue where the Unified Agent intermittently timed out during the initial update request due to the reuse of stale keep-alive connections. The agent now utilizes a fresh connection for each request, ensuring reliable communication and preventing unnecessary delays caused by half-open sockets.
Upgraded several transitive dependencies in the Unified Agent to fix CVEs.
New Features and Updates
Enhanced the Developer Platform's Repository and Jobs tables to support sorting and filtering across the entire dataset rather than just the current page. This update ensures that users can accurately organize and locate specific repositories or jobs within the full scope of their data, providing a more comprehensive and efficient management experience.
(SAST) Introduced a production-grade AI-based triage capability for SAST findings, enabling developers and security managers to quickly identify and prioritize real vulnerabilities in their SCM. This feature automates false positive detection, provides AI-generated explanations and exploitation paths, and significantly reduces manual review time.
For more information, refer to the AI Triage section of the relevant SCM:
Resolved Issues
(SCA) Fixed an issue where scan results were sorted alphabetically, potentially causing high-severity findings to be omitted due to table size limitations. Results are now prioritized by severity level, ensuring that the most critical vulnerabilities are always reported and accurately reflected in scan success or failure statuses.
New Features and Updates
(SAST) GitHub issues created for SAST findings now include the full data flow trace, showing each step of how tainted data moves through the code. The check run summary has been simplified to a brief overview with a direct link to the corresponding issue, so developers get the right level of detail in the right place without leaving GitHub.
(SAST) Users can now trigger /mend code actions by replying directly to Mend's finding comment in PR conversations, instead of posting a separate comment at the bottom of the PR.
Resolved Issues
(SCA) Fixed an issue where scan results were sorted alphabetically, potentially causing high-severity findings to be omitted due to table size limitations. Results are now prioritized by severity level, ensuring that the most critical vulnerabilities are always reported and accurately reflected in scan success or failure statuses.
(Renovate) Fixed an issue where Renovate for GitHub.com would intermittently stop processing repositories due to an "Error getting installation token." This required users to manually disable and re-enable Renovate to resume operations. The underlying authentication mechanism has been stabilized to ensure continuous repository scanning and pull request creation without manual intervention.
(Renovate) Fixed an issue where Renovate workers individually requested GitHub installation tokens, increasing API overhead. The system now centralizes token generation on the server, improving efficiency and reducing the number of requests to GitHub.
Resolved Issues
Fixed an issue where the Gradle `mendDeps` pre-step was executed in the incorrect directory when using the SCA orchestrator. This occurred due to a path resolution mismatch that caused the process to default to the workspace root instead of the specific project directory. The logic has been corrected to ensure Gradle commands run in the proper context, allowing for successful dependency resolution and preventing failures in multi-module or nested repository structures.
Fixed an issue where scan results were sorted alphabetically, potentially causing high-severity findings to be omitted due to database column size limitations. Results are now prioritized by severity level, ensuring that the most critical vulnerabilities are always reported and accurately reflected in scan success or failure statuses.
Unified Agent 26.5.1 | Renovate 43.235.0 | Remediate 26.6.1 | Pre-Scan Builder (PSB) 25.8.1
New Features and Updates
(SCA) Java 25 projects are now supported in SCA scans.
(Renovate Enterprise Self-hosted) Introduced a comprehensive Dependency Dashboard in the Renovate Self-hosted Web UI, providing users with centralized visibility and actionable control over dependency management. The dashboard features dedicated sections for repository notes and warnings, detected dependencies, and suggested updates. Users can now directly trigger Renovate jobs, create or open pull requests, and retry or rebase updates. This enhancement streamlines workflows and ensures parity for environments where in-repository dashboards are unavailable.
Resolved Issues
(SCA) Fixed an issue where the `gradle.additionalArguments` parameter was not correctly applied when defined within the `whitesource.config` file during repository integrations.
(SAST) Fixed an issue where manual SAST scans could be triggered via the API even if SAST was not enabled for the target repository. The system now correctly verifies repository settings before initiating a scan, ensuring that no check-runs or security reports are generated for repositories without SAST enablement.
Unified Agent 26.5.1 | Renovate 43.235.0 | Remediate 26.6.1 | Pre-Scan Builder (PSB) 25.8.1
New Features and Updates
Java 25 projects are now supported in SCA scans.
(Renovate Enterprise Self-hosted) Introduced a comprehensive Dependency Dashboard in the Renovate Self-hosted Web UI, providing users with centralized visibility and actionable control over dependency management. The dashboard features dedicated sections for repository notes and warnings, detected dependencies, and suggested updates. Users can now directly trigger Renovate jobs, create or open pull requests, and retry or rebase updates. This enhancement streamlines workflows and ensures parity for environments where in-repository dashboards are unavailable.
Resolved Issues
Fixed an issue where the `gradle.additionalArguments` parameter was not correctly applied when defined within the `whitesource.config` file during repository integrations.