---
version: "Latest"
language: "en"
---
# Mend Platform Guide

![image-20250126-135327.png](https://docs.mend.io/__attachments/a_e36d9243c39c6bfe8b9764490c4be3a99ddf2a0147186cc815ece1c0f578e3e2/image-20250126-135327.png?cb=f3b87ae7936a172960020f5cf88435af)

## Overview

The Mend Platform offers a powerful suite of Application Security Testing (AST) tools, including the web-based Mend Application user interface and our easy-to-implement integrations, to ensure seamless monitoring, reporting, and remediation of vulnerabilities throughout your software development life cycle (SDLC).

## What does the Mend Platform do?

Mend consolidates all of your organization's information into a single location, with SAST, SCA, and container image scans available for all projects. The Mend Platform streamlines security and license management for your organization with its consistent severity presentation across all scans and centralized management of policies, licenses, and reports.

Our comprehensive Mend Platform documentation provides in-depth information on its many capabilities. Take the time to explore its features and discover how Mend can help you achieve your security objectives.

## Release Notes

* [Mend Container Release Notes](https://docs.mend.io/platform/latest/mend-container-release-notes.md)
* [Mend Renovate Release Notes](https://docs.mend.io/platform/latest/mend-renovate-release-notes.md)
* [Mend Platform Release Notes](https://docs.mend.io/platform/latest/mend-platform-release-notes.md)
* [Mend SAST Release Notes](https://docs.mend.io/platform/latest/mend-sast-release-notes.md)
* [Mend SCA Release Notes](https://docs.mend.io/platform/latest/mend-sca-release-notes.md)
* [Mend AI Release Notes](https://docs.mend.io/platform/latest/mend-ai-release-notes.md)

---
version: "Latest"
language: "en"
---
# ABAP

This article covers ABAP support and vulnerability detection for Mend SAST.

## Mend SAST-supported ABAP file types

| **File Type** |
|---------------|
| .abap         |
| .bsp          |

## Mend SAST-supported ABAP frameworks

| **Framework** |
|---------------|
| BSP           |

## Mend SAST-supported ABAP vulnerability types

The ABAP vulnerability types detected by SAST are provided below, organized by CWE ID within each of their identified severities.

### ABAP high-severity vulnerability types

|---------|--------------------------|
| **CWE** | **Vulnerability Type**   |
| CWE-22  | Path/Directory Traversal |
| CWE-78  | Command Injection        |
| CWE-79  | Cross-Site Scripting     |
| CWE-89  | SQL Injection            |
| CWE-94  | Code Injection           |

### ABAP medium-severity vulnerability types

|---------|---------------------------------|
| **CWE** | **Vulnerability Type**          |
| CWE-400 | Regex Denial of Service (ReDoS) |

---
version: "Latest"
language: "en"
---
# Academic Security Findings in the AI Models Table

**Note:** This feature is only available with a **Mend AI Core** or**Mend AI Premium** subscription.

## Overview

This feature brings academic research on AI model vulnerabilities directly into your AI Models table. Here's what you get and why it matters:

* **Immediate Security Context:** See at a glance which AI models in your environment have known vulnerabilities, based on the latest academic research.

* **Aggregated Risk Indicators:** Each model displays a count of findings, with severity indicators, so you can quickly spot high-risk models.

* **Detailed Vulnerability Insights:** For each finding, you'll see:

  * Vulnerability classification

  * Attack type and affected models

  * Vulnerability score and severity.

  * References to research papers and academic sources

  * Technical details, attack vectors, and mitigation advice

* **Actionable Recommendations:** Each finding includes remediation steps, helping you proactively secure your AI infrastructure.

* **No More Context Switching:** All this information is available right where you already manage your AI models---no need to jump between different tools or interfaces.

**Why it's valuable:**

You can assess and address AI model risks faster, make informed security decisions, and stay ahead of emerging threats---without leaving your familiar workflow.

## Getting it done

**Step 1: Open the AI Models Table**

* Navigate to the AI Models section in your product dashboard.

**Step 2: Review Security Findings at a Glance**

* In the table, each model now displays an aggregated count of security findings, with severity icons (e.g., red for critical, yellow for moderate).

**Step 3: Dive Deeper with the Side Panel**

* Click on any model row to open its side panel.

* You'll see a new **AI Models Findings** tab. Click it to view a list of all academic findings associated with that model.

  ![image-20250911-085726.png](https://docs.mend.io/__attachments/a_45d7f5b597454389a2fee36b49d499d524eafb803eb19b9574b0ef30b4c14969/image-20250911-085726.png?cb=fbea6524cf8db927a3eeee198eab9d05)

**Step 4: Explore Detailed Information**

Click on any finding in the list to open a detailed view.

Here you'll find:

1. **Security Overview** - Contains the severity and ID of the vulnerability.

2. **Finding Information** - Contains the description and mitigation steps, based on the academic papers.

3. **CVSS Score** - Contains information about the vulnerability classification and attack vectors.

   Note: CVSS scores for ML models are determined using a hybrid approach combining LLM-based assessment with manual supervision by Mend AI analysts. The scoring process was initially set up using CVSS 4.0 framework, later converted to CVSS 3.x.

4. **References** - Contains links to the academic research papers.

![image-20250911-140156.png](https://docs.mend.io/__attachments/a_3af469767f2abf5b388e61de2c1e9be105874fbc603b112150763c162fd608bb/image-20250911-140156.png?cb=f78555d1b0523ea527fe9e372a51defc)
AI Model Finding - Security Overview and Finding Information  
![image-20250911-085955.png](https://docs.mend.io/__attachments/a_10e44ff01ab8b8fbf63e660e86dedbbf2b5b398b6437c0e442d22abab7423048/image-20250911-085955.png?cb=78e03f8c625b2903de1c9ab7c1189f5b)
AI Model Finding - CVSS Score and References

**Step 5: Take Action**

* Use the provided recommendations to address vulnerabilities.

* Reference the academic sources for deeper understanding or compliance documentation.

**Step 6: Stay Updated**

* As new security findings are published, the table and findings tab will update automatically---no manual refresh needed.

## Limitations \& Notes

* **Data Migration \& Rescanning:** Findings are based on the current scan of your environment. If you migrate data or rescan, findings may update or change.

* **Academic Source Scope:** Currently, findings are based on academic research papers. Future updates may include additional sources.

* Academic Security findings currently cannot be used in [Automation Workflows](https://docs.mend.io/platform/latest/create-an-automation-workflow-for-mend-ai.md).

* Research papers don't always provide specific action items to mitigate risks.

  Expect Mend AI to continuously update and improve the information about mitigation and mitigation steps.

---
version: "Latest"
language: "en"
---
# Account-level Reports in the Mend AppSec Platform

## Overview

Some Dependencies reports can be generated at the account-level, spanning all the organizations in the account.

## Getting it done

As an account administrator logged into the platform, click your profile picture/initials and then **Account Management** in the drop-down menu:  
![image-20251202-163251.png](https://docs.mend.io/__attachments/a_90868df6b08bb4b4cbd775502308b5a853cf637d9ba17f62c4e29fae1266e7ef/image-20251202-163251.png?cb=5d796af79be9d878545dc1ea8636f261)

This will take you to the Account Management page. Click **Reports** on the bar at the top.  
![image-20251202-163601.png](https://docs.mend.io/__attachments/a_fb7515c38c0903f5c5951c67e98d9e0c6b8cde3ad4eb3320d539ffd7947ee11f/image-20251202-163601.png?cb=448a994965d44aec0c5c7a0cf03fd79d)

Once you click the **Create** button on the far-right, the Create Report wizard will spawn, allowing oyu to select the account-level report to create.  
![image-20251202-163819.png](https://docs.mend.io/__attachments/a_c05d709ad77c556a7a79a96ef438cbb4ea1cadc20dbb2dc41df66211786e1682/image-20251202-163819.png?cb=682f20d2f574c65cc3f02ecf1f17b815)

* Dependencies Inventory

* Dependencies Findings

* Dependencies Findings (by Library)

### Report Configuration

The **Configuration** section of the wizard will allow you configure the following:

* **Report Name** - Mandatory. Defaults to the name of the selected report type.

* **Filter By** - Optional. Note that the available filter may be different between report types.

* **Format** - e.g., "Excel".

* **Notification** - Check this option to get notified by email when the report is ready.

![image-20251202-164139.png](https://docs.mend.io/__attachments/a_43fe55d879b51175f50934c0dc2322f7df5004fe38a2dcb9e2bd5f1e7617fbd8/image-20251202-164139.png?cb=4c4a8f8ac8d692191a3affe8363fdb6f)

Click the **Create** button at the bottom when you are ready to create your report.  
![image-20251202-164724.png](https://docs.mend.io/__attachments/a_1ccaecfe52123ac7d3909323b408c982a27afbf8ffebd694e0ff39f9b2153c92/image-20251202-164724.png?cb=f6d7e4a629b1cce5a4d3f994981df659)

## Legacy SCA Comparison

For customers migrating from the Legacy SCA application, the following table helps ensure you select the correct report type:  

|                                                                                              **Legacy SCA Report Name**                                                                                               | **Mend AI Native AppSec Platform Report Name** |
|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------|
| Inventory                                                                                                                                                                                                             | Dependencies Inventory                         |
| Security Alerts - View By Vulnerability ![image-20251202-170110.png](https://docs.mend.io/__attachments/a_2efc1b6df230281bc3e2a980422bd9cdbb4ebc1060c1d556508e02f4ce174b3a/image-20251202-170110.png?cb=51d013b44ce40292205d15c21b3423f8) | Dependencies Findings                          |
| Security Alerts - View By Library ![image-20251202-170204.png](https://docs.mend.io/__attachments/a_d11112c200e4fc4d3b22eff8e393c5728de3be81e1fc4af483411459d0a4f8d1/image-20251202-170204.png?cb=16ae96df5109081a0c76e92ba03cd54b)       | Dependencies Findings (by Library)             |

---
version: "Latest"
language: "en"
---
# AI Agents Configuration Risk

**Note:** This feature is only available with **Mend AI Core** or **Mend AI Premium** .

Contact your Customer Success Manager at [++Mend.io++](http://mend.io/) for more details.

## Overview

AI agents are increasingly defined through version-controlled configuration files that specify prompts, tool access, permissions, workflows, and integrations. While often treated as simple configuration, these files define the AI system's behavior and attack surface.

Misconfigured agent configurations can enable:

* Command execution

* Credential exposure

* Data exfiltration

* Permission escalation

* Policy bypass

* Prompt injection

**Mend AI**extends static security analysis to AI agent configuration files --- treating them as code and enforcing security controls before they reach production.

The capability provides:

* Discovery of agent configuration files

* Static risk analysis

* Severity classification

* Actionable mitigation guidance

Agent configuration scanning supports development-time assistants (such as Cursor, Claude Code, and Windsurf), declarative runtime agents (such as OpenClaw), and other configuration-driven agent frameworks.

This enables organizations to secure the AI control plane with the same discipline applied to application code and Infrastructure as Code.

## Prerequisites

* A relevant Mend AI entitlement for your organization.

* Your organization's consent to using AI features (via an addendum in your [Mend.io](http://mend.io/) contract).

## The Agent Configurations Table

When in the context of an application/project, click the **Agent Configurations** button on the left-pane menu. This will take you to the Agent Configuration table, listing information about the configuration risk and the **aggregated findings** associated with it.  
![image-20260508-093731.png](https://docs.mend.io/__attachments/a_db6e9900f02d0ba53930ec116ad131edb58aecd66a82717a22d10d11f8bb6f80/image-20260508-093731.png?cb=adb862ebef29b4b31e9e792b3a843c91)

### Filter and Export

Use **Search by name** and **+ More Filters** to filter the data in the table  
![image-20260508-100328.png](https://docs.mend.io/__attachments/a_3932527972eae156b71b3d37dd4bec7b2b113e4cb144b81543cd92a0259c402c/image-20260508-100328.png?cb=4b9924d80ff68b6bca8a3f44379757e3)

At any point the data displayed in the table can be exported to CSV or JSON using the **Export to...** button on the right.

## The Agent Configuration Side-Panel

Click anywhere on a row in the table to spawn its side-panel, listing information about the findings associated with the configuration risk, including their Description, ID, Severity, etc.

### The Overview Tab

The side-panel will display the **Overview** tab by default. This tab contains the following information about the selected agent configuration:

* **Agent Configuration Information**

  * Agent Type

  * File Location (includes a Copy to Clipboard button)

  * Configuration Type

* **Security Overview**

  * Severity

  * Findings

  * Violations

![image-20260508-091338.png](https://docs.mend.io/__attachments/a_76d6a1fb42aca0f15a501b6c0190f8dcfa665ad5e0ca3b385195eb73de6f62e1/image-20260508-091338.png?cb=8be5bdcbfa477feaf8de65137bd1988b)

### The Security Findings Tab

Switch to the **AI Agent Configurations Security Findings** tab to list all the security findings detected for the selected agent configuration.  
![image-20260508-092645.png](https://docs.mend.io/__attachments/a_e3b22eea29f3be9bb574a2eb667078c4547b917a2f07be4d239d53689b64ca0b/image-20260508-092645.png?cb=d6ad6380dbe056761b92b2e595a9514f)

Click a row to display additional information about the security finding in question:

* **Description** (displayed at the top)

* **Security Overview**

  * Severity (Low / Medium / High)

  * ID

  * Mitigation Steps

* **Code Snippet** and **Code Location**

![image-20260508-091912.png](https://docs.mend.io/__attachments/a_42c49d72bb8fa992051229a0956331e6e08612735bd87c3ed62a69ddf96008d0/image-20260508-091912.png?cb=5466f9208ade1daafc1ee717b9181832)

### Supported Agent Configuration Files

The following agent configuration formats are currently supported:  

|     **Agent / Platform**      |               **Supported Configuration Files**               |
|-------------------------------|---------------------------------------------------------------|
| **Cursor**                    | `.cursorrules`, `.cursor/rules/*.md`                          |
| **Claude Code**               | `CLAUDE.md`, `.claude/commands/*.md`, `.claude/settings.json` |
| **GitHub Copilot**            | `.github/copilot-instructions.md`                             |
| **OpenAI Codex CLI**          | `codex.md`, `.codex/*.md`                                     |
| **Windsurf**                  | `.windsurfrules`                                              |
| **Aider**                     | `.aider`, `.conf.yml`                                         |
| **Continue.dev**              | `.continue/config.json`                                       |
| **OpenClaw**                  | `.openclaw/*.json`                                            |
| **Generic Agent Definitions** | `AGENTS.md`, `SKILL.md`                                       |

## Additional Tables and Widgets

1. The AI Agent Configuration Findings are also listed under the **Agent Configurations Security Findings** column in the [Applications and Projects views](https://docs.mend.io/platform/latest/the-applications-and-projects-views.md). If the column is not visible, make sure to add it via the Columns menu on the right.

   ![image-20260219-060240.png](https://docs.mend.io/__attachments/a_26d802559817c3bc0572a1223177c4703b3a9f8be7c4ca7805d86dff8fa3b1ef/image-20260219-060240.png?cb=d5c4376aedd55176bcaee7cb5e91ba8d)
2. Relevant information is also available via the [AI Security Dashboard](https://docs.mend.io/platform/latest/ai-security-dashboard.md) in the form of the **Vulnerable Agent Configurations** widget, which displays the number of vulnerable agent configurations out of the total number of agent configurations.

   Clicking the main number will take you to the Applications view.

   ![image-20260219-064047.png](https://docs.mend.io/__attachments/a_3959e76b0432175b2e4a0dac19e55d1c4cd284eec6f62e594d7a3ad18af23cde/image-20260219-064047.png?cb=cee92951293139a5fa253201a3295e3e)

## Risk Coverage

Agent configuration files are evaluated against a set of AI-specific security controls.  

|   **Risk**    |             **Category**             | **Severity** |                                **What It Detects**                                 |
|---------------|--------------------------------------|--------------|------------------------------------------------------------------------------------|
| **MAI-AC-01** | Prompt Injection                     | High         | Ignore instructions, role hijacking, reveal system prompt, conceal from user, etc. |
| **MAI-AC-02** | Command/Code Execution               | High         | Shell, curl/wget, sudo, rm -rf, eval/exec, subprocess, etc.                        |
| **MAI-AC-03** | Social Engineering / Approval Bypass | High         | Urge always approve, false trust, reassure user                                    |
| **MAI-AC-03** | Social Engineering                   | Medium       | Impersonate official skills / misleading branding                                  |
| **MAI-AC-04** | Permission Escalation                | High         | Blanket allow, bypass approval, auto-approve, wildcard tools                       |
| **MAI-AC-05** | File Exfiltration                    | Medium       | Read .env, SSH keys, credentials; send/upload data                                 |
| **MAI-AC-06** | Credential Access                    | High         | Eextract/harvest credentials, output env vars, embed in output                     |
| **MAI-AC-07** | Network Exfiltration                 | High         | Webhook sites, Discord/Telegram, paste sites, tunnels, send to URL                 |
| **MAI-AC-08** | Persistence                          | High         | Crontab, shell profiles, git hooks, startup/autostart                              |
| **MAI-AC-09** | Obfuscation                          | High         | Zero-width chars, homoglyphs, encoding, XOR, Base64 payloads                       |
| **MAI-AC-10** | Hardcoded Secrets                    | High         | AWS, Stripe, Google, GitHub, JWT, private keys, DB URLs                            |
| **MAI-AC-11** | Supply Chain                         | High         | Hidden file with executable code                                                   |
| **MAI-AC-12** | Resource Abuse                       | High         | Infinite loops, fork bomb, os.fork                                                 |

Each finding includes:

* Risk category

* Severity

* Affected file

* Code snippet (where applicable)

* Mitigation guidance

---
version: "Latest"
language: "en"
---
# AI Technologies Inventory

## Overview

A technology framework refers to any technology used by a piece of software. This can include a product, a category of products, a protocol, or any other indicator that helps us understand the software's usage (e.g., AI, LLM, RPC, payments).

An AI framework is essentially a group of AI technologies, listed as **High-Level Technology** in the Mend AI user interface. It includes tools, libraries, and methodologies for developing, deploying, and managing AI models. Examples include model frameworks (e.g., TensorFlow, PyTorch), AI agent orchestration tools (e.g., LangChain, LlamaIndex), and security frameworks that enforce governance and compliance (e.g., Guardrails AI, TruLens).

In Mend AI, framework identification detects and categorizes AI-related frameworks in enterprise codebases, helping security teams assess risk and enforce governance policies.

The data containing the related package evidence will be available on the **AI Technologies** inventorypage.

## Getting it done

To access your AI Technologies inventory, navigate to the AI section on the left-pane navigation menu and click **AI Technologies**.  
![image-20250629-150614.png](https://docs.mend.io/__attachments/a_cb810f7aeb34e01dcdb83a2577041e4c0988b5d3f87c7843ebd13dcf229d53c7/image-20250629-150614.png?cb=6efd10c94c89581e3e2ead389b648d7c)

This will take you to the AI Technologies inventory table, which contains the columns listed below.

### Table Columns

* **High-Level Component**denotes a high-level AI infrastructure technology that consists of a group of related AI elements, including libraries, tools, and environments used for model development and deployment.

* **Projects** in which the high-level technology was detected. By default, this column specifies the number of projects in which the technology was detected. Clicking the number will take you to the project list.

* **Category** of the high-level technology(e.g., Third-Party LLM Service, AI Agent, Open-Source LLM, etc.).

* **Exposure Level** is the level of risk associated with the AI technology, assessed by [Mend.io](http://mend.io/)'s research team. It considers factors like security vulnerabilities, compliance issues, and governance risks. Categories include Low, Medium, High, and Critical based on [Mend.io](http://mend.io/)'s evaluation.

* **Potential Threats Exposure** liststhe specific threats related to the AI technology, mapped from the OWASP Top 10 for LLM Applications. These may include prompt injection, model poisoning, insecure output handling, excessive agency, or training data extraction risks.

* **Related Libraries and Models** are components within the AI infrastructure that relate to the application, such as packages, models, and inference providers.

![image-20260106-105912.png](https://docs.mend.io/__attachments/a_aeb8850a02ffc0966c73ce4c2354141fec04c96b9f6a14f383e560397d3ebefe/image-20260106-105912.png?cb=5462e29e8ba3de4762e0777b11c14192)  
**Note:**

1. Click the **Columns** button at the right edge of the screen to add/remove columns.  
![image-20250321-104431.png](https://docs.mend.io/__attachments/a_14111b425a764284f1130baa791513c4324c5c34887e98c9788968bcc06ceea6/image-20250321-104431.png?cb=754b2b777db5d8b64cb0337c21301a30)

2. The columns are all **filterable**. For instance, you can use the filter box under the High-Level Technology column header to filter the results by the technology name.

3. Some column headers have tooltips (marked by ![image-20250311-081134.png](https://docs.mend.io/__attachments/a_b2eec90d55c48601d65b0e7e399b111ee569aeb5fa4c9e27a5bd38e7880ab24e/1c40b7bc-5a53-458e-8ba7-76887df4712d?cb=c22f05b176739f155835eec3adca3368) ) containing a comprehensive explanation about the column.

### Side-panel

Clicking any line in the table will spawn a side-panel containing an overview of the selected AI technology.

Example:  
![image-20250829-135745.png](https://docs.mend.io/__attachments/a_732b88e3e1aaf93a5cace451e127e367e93754dcb9d91483643d88e776c48f59/image-20250829-135745.png?cb=d5c0146983b8ab8faae3313d07bd17ce)

---
version: "Latest"
language: "en"
---
# AI Model Artifact Detection

## Overview

Mend AI detects various types of AI model artifacts.  
* To minimize noise and increase accuracy, Mend AI automatically filters out irrelevant file types (e.g., .txt, .tar, .zip) and employs smart content validation to handle ambiguous extensions such as .pkl, .npy, etc.

* Mend AI only detects files equal to or larger than 10MB in size.

## Testing Artifact Detection with Git LFS

To properly test the AI Model Artifact Detection capability, it is highly recommended to use Git LFS (Large File Storage), since model artifacts are typically larger than 10MB.

1. Clone a Hugging Face repository.

2. Run `git lfs`.

3. Verify the files are on your file system.

### Prerequisites

Before testing, ensure you have Git LFS installed. If not, install it following the [++Hugging Face requirements guide++](https://huggingface.co/docs/hub/en/repositories-getting-started#requirements).

### Testing Steps

1. **Clone a repository with model artifacts from Hugging Face:**

       git clone https://huggingface.co/[model-name]

   Example repositories you can use for testing:
   * `https://huggingface.co/bert-base-uncased`

   * `https://huggingface.co/gpt2`

2. **Pull the LFS files:**

       cd [repository-name]
       git lfs pull

3. **Verify the files are present on your filesystem:**

       ls -lh

   Look for files larger than 10MB (typically `.bin`, `.safetensors`, or `.ckpt` files). These should now show their actual size rather than being LFS pointer files.
4. **Run the Mend artifact scanner:**

   Now you can test the artifact detection capabilities against these actual model files.

### Common Issues

* **Issue:** Scanner doesn't detect artifacts

  * **Cause:** Git LFS files weren't pulled, only pointer files exist

  * **Solution:** Run `git lfs pull` to download the actual artifacts

* **Issue:** Files appear to be only a few KBs in size

  * **Cause:** These are LFS pointer files, not the actual artifacts

  * **Solution:** Ensure Git LFS is installed and run `git lfs pull`

## AI Model Artifact File Types

        "bin", "safetensors", "safetensorsc", "ggmlv3", "trt", "tdict", "safetens", "argosmodel", "pt",
        "v2", "pth", "onnx", "ckpt", "gguf", "guff", "wv", "model", "weight", "weights",
        "caffe", "caffemodel", "nemo", "pdmodel", "neuron", "skops", "pkl", "index", "npz", "npy",
        "pb", "pickle", "qweight", "tfrecord", "engine", "pbmm", "scorer", "tflite", "data", "binary",
        "llamafile", "dat", "mlmodel", "keras", "ggml", "safetensor", "tfbson", "tensors", "gguff", "mil",
        "torch", "safetensorsa", "savetensors", "savetensor", "h5", "h5ad", "pyth", "wandb",
        "onnx_data", "pdparams", "cleanrl_model", "qzeros", "safetesors",
        "mar", "joblib", "cbm", "mlpackage", "plan", "dlc", "ubj", "pmml"

---
version: "Latest"
language: "en"
---
# AI Security Dashboard

## Overview

The **AI Security Dashboard** provides security leaders and governance teams with a centralized view of unique AI risks across the organization.

It is designed to help identify critical vulnerabilities in AI components, streamline compliance with emerging AI regulations, and reduce exposure from AI implementations.

The dashboard supports a focused, three-part workflow:

1. **Assess** -- Get a single-view assessment of AI components and their associated risks.

2. **Prioritize** -- Identify the most vulnerable applications and projects for targeted remediation.

3. **Track** -- Monitor security improvements over time with measurable metrics.

## Switching to AI Security Dashboard

When you log in to the Mend AppSec Platform, the default view is the Security Dashboard, which provides an overview of your entire organization, including applications, projects, scans, and more.

To access the Value Dashboard, follow these steps:

1. Click on **Dashboards**.

2. Select **AI Security Dashboard**.

![image-20250811-144750.png](https://docs.mend.io/__attachments/a_bcb21d3562a86e8b298d71004526f5840217f81be329d31be307d448a6e250b8/image-20250811-144750.png?cb=61db7f5e39a367ea81e3294ff403baec)  
![image-20260101-104051.png](https://docs.mend.io/__attachments/a_9b55da00ce16526e30f948539b19a3eb8df3e784453380d1ce7ab9a69503e891/image-20260101-104051.png?cb=9af4e4dc489ae10d02dfbc00e3b3dd0b)

## Understanding AI Security Dashboard Widgets

### Access and Permissions

All users in the Mend Platform can access the AI Security Dashboard; however, the data displayed is permission-based and reflects only the information that a user is authorized to view.

* **Organization Admins** will see aggregated data across all applications and projectsthey are permitted to access.

* **Application Admins and Members** will have visibility into data limited to their assigned applications and projects.

This ensures that users only view data that aligns with their assigned responsibilities and access levels, maintaining security and data integrity across the organization.  
An active AI Premium/AI Core subscription is required to access risk data in the widgets.

### Overview

The Overview section provides the top organization indicators, including current state and trends for Applications, Projects, and Scans that contain AI-Driven technology.  
![image-20260101-105034.png](https://docs.mend.io/__attachments/a_258272ada8fe3d64050a83c33aebec0c1b5711d705d7aead3878a83314e584df/image-20260101-105034.png?cb=016a17060a7df34f240c246afb883301)

### AI Risk

The AI Risk section provides several widgets / tables:

* HuggingFace Malicious Models

* Vulnerable System Prompts

* Vulnerable Agent Configurations

* AI Model Vulnerabilities by Severity

* Components Visibility

![image-20260219-061659.png](https://docs.mend.io/__attachments/a_6a235887401c8111a9e904018ef6e35b017222b11bfe844cf2636f3f8fce0ba4/image-20260219-061659.png?cb=ea598527b3e913374c4bfbfcec20b322)

#### Hugging Face Malicious Models

Total number of models flagged by Hugging Face as potentially unsafe or malicious. You can click on the findings to view the affected projects.

#### Vulnerable System Prompts

Total number of detected system prompt weaknesses (out of the overall number of system prompts).

#### Vulnerable Agent Configurations

Displays number of vulnerable agent configurations out of total agent configurations.

#### AI Model Vulnerabilities by Severity

Shows the total number of AI models' security findings, broken down by severity. Click on a severity to view projects with the highest number of findings of that type.

#### Components Visibility

The Component Visibility table maps the number of projects and applications using this AI component, helping prioritize based on usage impact.  
![image-20250907-144446.png](https://docs.mend.io/__attachments/a_e4728ff90ec05c8efb851c8f862ec883c70f4d54fa23141156061165e6ee3ac7/image-20250907-144446.png?cb=fbdb26b9cdffab9567f04ab53f73fbbf)

### High-Risk Applications \& Projects by AI Security Posture

The top 10 AI-powered applications and projects with policy violations are listed in this table, sorted by number of violations in descending order. This view helps you track and focus on the applications/projects with the highest number of violations.  
**Note:** If all counts are zero, a random set of AI-powered projects will be shown instead.  
![image-20260101-105416.png](https://docs.mend.io/__attachments/a_46db1d565cdc198a08fd264033bda5f9ccfdcd2707b84004147741a52bf6cf0f/image-20260101-105416.png?cb=b8986e2a30515af2f3d676060740a185)

## Limitations \& Known Issues

* Clicking an AI technology item in the *Top 10* widget currently navigates to the **AI Models** table instead of the **AI Technologies** table.

* Number-based cards/widgets are currently unclickable.

* Some AI components currently do not have icons.

* The dashboard only accounts for data added after its launch on September 7th, 2025. Please rescan older projects, to make sure their data is accounted for in the dashboard.

---
version: "Latest"
language: "en"
---
# Analyze your results in the Mend AppSec Platform

## Overview

The process of effective triaging and analyzing security findings plays a pivotal role in enabling your organization to swiftly identify and prioritize potential threats, allowing you to respond promptly and effectively and minimize the impact of security incidents while safeguarding your assets.

A "one-stop-shop" for your **SCA** , **SAST,** and **IMAGE** scan findings, the web-based **Mend Platform** empowers your AppSec Managers and Security Champions in moderating your **Applications** ' security compliance in one portal*.*

## Use-cases for analyzing your Mend scan results

* **Monitor Application Security** : The **Mend Platform** offers real-time insights into the security status of all applications. Your AppSec Manager and Security Champion can quickly assess which **applications** have outstanding vulnerabilities and identify potential risks.

* **Follow Trends and Patterns** : By analyzing data on vulnerability trends and patterns in the **Mend Platform**, your AppSec Manager can identify common weaknesses across applications or specific development teams. This information can be used to implement targeted security actions.

* **Prioritize and Communicate Security Risks** : With the help of the **Mend Platform**, your Security Champion can identify high-risk vulnerabilities and prioritize their resolution based on criticality. They can effectively communicate these risks to your development team, highlighting the potential impact and advocating for timely remediation.

* **Drive Security Awareness** : By utilizing the **Mend Platform**, the Security Champion can identify recurring security weaknesses within your team's applications. They can use this information to tailor security awareness initiatives via targeted training sessions for your development team, addressing specific areas of improvement and reinforcing secure coding best practices.

## Reference

* [The Active Projects Only View](https://docs.mend.io/platform/latest/the-active-projects-only-view.md)
* [Search Findings in your Organization](https://docs.mend.io/platform/latest/search-findings-in-your-organization.md)
* [Review the Code Findings (SAST) within your Organization](https://docs.mend.io/platform/latest/review-the-code-findings-within-your-organization.md)
* [Review the Dependencies Findings (SCA) within your Organization](https://docs.mend.io/platform/latest/review-the-sca-findings-within-your-organization.md)
* [Review the Container Image Scan Findings within your Organization](https://docs.mend.io/platform/latest/review-container-scan-findings-organization.md)
* [Review the Infrastructure as Code Findings (IaC) within your organization](https://docs.mend.io/platform/latest/review-the-infrastructure-as-code-findings-iac-within-your-organization.md)
* [View the overall state of your Organization](https://docs.mend.io/platform/latest/view-the-overall-state-of-your-organization.md)
* [View the overall state of an Application](https://docs.mend.io/platform/latest/view-the-overall-state-of-an-application.md)
* [View the overall state of a Project](https://docs.mend.io/platform/latest/view-the-overall-state-of-a-project.md)
* [Reports in the Mend Platform](https://docs.mend.io/platform/latest/reports-in-the-mend-platform.md)
* [Prioritize Results based on Context](https://docs.mend.io/platform/latest/prioritize-results-based-on-context.md)
* [The Applications and Projects Views](https://docs.mend.io/platform/latest/the-applications-and-projects-views.md)
* [The Scans View](https://docs.mend.io/platform/latest/the-scans-view.md)

---
version: "Latest"
language: "en"
---
# Android Java

This article covers Android Java support and vulnerability detection for Mend SAST.

## Mend SAST-supported Android Java file types

| **File Type** |
|---------------|
| .java **\***  |
| .kt           |
| .ktm          |
| .kts          |

**\* Note:** These extensions are marked as 'Secondary' file extensions.

They will only be scanned if at least one file with any of the other 'Primary' file extensions is present to identify the language as the relevant language.

## Mend SAST-supported Android Java frameworks

| **Frameworks** |
|----------------|
| N/A            |

## Mend SAST-supported Android Java vulnerability types

The Android Java vulnerability types detected by SAST are provided below and are organized by CWE ID within each of their identified severities.

### Android Java high-severity vulnerability types

|---------|------------------------------|
| **CWE** | **Vulnerability Type**       |
| CWE-89  | External Data In SQL Queries |
| CWE-94  | Arbitrary Code Injection     |

### Android Java medium-severity vulnerability types

|---------|-----------------------------------------|
| **CWE** | **Vulnerability Type**                  |
| CWE-200 | Insecure Data Storage                   |
| CWE-200 | Shared Preferences Usage                |
| CWE-200 | Location Information                    |
| CWE-209 | Log Messages                            |
| CWE-244 | Heap Inspection                         |
| CWE-295 | Man-in-the-Middle Attack                |
| CWE-319 | Insufficient Transport Layer Protection |
| CWE-338 | Weak Pseudo-Random                      |
| CWE-676 | Miscellaneous Dangerous Functions       |
| CWE-749 | WebView Implementation                  |
| CWE-798 | Hardcoded Password/Credentials          |
| CWE-926 | Intents Usage                           |

### Android Java low-severity vulnerability types

|---------|---------------------------|
| **CWE** | **Vulnerability Type**    |
| CWE-16  | Application Configuration |
| CWE-326 | Weak Encryption Strength  |
| CWE-676 | External URL Access       |

---
version: "Latest"
language: "en"
---
# Apex

This article covers Apex support and vulnerability detection for Mend SAST.

## Mend SAST-supported Apex file types

| **File Types** |
|----------------|
| .apex          |
| .apexp         |
| .cls           |
| .page          |

## Mend SAST-supported Apex frameworks

| **Frameworks** |
|----------------|
| N/A            |

## Mend SAST-supported Apex vulnerability types

The Apex vulnerability types detected by SAST are provided below, organized by CWE ID within each of their identified severities.

### Apex high-severity vulnerability types

|---------|-----------------------------|
| **CWE** | **Vulnerability Type**      |
| CWE-89  | SQL Injection               |
| CWE-918 | Server-Side Request Forgery |

### Apex medium-severity vulnerability types

|---------|-------------------------------------|
| **CWE** | **Vulnerability Type**              |
| CWE-209 | Error Messages Information Exposure |
| CWE-244 | Heap Inspection                     |
| CWE-501 | Trust Boundary Violation            |
| CWE-798 | Hardcoded Password/Credentials      |

---
version: "Latest"
language: "en"
---
# ASP Classic/Visual Basic/VBScript

This article covers ASP Classic/Visual Basic/VBScript support and vulnerability detection for Mend SAST.

## Mend SAST-supported ASP Classic/Visual Basic/VBScript file types

| **File Type**  |
|----------------|
| .asp           |
| .bas           |
| .cls           |
| .inc **\***    |
| .master **\*** |
| .vb **\***     |
| .vbs           |
| .as            |

**\* Note:** These extensions are marked as 'Secondary' file extensions.

They will only be scanned if at least one file with any of the other 'Primary' file extensions is present to identify the language as the relevant language.

## Mend SAST-supported ASP Classic/Visual Basic/VBScript frameworks

| **Framework** |
|---------------|
| N/A           |

## Mend SAST-supported ASP Classic/Visual Basic/VBScript vulnerability types

The ASP Classic/Visual Basic/VBScript vulnerability types detected by SAST are provided below and are organized by CWE ID within each of their identified severities.

### ASP Classic/Visual Basic/VBScript high-severity vulnerability types

|---------|-----------------------------|
| **CWE** | **Vulnerability Type**      |
| CWE-22  | Path/Directory Traversal    |
| CWE-73  | File Manipulation           |
| CWE-78  | Command Injection           |
| CWE-79  | Cross-Site Scripting        |
| CWE-89  | SQL Injection               |
| CWE-94  | Code Injection              |
| CWE-94  | Server Pages Execution      |
| CWE-643 | XPath Injection             |
| CWE-918 | Server-Side Request Forgery |

### ASP Classic/Visual Basic/VBScript medium-severity vulnerability types

|---------|-----------------------------------|
| **CWE** | **Vulnerability Type**            |
| CWE-338 | Weak Pseudo-Random                |
| CWE-472 | Hidden HTML Input                 |
| CWE-676 | Miscellaneous Dangerous Functions |

### ASP Classic/Visual Basic/VBScript low-severity vulnerability types

|---------|-----------------------------|
| **CWE** | **Vulnerability Type**      |
| CWE-20  | Mail Relay                  |
| CWE-113 | HTTP Response Splitting     |
| CWE-113 | HTTP Header Injection       |
| CWE-117 | Log Forging                 |
| CWE-434 | File Upload                 |
| CWE-530 | Dangerous File Extensions   |
| CWE-601 | Unvalidated/Open Redirect   |
| CWE-941 | Arbitrary Server Connection |

---
version: "Latest"
language: "en"
---
# Assign a Project to an Application in the Mend AppSec Platform

## Overview

**Applications** organize **Projects** . Ideally, all **Projects** related to the same product application would be grouped together within the same **Application** . This article provides the details of assigning **Projects** to **Applications**.

## Getting it done

### Assign Projects to Applications in the Mend Platform

1. Log into the **Mend Platform**.

2. Click the settings gear in the top right corner of the page.

3. Clicking **Administration** to navigate to the **Administration** page.

![new_set_admin.png](https://docs.mend.io/__attachments/a_c6c6e8d15f42ed73c535fde70f5f8338143bb4c6d0d77f5e601cff833d076720/new_set_admin.png?cb=d8890d29f618a7d126cd97c94ce77350)

4. Click **Projects** in the left **Administration** list to navigate to the **Projects** management page.

5. Check the boxes next to the desired **Projects.**

6. Click the **Assign to Application** button in the top right corner of the **Projects** table.

![proj_to_app.png](https://docs.mend.io/__attachments/a_c114c5bcf823d8edd1759da9e3957e7ccad20fc718658cadedd73c7d35b57333/proj_to_app.png?cb=c7f22448ea73f48b5bcc88081e85beee)

4. Select an **Application** in the **Assign to Application** pop-up window.

   ![new_ass_to_app.png](https://docs.mend.io/__attachments/a_52cf6185831be8e48947159e9de9cf4a2e7672ae1ee760ab44a66992cf718688/new_ass_to_app.png?cb=f70173857f9d7fec3d07a27d6b76cdf8)
5. Click **OK**

   ![proj_app_ok.png](https://docs.mend.io/__attachments/a_1e5eeb87a1583015c89dc827e9e2c008ebef9188bd87f5a5fb812f967aa88847/proj_app_ok.png?cb=b5ba3f65d38ec41d1b3a69cad55b9120)

The **Application** associated with the **Project** will be updated in the **Projects** table, and a notification will appear in the bottom right corner of the window.  
![proj ass.png](https://docs.mend.io/__attachments/a_b9a3c782e92d52343402260e5c1d7e5cde6ec9d00f7f2740f6a20437c27ac938/proj%20ass.png?cb=949e7c6838d60dd2e47d0c709035a267)

---
version: "Latest"
language: "en"
---
# Authenticate your login for the Mend CLI

## Overview

You must log in to the Mend CLI once for each environment where it runs, which authenticates you to work in a single organization.

## Mend CLI login example

![image-20260306-132220.png](https://docs.mend.io/__attachments/a_79ae713e5a395952763fbadea48866ecfe9b1f766c013888b9e30189dc7de697/image-20260306-132220.png?cb=ec9ad6678cb93009f3bdf41ca79525d5)

## Getting it done

### Prerequisites before you log into the Mend CLI

* The following operating systems are supported by the Mend CLI:

  * **Linux** (Intel processors): Ubuntu, Debian, and other flavors which have glibc (GNU C library)

  * **Windows**: Windows 10/11 or Windows Server 2016 and higher

  * **MacOS**: Docker for Mac is installed.

    * For Docker Desktop users: Enable the default Docker socket in the [Advanced settings](https://docs.docker.com/desktop/settings/mac/#advanced).

* Have an active Mend license.

* Obtain your service user key (*recommended*) or your user key:

  * **Service user key** : Mend Platform Application → **Administration** → **Users** → locate service user → **Copy Token**

  * **Your user key** : Mend Platform Application → **My Profile** → **User Keys**.

### Log in to the Mend CLI via the interactive terminal

You can log in to the Mend CLI interactively by entering `mend auth login` in your terminal:  
![MendCLI-Login.gif](https://docs.mend.io/__attachments/a_37de4e07dc36bc5147220dd5d3a34db95cc4cb6e05e97273ec61eb51de99e874/MendCLI-Login.gif?cb=ba18400394a84b90ae5aa2d9af47ccbe)

### Log in to the Mend CLI via environment variables

You can log in to the Mend CLI by defining environment variables.  
![:light_bulb_on:](https://docs.mend.io/__attachments/a_421ca70b6fef34ea37ab3303b88dbd585aa298da1b4522dede6b97f8f3841ea7/atlassian-light_bulb_on?cb=485b9fcaee6e0d0eefa559cab514727e)  
**Tip** : As a common best practice, we strongly recommend creating and using a service user when configuring the Mend CLI authentication through environment variables in your CI/CD pipelines. Read more on service users in our [Manage service users in the Mend Platform](https://docs.mend.io/platform/latest/manage-service-users-in-the-mend-platform.md) documentation.

To define the variables in your environment, you can:

* Set environment variables prior to the Mend CLI run to ***persist between sessions*** **:**

  * In MacOS and Linux, use a shell startup script

  * In Windows, use the `setx` command.

    * `setx VARIABLE "MYVALUE"`

* Set environment variables prior to the Mend CLI run, for the ***current session only***:

  * In MacOS and Linux, use the `export` command.

    * `export VARIABLE=value`

  * In Windows, use the `set` command.

    * `set VARIABLE=value`

**Note:** If you receive this error:` Executing <mend dependencies> and the corresponding help command requires to authenticate first, either through environment variables or by executing mend auth login`.

Remove any `MEND_SAST_*`variables from your environment and rerun the SCA scan*.*

For more information on `MEND_SAST_*`variables, refer to our [++CLI Parameters++](https://docs.mend.io/platform/latest/configure-the-mend-cli-for-sast.md) documentation.

### Set up a proxy and automatic updates for the Mend CLI

You can set up a proxy as well as toggle automatic updates for the Mend CLI for all scan types using the `mend config` command. Read through our **mend config parameters section** within this documentation to learn more.  
**Note:**

* When automatic updates are disabled, the Mend CLI will still check for updates and notify you that a new version is available to download.

* When running a Mend CLI scan with proxy enabled, the terminal output and logs will notify you that a proxy is being used after executing a command: `Running with proxy - https:/myproxy.prx`.

#### Proxy Setup for Restricted Environments

* Step 1: Set temporary environment variable

  Example: `export HTTP_PROXY=https://myproxy.example.com:8080`

* Step 2: Configure CLI with proxy

  `mend config`

  * Answer prompts to save proxy permanently

* Step 3 (Optional): Remove temporary variable

  `unset HTTP_PROXY`

**Note:** The Mend CLI respects the `HTTPS_PROXY`, `HTTP_PROXY` and `NO_PROXY` enviornment variables.

### Verify the connection from the Mend CLI to the Mend Server

You can verify the connection from the Mend CLI on your environment to the Mend Server using the `mend connectivity` command. The command checks if all external URL resources needed during the scan are accessible with the current network/proxy settings and reports an error for each URL where the access attempt fails.

To check the connectivity, you should:

* Use the `mend connectivity --mend-url="MEND_URL"` command and insert the "Mend_URL" value for the connection test.

* MEND_URL represents the Mend environment URL. The supported values are available in [Mend CLI - mend auth login parameters](https://docs.mend.io/platform/latest/authenticate-your-login-for-the-mend-cli#AuthenticateyourloginfortheMendCLI-MendCLI-mendauthloginparameters).

  ![image-20250118-145104.png](https://docs.mend.io/__attachments/a_d337448449adee235eba53039bd6d2e5dd255b279f440ed1c16050c28a387875/image-20250118-145104.png?cb=d1ef7f9f026ce7e3d7880d079bde7733)

|                                                 **Endpoint**                                                 |                      **Required For**                       |              **Consumer**               |
|--------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------|-----------------------------------------|
| Mend instance (e.g: [saas.mend.io](http://saas.mend.io/)/saas-eu.mend.io)                                    | Communicating with [Mend.io](http://mend.io/) instance APIs | All [Mend.io](http://mend.io/) products |
| Mend Instance API (e.g: [api-saas.mend.io/api-saas-eu.mend.io](http://api-saas.mend.io/api-saas-eu.mend.io)) | Communicating with [Mend.io](http://mend.io/) instance APIs | All [Mend.io](http://mend.io/) products |
| [https://downloads.mend.io](https://downloads.mend.io/)                                                      | Downloading scanner executables                             | All [Mend.io](http://mend.io/) products |
| [https://mend.io](https://mend.io/)                                                                          | Proxy validation                                            | All [Mend.io](http://mend.io/) products |
| [https://auth.docker.io](https://auth.docker.io/)                                                            | Downloading Docker Hub images                               | Mend Container                          |
| [https://index.docker.io](https://index.docker.io/)                                                          | Downloading Docker Hub images                               | Mend Container                          |
| [https://production.cloudflare.docker.com](https://production.cloudflare.docker.com/)                        | Downloading Docker Hub images                               | Mend Container                          |

## Reference

### Mend CLI - mend auth login parameters

![:light_bulb_on:](https://docs.mend.io/__attachments/a_421ca70b6fef34ea37ab3303b88dbd585aa298da1b4522dede6b97f8f3841ea7/atlassian-light_bulb_on?cb=485b9fcaee6e0d0eefa559cab514727e)  
**Note:** For inline help, use `mend auth login -h` or `mend auth login --help`.  

|                                       **Parameter**                                        |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
|--------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Command Line:** `Select Mend environment` **Environment Variable:** `MEND_URL`           | Select the Mend environment URL of your shared instance. The supported values are: * `https://saas.mend.io` * `https://saas-eu.mend.io` * `https://app.mend.io` * `https://saas-il.mend.io` * `https://saas.whitesourcesoftware.com` * `https://saas-eu.whitesourcesoftware.com` * `https://app-eu.whitesourcesoftware.com` * `https://app.whitesourcesoftware.com`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **Command Line** : `User Email` **Environment Variable:** `MEND_EMAIL`                     | Input your user email that has access to the Mend organization from the Mend Platform Application → **My Profile** → **Identity** page.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **Command Line:** `User Key` **Environment Variable:** `MEND_USER_KEY`                     | Input your service user key (*recommended*) or your personal user key that has access to the Mend organization: * **Service user key** : Mend Platform Application → **Administration** → **Users** → locate service user → **Copy Token** * **Your user key** : Mend Platform Application → **My Profile** → **User Keys**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Command Line:** `Select Mend organization` **Environment Variable:** `MEND_ORGANIZATION` | **Command Line:** Select the Mend organization that you want to authenticate to from the provided organization list. **Environment Variable:** Provide your organization UUID. This can be found within the Mend Platform Application via settings(:mp_cogicon:) → **Administration** →**General** → **Organization UUID**: ![image-20230829-175911.png](https://docs.mend.io/__attachments/a_5ef7845bc4fc8334bc9ab9541fbd85b2d6fcd77bc7f07fa71682c36ef51d3c06/image-20230829-175911.png?cb=5d652fae80b1180b9bb3973ba8e19d2a) ![:light_bulb_on:](https://docs.mend.io/__attachments/a_421ca70b6fef34ea37ab3303b88dbd585aa298da1b4522dede6b97f8f3841ea7/atlassian-light_bulb_on?cb=485b9fcaee6e0d0eefa559cab514727e) **Tip:** You can also access your organization's UUID via Mend's API 3.0 login call (`baseUrl/api/v3.0/login`) and sending the username and userKey to receive your JWT token ([++learn more++](https://api-docs.mend.io/platform/3.0/access-management/login)), then use the JWT to call `baseUrl/api/v3.0/login/accessToken` to retrieve the `uuid` ([++learn more++](https://api-docs.mend.io/platform/3.0/access-management/refreshaccesstoken)). |

### Mend CLI - mend config parameters

|                                                          **Parameter**                                                           |                                                                                                                                                                                                                       **Description**                                                                                                                                                                                                                        |
|----------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Command Line:** `[Updates] Enable automatic updates? (Y/n, current: )`                                                         | **Default Value:** `Y (Yes)`: **Automatic Updates enabled**. Toggle automatic updates for the Mend CLI: * `Y`: Yes. Enable automatic updates for the Mend CLI. * `n`: No. Disable automatic updates for the Mend CLI. * `current`: Your current, active configuration.                                                                                                                                                                                       |
| **Command Line:** `[Proxy] Change proxy settings? (y/N/reset, current: )`                                                        | Whether to start the set up process for configuring a proxy: * `y`: Yes. Start the proxy setup process. * `N`: No. Do not start the proxy setup process. The `mend config` command will exit with a `Configuration completed` message. * `reset`: Remove your current proxy setup. This will set the proxy settings back to the default value, `None`. * `current`: **Default Value:** `None` **(No proxy configured)**. Your current, active configuration. |
| **Command Line:** `[Proxy] URL (current: )` **Environment Variable (All scan types)** : `HTTP_PROXY`                             | Enter the URL of your proxy. * `current`: **Default Value:** `None` **(No proxy URL configured)**. Your current, active configuration.                                                                                                                                                                                                                                                                                                                       |
| **Command Line:** `[Proxy] Configure proxy authentication? (y/N)`                                                                | Whether to start the set up process of configuration proxy credentials: * `y`: Yes. Start the proxy credential setup process. * `N`: No. Do not start the proxy credential setup process.                                                                                                                                                                                                                                                                    |
| **Command Line:** `[Proxy authentication] Username (current: )` **Environment Variable (All scan types):** `HTTP_PROXY_USERNAME` | Enter the username of your proxy authentication. * `current`: **Default Value:** `None` **(No proxy username configured)**. Your current, active configuration.                                                                                                                                                                                                                                                                                              |
| **Command Line:** `[Proxy authentication] Password (current: )` **Environment Variable (All scan types):** `HTTP_PROXY_PASSWORD` | Enter the password of your proxy authentication. * `current`: **Default Value:** `None` **(No proxy password configured)**. Your current, active configuration.                                                                                                                                                                                                                                                                                              |

---
version: "Latest"
language: "en"
---
# Automate your Workflows in the Mend AppSec Platform

## Overview

The Mend Platform enables you to enforce workflow policies automatically throughout your development teams' software development life cycle.

Workflows define a set of rules that reflect how an organization can handle specific conditions that are detected in the code used by its software.

From defining and enforcing security policies to expediting manual processes, Mend's Automation Workflow module enhances operational efficiency and bolsters overall application security.

## Getting it done

* [Create an Automation Workflow in the Mend AppSec Platform](https://docs.mend.io/platform/latest/create-an-automation-workflow-in-the-mend-platform.md)
* [Edit an Automation Workflow in the Mend AppSec Platform](https://docs.mend.io/platform/latest/edit-an-automation-workflow-in-the-mend-platform.md)
* [Disable an Automation Workflow in the Mend AppSec Platform](https://docs.mend.io/platform/latest/disable-an-automation-workflow.md)
* [Delete an Automation Workflow in the Mend AppSec Platform](https://docs.mend.io/platform/latest/delete-an-automation-workflow-in-the-mend-platform.md)
[Configure Policy Violations with Automation Workflows](https://docs.mend.io/platform/latest/configure-policy-violations-with-workflows.md)
* [Workflow Configuration Parameters in the Mend AppSec Platform](https://docs.mend.io/platform/latest/workflow-configuration-parameters.md)

## Reference

### Where is the Automation Workflows page in the Mend Platform?

The **Workflows** page is found in the top menu bar in the Mend Platform:  
![image-20240910-210753.png](https://docs.mend.io/__attachments/a_f3d69c49497975c3789fcbd8433362b4f1aab887cf52f9f4c5708cd185273af0/image-20240910-210753.png?cb=ae520ab6f383ce80d58028d88bddb9c5)

---
version: "Latest"
language: "en"
---
# Automatic issue update with Mend for Jira (Data Center)

## Overview

With the Mend for Jira Data Center plugin, you can create issues in your Jira Data Center via the Mend AppSec Platform and also automate the [Jira issue creation](https://docs.mend.io/platform/latest/mend-jira-plugin-automated-issue-creation.md) using workflows. To complement this, existing issues (whether created manually or automatically) that are **updated** in your Jira are automatically updated in the Mend Platform as well, ensuring seamless synchronization between Jira and the Mend AppSec Platform and **containing comprehensive details** such as status, link, reporter, and timestamps, for robust issue tracking.

### Requirements

* Plugin version 25.1.1 or above is required for this feature.

### Functional Specifications

* Updates are unidirectional, from Jira to the Mend AppSec Platform.

* Updates to either the **Status** or **Ticket #** in Jira will be reflected in the Mend Platform.

* The **Reporter** field will never get updated, as it represents the reporter who triggered the issue creation on the Mend Platform.

## Jira issue status in the Mend Platform

The information about the Jira issue is available in the **Issue Tracking Details** section on the finding's **Overview** tab:  
![image-20250127-133852.png](https://docs.mend.io/__attachments/a_91708b08222bde1b2f3ec17f4e560857e559a73f6c85a5b1029489067974a682/image-20250127-133852.png?cb=5b34244a989ce61bdb32daf2320ac6a3)

This information is also available in a tooltip that pops-up while hovering over the finding's status in the Findings table:  
![image-20250127-133902.png](https://docs.mend.io/__attachments/a_edf661b0f59a9c3e0c1832c86f3ca7068507d4f9c69dda5b46c9172b9414cb25/image-20250127-133902.png?cb=be0843024fe2771b76be39c12600f86a)

---
version: "Latest"
language: "en"
---
# Best Practices and Troubleshooting

## Best Practices

### Campaign Configuration

1. **Start with Basic Strategies:** Begin with "basic" and "jailbreak" strategies for comprehensive baseline coverage.

2. **Select Relevant Probes:** Choose probe types that match your application's risk profile.

3. **Provide Detailed Context:** Include comprehensive application purpose descriptions for more accurate testing.

4. **Iterative Testing:** Run multiple campaigns as you implement mitigations.

### Results Analysis

1. **Prioritize by Severity:** Address Critical and High severity vulnerabilities first.

2. **Review Failed Tests:** Examine actual attack conversations to understand exploitation techniques.

3. **Track Progress:** Compare campaigns over time to measure security improvements.

4. **Document Mitigations:** Record what defenses were implemented for each vulnerability.

### Security Posture Management

1. **Regular Testing:** Schedule periodic adversary campaigns.

2. **Comprehensive Coverage:** Test all probe types relevant to your use case.

3. **Defense Validation:** Re-run campaigns after implementing security controls.

4. **Trend Analysis:** Monitor your pass rate and vulnerability counts over time.

### Technical Architecture Notes

#### Probe Types

Probes are modular test components that can be:

* Combined with multiple strategies

* Executed in parallel

* Customized with application-specific context

#### Strategy Execution

Strategies modify probe prompts through:

* Direct transformation (basic)

* Obfuscation techniques (encoding)

* Multi-turn conversations (advanced)

* Systematic search (tree-based)

## Troubleshooting

### Common Issues

* **Campaign Fails to Start:**

  * Verify target credentials are correct.

  * Check API endpoint connectivity.

  * Ensure deployment name matches Azure configuration.

* **Low Pass Rates:**

  * Review application purpose and system prompts.

  * Implement additional input validation.

  * Add content filtering layers.

  * Consider RBAC controls.

* **Inconsistent Results:**

  * Model responses may vary between runs.

  * Temperature and sampling settings affect consistency.

  * Run multiple campaigns for statistical significance.

---
version: "Latest"
language: "en"
---
# Beta Version Disclaimer

For customers downloading a beta version, please notice the following important disclaimer:  
By downloading a beta version you acknowledge that it is being provided on an "as-is" basis and may not be at the level of performance of a final, generally available product offering. Mend will have no liability for damages arising out of or in connection with the beta version. Mend shall have no obligation to perform any fixes to the beta version and may immediately and without notice change or remove the beta version or any part thereof for any reason.

For questions or concerns, please refer to your Mend contact point.

---
version: "Latest"
language: "en"
---
# C/C++ Gen 1

In this article, we cover C/C++ support and vulnerability detection for Mend SAST.

## Mend SAST-supported C/C++ file types

| **File Type** |
|---------------|
| .c            |
| .cc           |
| .cpp          |
| .h            |

## Mend SAST-supported C/C++ frameworks

| **Framework** |
|---------------|
| IBM DB2       |

## Mend SAST-supported C/C++ vulnerability types

The C/C++ vulnerability types detected by SAST are provided below and are organized by CWE ID within each of their identified severities.

### C/C++ high-severity vulnerability types

|---------|----------------------------|
| **CWE** | **Vulnerability Type**     |
| CWE-22  | Path/Directory Traversal   |
| CWE-78  | Command Injection          |
| CWE-89  | SQL Injection              |
| CWE-121 | Buffer Overflow            |
| CWE-134 | Uncontrolled Format String |
| CWE-190 | Integer Overflow           |
| CWE-415 | Double Free                |
| CWE-416 | Use After Free             |
| CWE-787 | Out of Buffer Bounds Write |

### C/C++ medium-severity vulnerability types

|---------|-----------------------------------|
| **CWE** | **Vulnerability Type**            |
| CWE-90  | LDAP Injection                    |
| CWE-125 | Out of Buffer Bounds Read         |
| CWE-191 | Integer Underflow                 |
| CWE-244 | Heap Inspection                   |
| CWE-367 | Time of Check Time of Use         |
| CWE-676 | Miscellaneous Dangerous Functions |

### C/C++ low-severity vulnerability types

|---------|--------------------------------------|
| **CWE** | **Vulnerability Type**               |
| CWE-114 | Arbitrary Library Injection          |
| CWE-242 | Use of Inherently Dangerous Function |
| CWE-369 | Divide By Zero                       |
| CWE-789 | Uncontrolled Memory Allocation       |

---
version: "Latest"
language: "en"
---
# C/C++ Gen 2

**Note:** [Gen 1](https://docs.mend.io/platform/latest/c-c-gen-1.md) is the default C/C++ detection engine for existing customers. Please reach out to your Customer Success Manager at Mend.io to upgrade to Gen 2.

## Mend SAST-supported C/C++ file types

| **Source Files** | **Header Files** |
|------------------|------------------|
| .c               | .h               |
| .cc              | .hh              |
| .cpp             | .hxx             |
| .cxx             | .hpp             |

## Mend SAST-supported C/C++ frameworks

|          Framework / Ecosystem / Domain          |
|--------------------------------------------------|
| LLVM / MinGW / C++ toolchain                     |
| C standard library (glibc / musl)                |
| GLib / GObject / GNOME                           |
| Apache Portable Runtime (APR)                    |
| Asynchronous I/O / Event Loop (libuv / libevent) |
| SQLite                                           |
| ODBC / unixODBC                                  |
| MySQL                                            |
| PostgreSQL                                       |
| MongoDB                                          |
| BSON                                             |
| Talloc                                           |
| cURL / libcurl                                   |
| OpenSSL / TLS / Cryptography                     |
| Redis                                            |
| Memory Allocation (mimalloc)                     |
| JSON (jansson)                                   |
| Protocol Buffers (protobuf-c)                    |
| MessagePack (msgpack-c)                          |
| Linux System APIs                                |
| Compression / Archiving (zlib / libarchive)      |
| C++ Formatting \& Logging (fmtlib / spdlog)      |
| Boost C++ Libraries                              |
| Qt Framework                                     |
| Scripting / Embedding (Lua / CPython / Duktape)  |
| XML Processing (libxml2 / Xerces)                |
| Cassandra                                        |
| OpenLDAP                                         |
| SSH / Secure Shell (libssh / libssh2)            |
| RabbitMQ / AMQP                                  |
| AWS SDK for C / C++                              |
| Azure SDK (C / C++)                              |
| MQTT (Paho)                                      |
| HTTP / Web (httplib)                             |

## Mend SAST-supported C/C++ vulnerability types

The C/C++ vulnerability types detected by SAST are provided below and are organized by CWE ID within each of their identified severities.

### C/C++ high-severity vulnerability types

|---------|------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **CWE** | **Vulnerability Type**             | **Low Probability Impact**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| CWE-22  | Path/Directory Traversal           | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                                                                                                                                                                                                                                                                           |
| CWE-78  | Command Injection                  | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                                                                                                                                                                                                                                                                           |
| CWE-89  | SQL Injection                      | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                                                                                                                                                                                                                                                                           |
| CWE-94  | Code Injection                     | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                                                                                                                                                                                                                                                                           |
| CWE-121 | Buffer Overflow                    | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) * Skipped Taint Sanitizers: No heuristical sanitizier for comparisons (\<,\>,\<=..) * Additional Taint Sinks: Buffer lengths in the method lead to an overflow (neither's lengths are user controlled, no data flow, no trace) Allocating buffer with negtive size Reading from a socket to an insufficient length buffer |
| CWE-134 | Uncontrolled Format String         | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                                                                                                                                                                                                                                                                           |
| CWE-190 | Integer Overflow                   | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) * Skipped Taint Sanitizers: No heuristical sanitizier for comparisons (\<,\>,\<=..)                                                                                                                                                                                                                                       |
| CWE-415 | Double Free                        | * Additional Taint Sources: Source is not user controlled                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| CWE-416 | Use After Free                     | * Additional Taint Sources: Source is not user controlled                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| CWE-787 | Out of Buffer Bounds Write         | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) * Skipped Taint Sanitizers: Using resolved numbers * Additional Taint Sinks: Mismatched with resolved buffer sizes and indexes                                                                                                                                                                                            |
| CWE-824 | Access of Uninitialized Pointer    | * ONLY detected when Low Probability Findings are enabled                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| CWE-918 | Server Side Request Forgery (SSRF) | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                                                                                                                                                                                                                                                                           |
| CWE-943 | No-SQL Injection                   | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                                                                                                                                                                                                                                                                           |

### C/C++ medium-severity vulnerability types

| **CWE** |       **Vulnerability Type**        |                                                                                                                      **Low Probability Impact**                                                                                                                       |
|---------|-------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| CWE-125 | Out of Buffer Bounds Read           | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                                     |
| CWE-191 | Integer Underflow                   | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) * Skipped Taint Sanitizers: No heuristical sanitizier for comparisons (\<,\>,\<=..) |
| CWE-457 | Use of Uninitialized Variable       | * ONLY detected when Low Probability Findings are enabled                                                                                                                                                                                                             |
| CWE-606 | Unchecked Input for Loop Condition  | * UNAFFECTED                                                                                                                                                                                                                                                          |
| CWE-611 | XML External Entity (XXE) Injection | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                                     |
| CWE-676 | Miscellaneous Dangerous Functions   | * ONLY detected when Low Probability Findings are enabled                                                                                                                                                                                                             |
| CWE-798 | Hardcoded Password/Credentials      | * Additional Taint Sinks: Assignments of hard-coded strings to variables/attributes with special names like password                                                                                                                                                  |

### C/C++ low-severity vulnerability types

| **CWE** |        **Vulnerability Type**        |                                                                                                                                                 **Low Probability Impact**                                                                                                                                                 |
|---------|--------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| CWE-242 | Use of Inherently Dangerous Function | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                                                                                          |
| CWE-369 | Divide By Zero                       | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) * Skipped Taint Sanitizers: No sanitizer for division by zero * Additional Taint Sinks: Denominator is resolved to numberical value zero |
| CWE-476 | NULL Pointer Dereference             | * UNAFFECTED                                                                                                                                                                                                                                                                                                               |
| CWE-789 | Uncontrolled Memory Allocation       | * UNAFFECTED                                                                                                                                                                                                                                                                                                               |

**Note:** In comparison to [Gen 1](https://docs.mend.io/platform/latest/c-c-gen-1.md), you may notice that some CWEs are not supported. This is not a regression but an intentional change. In detail, the following adjustments were made:

* CWE-90: LDAP Injection: Intentionally dropped, because LDAP Injection is not relevant for C/C++

* CWE-114: Arbitrary Library Injection: This CWE is now covered under CWE-94: Code Injection

* CWE-244: Heap Inspection: Intentionally dropped, because Heap Inspection is very uncommon and requires the application server to be compromised for it to be exploitable. Static analysis alone can't determine if the vulnerability is a TP, so a lot of noise is generated.

* CWE-367: Time of Check Time of Use: This CWE is now covered under CWE-22

---
version: "Latest"
language: "en"
---
# C/C++

**Note:**

* Gen 1 is the default detection engine for existing customers.

* Configure the desired detection engine generation using a CLI parameter or environment variable as detailed [here](https://docs.mend.io/platform/latest/configure-the-mend-cli-for-sast.md#SAST-Scan-Parameters).

Supported file types, frameworks and CWEs:  
* [C/C++ Gen 1](https://docs.mend.io/platform/latest/c-c-gen-1.md)
* [C/C++ Gen 2](https://docs.mend.io/platform/latest/c-c-gen-2.md)

## Introduction to C/C++ Security: Why It Matters and How Mend SAST Helps

C and C++ are foundational programming languages that power a vast array of modern software---from embedded systems and automotive applications to high-performance computing and critical infrastructure. Their flexibility and performance make them the language of choice for systems where efficiency and control are paramount.

However, this power comes with complexity. C/C++ code is notoriously difficult to analyze for security vulnerabilities due to manual memory management, pointer arithmetic, and the lack of built-in safety features. As a result, C/C++ applications are frequent targets for security exploits, and vulnerabilities in these languages can have severe, far-reaching consequences.

Given the prevalence and risk profile of C/C++, it's essential for organizations to have robust tools that can:

* Accurately detect vulnerabilities in C/C++ codebases, including those specific to embedded and automotive domains.

* Provide actionable remediation suggestions to help developers fix issues quickly and efficiently.

* Scale to large codebases (up to 10 million lines of code) and deliver results rapidly, supporting modern development workflows.

## How Mend SAST Helps

* **Coverage:** [++Mend.io++](http://mend.io/)'s new generation C/C++ detection engine (Gen 2) offers significantly broader coverage of Common Weakness Enumerations (CWEs) and frameworks, including glibc, STL, Boost, QT, FreeRTOS, libcurl, libuv, and Mongoose. This ensures that your scans are both comprehensive and relevant to real-world C/C++ projects.

* **High Precision:** Mend SAST is designed to minimize noise and maximize accuracy, providing high-precision memory analysis and reducing false positives.

* **Memory Analysis:** The most relevant CWEs for C/C++ are related to memory corruption (Buffer Overflows/Underflows, Use after Free etc.). Mend SAST can precisely track these situations and report findings whenever such a dangerous flow can be triggered from the outside.

* **Scalability:** The engine is optimized for speed and scale, enabling scans of very large codebases with results delivered in hours, not days.

* **Developer-Centric Workflow:** Remediation suggestions are integrated directly into developer workflows---whether in code repositories, via CLI, or through the Mend AppSec Platform. Developers can review, accept, or provide feedback on suggestions, and even auto-create pull requests for fixes. Essentially, developers spend less time fixing security findings and more time building features. [++Mend.io++](http://mend.io/)'s remediation suggestions are tailored to C/C++, reducing the learning curve and accelerating secure development.

* **Security Champion Enablement:** Security teams and engineering managers can monitor remediation adoption, analyze impact, and generate tickets for unresolved issues, ensuring that security improvements are both measurable and actionable.

---
version: "Latest"
language: "en"
---
# C#

This article covers C# support and vulnerability detection for Mend SAST.

## Mend SAST-supported C# file types

| **File Type**  |
|----------------|
| .aspx          |
| .ascx **\***   |
| .cs            |
| .cshtml **\*** |
| .razor         |

**\* Note:** These extensions are marked as 'Secondary' file extensions.

They will only be scanned if at least one file with any of the other 'Primary' file extensions is present to identify the language as the relevant language.

## Mend SAST-supported C# frameworks

|    **Framework**     |
|----------------------|
| ASP.NET Core         |
| ASP.NET MVC          |
| ASP.NET Web Forms    |
| Azure Service Bus    |
| Azure Service Fabric |
| C# Web Services      |
| NHibernate           |
| Razor                |

## Mend SAST-supported C# vulnerability types

The C# vulnerability types detected by SAST are provided below and are organized by CWE ID within each of their identified severities.

### C# high-severity vulnerability types

|---------|-----------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **CWE** | **Vulnerability Type**            | **Low Probability Impact**                                                                                                                                                                                                                          |
| CWE-22  | Path/Directory Traversal          | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                   |
| CWE-78  | Command Injection                 | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                   |
| CWE-79  | Cross-Site Scripting              | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) * Additional Taint Sinks: Disabling standard CSRF implementations |
| CWE-89  | SQL Injection                     | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                   |
| CWE-94  | Code Injection                    | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                   |
| CWE-502 | Deserialization of Untrusted Data | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                   |
| CWE-643 | XPath Injection                   | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                   |
| CWE-918 | Server-Side Request Forgery       | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access)                                                                   |

### C# medium-severity vulnerability types

| **CWE**  |         **Vulnerability Type**          |                                                                            **Low Probability Impact**                                                                             |
|----------|-----------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| CWE-90   | LDAP Injection                          | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) |
| CWE-209  | Error Messages Information Exposure     | * UNAFFECTED                                                                                                                                                                      |
| CWE-319  | Insufficient Transport Layer Protection | * UNAFFECTED                                                                                                                                                                      |
| CWE-338  | Weak Pseudo-Random                      | * UNAFFECTED                                                                                                                                                                      |
| CWE-400  | Sleep Denial of Service                 | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) |
| CWE-501  | Trust Boundary Violation                | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) |
| CWE-611  | XML External Entity (XXE) Injection     | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) |
| CWE-676  | Miscellaneous Dangerous Functions       | * UNAFFECTED                                                                                                                                                                      |
| CWE-798  | Hardcoded Password/Credentials          | * Additional Taint Sinks: Assignments of hard-coded strings to variables/attributes with special names like password                                                              |
| CWE-1336 | Template Injection                      | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) |

### C# Low-severity vulnerability types

|----------|---------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **CWE**  | **Vulnerability Type**          | **Low Probability Impact**                                                                                                                                                        |
| CWE-20   | Mail Relay                      | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) |
| CWE-117  | Log Forging                     | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) |
| CWE-326  | Weak Encryption Strength        | * UNAFFECTED                                                                                                                                                                      |
| CWE-601  | Unvalidated/Open Redirect       | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) |
| CWE-614  | Sensitive Cookie Without Secure | * UNAFFECTED                                                                                                                                                                      |
| CWE-916  | Weak Hash Strength              | * UNAFFECTED                                                                                                                                                                      |
| CWE-941  | Arbitrary Server Connection     | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) |
| CWE-1004 | Cookie Without 'HttpOnly' Flag  | * UNAFFECTED                                                                                                                                                                      |
| CWE-1333 | Regex Denial of Service (ReDoS) | * Additional Taint Sources: Content from files and streams, databases, environment (command line calls, main method arguments, environment variables, configurations, url access) |

---
version: "Latest"
language: "en"
---
# CAPEC CWE Coverage

## Overview

**Common Attack Pattern Enumeration and Classification** **(CAPEC)** provides a publicly available catalog that helps users understand how adversaries exploit weaknesses in applications.

It offers a comprehensive framework for identifying, classifying, and describing common attack patterns, enabling security teams to better anticipate and defend against potential threats.

This article organizes **Common Weakness Enumerations (CWEs)** relevant to **CAPEC**.

Each row in the table below outlines a specific compliance standard, categorized by the following columns:

1. **Compliance Standard:** The specific category of the standard to which the CWE is mapped.

2. **Languages:** Supported programming languages.

3. **CWE-ID:** The relevant CWE for this standard, along with a short description.

## CAPEC CWE Coverage

|                               **Compliance Standard**                                |                                                                                                                                                                                                                                                                                  **CWE-ID**                                                                                                                                                                                                                                                                                   |
|--------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| CAPEC-37: Retrieve Embedded Sensitive Data                                           | * CWE-256: Plaintext Storage of a Password                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| CAPEC-100: Overflow Buffers                                                          | * CWE-121: Stack-based Buffer Overflow                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| CAPEC-102: Session side jacking                                                      | * CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| CAPEC-123: Buffer Manipulation                                                       | * CWE-787: Out-of-bounds Write                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| CAPEC-126: Path Traversal                                                            | * CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| CAPEC-134: Email Injection                                                           | * CWE-20: Improper Input Validation * CWE-941: Incorrectly Specified Destination in a Communication Channel                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| CAPEC-135: Format String Injection                                                   | * CWE-134: Use of Externally-Controlled Format String                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| CAPEC-136: LDAP Injection                                                            | * CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| CAPEC-159: Redirect Access to Libraries                                              | * CWE-114: Process Control                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| CAPEC-165: File Manipulation                                                         | * CWE-73: External Control of File Name or Path                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| CAPEC-194: Fake the Source of Data                                                   | * CWE-601: URL Redirection to Untrusted Site ('Open Redirect')                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| CAPEC-197: Exponential Data Expansion                                                | * CWE-776: Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| CAPEC-201: Serialized Data External Linking                                          | * CWE-611: Improper Restriction of XML External Entity Reference                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| CAPEC-215: Fuzzing and observing application log data/errors for application mapping | * CWE-209: Information Exposure Through an Error Message * CWE-532: Insertion of Sensitive Information into Log File                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| CAPEC-242: Code Injection                                                            | * CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| CAPEC-252: PHP Local File Inclusion                                                  | * CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| CAPEC-284: Improper Access Control                                                   | * CWE-501: Trust Boundary Violation                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| CAPEC-29: Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions          | * CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| CAPEC-337: Insufficient Transport Layer Protection                                   | * CWE-319: Cleartext Transmission of Sensitive Information                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| CAPEC-34: HTTP Response Splitting                                                    | * CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| CAPEC-475: Signature Spoofing by Improper Validation                                 | * CWE-297: Improper Validation of Certificate with Host Mismatch                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| CAPEC-492: Regular Expression Exponential Blowup                                     | * CWE-400: Uncontrolled Resource Consumption * CWE-1333: Inefficient Regular Expression Complexity                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| CAPEC-503: WebView Exposure                                                          | * CWE-749: Exposed Dangerous Method or Function                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| CAPEC-540: Overread Buffers                                                          | * CWE-125: Out-of-bounds Read                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| CAPEC-586: Object Injection                                                          | * CWE-502: Deserialization of Untrusted Data                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| CAPEC-62: Cross Site Request Forgery                                                 | * CWE-352: Cross-Site Request Forgery (CSRF)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| CAPEC-63: Cross-Site Scripting (XSS)                                                 | * CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| CAPEC-66: SQL Injection                                                              | * CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| CAPEC-83: XPath Injection                                                            | * CWE-643: Improper Neutralization of Data within XPath Expressions ('XPath Injection')                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| CAPEC-92: Forced Integer Overflow                                                    | * CWE-190: Integer Overflow or Wraparound                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| CAPEC-93: Log Injection-Tampering-Forging                                            | * CWE-117: Improper Output Neutralization for Logs                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| CAPEC-94: Man in the Middle Attack                                                   | * CWE-295: Improper Certificate Validation * CWE-322: Key Exchange without Entity Authentication                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| CAPEC-97: Cryptanalysis                                                              | * CWE-325: Missing Cryptographic Step * CWE-326: Inadequate Encryption Strength * CWE-327: Use of a Broken or Risky Cryptographic Algorithm * CWE-328: Use of Weak Hash * CWE-335: Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) * CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) * CWE-347: Improper Verification of Cryptographic Signature * CWE-780: Use of RSA Algorithm without OAEP * CWE-916: Use of Password Hash With Insufficient Computational Effort * CWE-1204: Generation of Weak Initialization Vector (IV) |
| CAPEC-462: Cross-Domain Search Timing                                                | * CWE-208: Observable Timing Discrepancy                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |

---
version: "Latest"
language: "en"
---
# COBOL

This article covers COBOL support and vulnerability detection for Mend SAST.

## Mend SAST-supported COBOL file types

| **File Type** |
|---------------|
| .cbl          |
| .cl2          |
| .cob          |
| .cpy          |
| .eco **\***   |
| .pco          |
| .sqb **\***   |

**\* Note:** These extensions are marked as 'Secondary' file extensions.

They will only be scanned if at least one file with any of the other 'Primary' file extensions is present to identify the language as the relevant language.

## Mend SAST-supported COBOL frameworks

| **Framework** |
|---------------|
| N/A           |

## Mend SAST-supported COBOL vulnerability types

The COBOL vulnerability types detected by SAST are provided below and are organized by CWE ID within each of their identified severities.

### COBOL high-severity vulnerability types

| **CWE** | **Vulnerability Type** |
|---------|------------------------|
| CWE-78  | Command Injection      |
| CWE-89  | SQL Injection          |
| CWE-121 | Buffer Overflow        |

---
version: "Latest"
language: "en"
---
# Code Findings Agentic Triage

## Overview

**Agentic Triage** is an AI-based capability that runs on top of the **Code Security Check (SAST)** in your repository integrations. For each code finding, it uses an LLM to assess whether the finding is a real vulnerability or a false positive, and returns that assessment together with a plain-language explanation of its reasoning.

The goal is to cut false-positive noise so your teams spend their time on the findings that actually warrant attention.

Agentic Triage is available in the Mend Developer Platform across the supported SCM integrations. For the exact behavior and screenshots in your environment, see the per-SCM guides linked in the [viewing the results](https://docs.mend.io/platform/latest/code-findings-triage.md#Viewing-the-results) section.

## How it works

When Code Security Check produces a finding, Agentic Triage analyzes the finding together with its data flow and surrounding code context, and returns:

* an **outcome** --- True Positive, Inconclusive, or False Positive;

* an **explanation** --- a structured breakdown of the evidence behind the outcome (for example: the vulnerable location, the relevant sanitizer or validator, control-flow coverage, and CWE relevance);

**Note:** AI results are advisory and are not perfect. Treat Agentic Triage outcomes as a prioritization aid, not a final decision --- a False Positive assessment does not automatically dismiss a finding, and outcomes should be validated by a human before you act on them.

## Prerequisites

Agentic Triage requires **the following** to be set before enabling the AI-based triaging.

1. AI addendum signed (AI Consent). Your organization must sign an addendum to your Mend contract that consents to AI processing. Contact your CSM to initiate this. Without it, the feature cannot be enabled.

2. Enable in the Mend Platform. An organization administrator enables the feature in the Mend Platform under **Administration → General** by toggling on **Code Findings Triage**.

![image-20260713-144804.png](https://docs.mend.io/__attachments/a_bdf07f6ffaac81cbc0f3172edaf3a1c963f250dcb9b157e836ad457a3742718d/image-20260713-144804.png?cb=2b8d51fb218c3ce0238b4f8359dad00d)

3. Enable in the Developer Platform. Enable the feature in the **Code Security** section of the **Developer Platform** settings.

![image-20260713-144820.png](https://docs.mend.io/__attachments/a_215f6e52ad05a3bf2141b9f34041ad8e4feeea74fe22dd1f9dfbad42a71ef5b1/image-20260713-144820.png?cb=b39d970157941d5e24d10b6551aa644d)  
When enabled, snippets of your source code and finding details are shared with [Mend.io](http://mend.io/)'s AI model to classify, prioritize, and provide triage insights. Disabling the option prevents any code from being shared with the model and turns off Agentic Triage entirely.

## Understanding the results

Every analyzed finding receives one of three outcomes, visible in the **Code Security Report**:  

|    **Outcome**     |                                            **Meaning**                                             |
|--------------------|----------------------------------------------------------------------------------------------------|
| **True Positive**  | The AI assesses the finding as a real, exploitable vulnerability. An exploitation path is provided |
| **Inconclusive**   | There is insufficient information to determine whether the finding is a true or false positive     |
| **False Positive** | The AI assesses the finding as not exploitable / not a real issue                                  |
| **Unknown**        | Mend doesn't support AI Triage for this type of vulnerability                                      |
| **Skipped**        | The triage for this vulnerability was disabled by the user                                         |
| **Error**          | There was an error when processing the results                                                     |

To review the analysis for a finding, expand the triage result under that finding to see the outcome, then expand the **Explanation** to see the full evidence breakdown. For True Positives, the exploitation path is included in the breakdown.  
![image-20260713-152151.png](https://docs.mend.io/__attachments/a_3215059ac276e3c600514a77cd9c35f8e7b7095da33820ffd0110462a501d441/image-20260713-152151.png?cb=0528e65aa2d01f4f2df7cd4972fe09ea)
An example of the full evidence breakdown under the **Explanation**per finding

## Supported languages

Agentic Triage supports the following languages:

* Java

* JavaScript / TypeScript

* Go

* Python

* C#

* Ruby

* Kotlin

* PHP

* Scala

* Rust

* C++

## Supported CWEs

* CWE-89 SQL Injection

* CWE-79 Cross-Site Scripting

* CWE-78 OS Command Injection

* CWE-94 Code Injection

* CWE-22 Path Traversal

* CWE-73 External Control of File Name/Path

* CWE-918 Server-Side Request Forgery

* CWE-90 LDAP Injection

* CWE-943 NoSQL Injection

* CWE-643 XPath Injection

* CWE-611 XML External Entity

* CWE-502 Deserialization of Untrusted Data

* CWE-113 HTTP Response Splitting / Header Injection

* CWE-113 HTTP Response Splitting

* CWE-117 Log Injection / Log Forging

* CWE-200 Sensitive Information Exposure

* CWE-501 Trust Boundary Violation

* CWE-601 Open Redirect

* CWE-1333 ReDoS

* CWE-798 Use of Hard-coded Credentials

* CWE-327 Broken/Risky Crypto Algorithm

* CWE-328 Use of Weak Hash

* CWE-338 Cryptographically Weak PRNG

* Cookie Without 'Secure' Flag

* CWE-1004 Cookie Without 'HttpOnly' Flag

* CWE-295 Improper Certificate Validation

* CWE-319 Cleartext Transmission

## Viewing the results

Agentic Triage results appear in the Code Security Report in the Mend Developer Platform and in your SCM. The exact UI, indicators, and steps differ slightly per integration. See the guide for your SCM:

* [View the results of your Mend Developer Platform SAST scan in Azure DevOps Repos \| Viewing the AI Triage Results](https://docs.mend.io/integrations/latest/view-results-mend-sast-scan-azure-devops.md#Viewing-the-AI-Triage-Results)

* [View the results of your Mend Developer Platform SAST scan in Bitbucket Cloud](https://docs.mend.io/integrations/latest/view-results-mend-dev-platform-sast-scan-bitbucket.md)

* [View the results of your Mend Developer Platform SAST scan in GitHub.com \| Viewing the AI Triage Results](https://docs.mend.io/integrations/latest/view-results-dev-platform-sast-scan-github.md#Viewing-the-AI-Triage-Results)

## Limitations

* Agentic Triage currently covers **SAST (Code Security)** findings only. AI triage for other engines (SCA, Containers, etc.) is out of scope.

* AI outcomes are advisory and not guaranteed to be correct; validate before acting.

---
version: "Latest"
language: "en"
---
# Code Scan Customization Candidates

## Overview

Scan Rule Customization is a project-specific mechanism that allows you to increase the accuracy of your Code scans. Scan Customization **Candidates** serve as a complementary feature, whereby potential candidates for enhancing the rules are picked up during the scan and presented to the [Mend.io](http://mend.io/) Professional Services engineer via the Rule Customization UI, where they can be accepted or rejected.

### Use-case

An organization uses a framework that [Mend.io](http://mend.io/) does not support out of the box. During the regular SAST scan, the code will be analyzed for any potential entry points/sources/sinks/sanitizers. These candidates will be presented to the [Mend.io](http://mend.io/) Professional Services engineer in the customization view and can be accepted to proactively increase the accuracy of the Code findings.

### Limitations

* Scan Customization Candidates cannot be edited, they can only be **approved** or **rejected**.

## Getting it done

**Note:** Rule Customization can only be performed by [Mend.io](http://mend.io/) Professional Services engineers.

Please reach out to your Customer Success Manager at [Mend.io](http://mend.io/) to request this service.

### AI Usage Toggle

**Note:** The Code Scan Customization toggle must be enabled for the Customization Candidates feature to be available.

Enable or disable AI-based Rule Customization for your Code scans using the **Code Scan Customization** toggle under the **AI Usage** section of your organization's **General Configuration**.

If enabled, data about invocations of external libraries and method declarations in your source code is collected during the scan and will be shared with [Mend.io](http://mend.io/)'s AI model to improve the accuracy of your Code scans by suggesting candidates for further customization of the Code scan rules. Disable this option to prevent any information about your code from being shared with the model and turn off the candidate suggestions entirely.

1. Navigate to the **Administration** page using the cogwheel drop-down menu:

![image-20250324-125949.png](https://docs.mend.io/__attachments/a_dbe000afe5bfb697bdb1f24745d658383339400d69bce82b5f8df86aede7995a/image-20250324-125949.png?cb=249dd3a62323495b05480c594ffd2bbe)

2. Under **General Configuration,** use the **Code Scan Customizatio** **n** toggle to enable or disable the feature.

   ![image-20250326-111645.png](https://docs.mend.io/__attachments/a_dc943fab27beac7975e10653659450b52ff49c1d5a65527abba9be56cc73e314/image-20250326-111645.png?cb=e54e7eee590a90147572dd9e2f46c732)

**Note:** Toggling these on means you consent to the use of AI for Code Findings Remediation and Code Scan Customization, respectively.

## Supported Languages

Mend AI-based Code remediation supports the following languages and CWEs (Common Weakness Enumeration):  

| **Language** |                                                                                                                                                                                                                                                                                         **CWE**                                                                                                                                                                                                                                                                                          |
|--------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| C/C++        | * CWE-22: Path Traversal * CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') * CWE-89: SQL Injection * CWE-134: Use of Externally-Controlled Format String * CWE-918: Server-Side Request Forgery (SSRF)                                                                                                                                                                                                                                                                                                                                |
| C#           | * CWE-22: Path Traversal * CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') * CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') * CWE-89: SQL Injection * CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') * CWE-117: Log Injection * CWE-502: Deserialization of Untrusted Data * CWE-601: Open Redirect * CWE-643: Improper Neutralization of Data within XPath Expressions ('XPath Injection') * CWE-918: Server-Side Request Forgery (SSRF) |
| Java         | * CWE-22: Path Traversal * CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') * CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') * CWE-89: SQL Injection * CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') * CWE-117: Log Injection * CWE-502: Deserialization of Untrusted Data * CWE-601: Open Redirect * CWE-643: Improper Neutralization of Data within XPath Expressions ('XPath Injection') * CWE-918: Server-Side Request Forgery (SSRF) |
| JavaScript   | * CWE-22: Path Traversal * CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') * CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') * CWE-89: SQL Injection * CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') * CWE-117: Log Injection * CWE-502: Deserialization of Untrusted Data * CWE-601: Open Redirect * CWE-643: Improper Neutralization of Data within XPath Expressions ('XPath Injection') * CWE-918: Server-Side Request Forgery (SSRF) |
| Python       | * CWE-22: Path Traversal * CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') * CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') * CWE-89: SQL Injection * CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') * CWE-117: Log Injection * CWE-502: Deserialization of Untrusted Data * CWE-601: Open Redirect * CWE-643: Improper Neutralization of Data within XPath Expressions ('XPath Injection') * CWE-918: Server-Side Request Forgery (SSRF) |
| TypeScript   | * CWE-22: Path Traversal * CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') * CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') * CWE-89: SQL Injection * CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') * CWE-117: Log Injection * CWE-502: Deserialization of Untrusted Data * CWE-601: Open Redirect * CWE-643: Improper Neutralization of Data within XPath Expressions ('XPath Injection') * CWE-918: Server-Side Request Forgery (SSRF) |
| Rust         | * CWE-22: Path Traversal * CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') * CWE-89: SQL Injection * CWE-90: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') * CWE-643: Improper Neutralization of Data within XPath Expressions ('XPath Injection')                                                                                                                                                                                                                                             |

---
version: "Latest"
language: "en"
---
# Code Secrets - Appendix

## Overview

This article lists the various types of secrets detected by Mend SAST as part of the [secret detection](https://docs.mend.io/platform/latest/code-secret-scanning.md).

## Supported Secrets

### **Cloud Provider Access Tokens and Secrets**

These represent credentials that grant access to cloud environments:

* **AWS**

  * Access Key ID

  * Secret Access Key

  * Account ID

* **Azure DevOps**

  * Azure Database for PostgreSQL / MySQL / MariaDB

  * Azure Cosmos DB connection string

  * Azure Storage account connection string

  * Azure Storage SAS token

  * Azure AD Client Secret (new `Q~` format)

  * Azure Active Directory Access Token

  * Azure App Configuration Access Key

  * Azure App Service deployment password

  * Azure Databricks Personal Access Token

  * Azure SignalR Access Key

  * Azure Communication Services Access Key

  * Azure Maps Subscription Key

  * Azure Web PubSub Access Key

  * Azure Redis Cache password

  * Azure IoT Shared Access Key

  * Azure Shared Access Signature (generic SAS)

  * Azure Logic App SAS URL

  * Azure Service Bus SAS

* **Google Cloud Platform (GCP)**

  * Service account credentials

* **Alibaba Cloud**

  * Access Key ID

  * Secret Key

* **Heroku**

  * API Key

* **HashiCorp**

  * Terraform API Token

* **Pulumi**

  * API Token

* **PlanetScale**

  * API Token

  * Password

*** ** * ** ***

### **Asymmetric \& Encryption Keys**

These are used for securing communications or authentication:

* **Asymmetric Private Keys**

  * PEM-formatted keys like RSA, DSA, EC, etc.

* **Age**

  * AGE-SECRET-KEY for file encryption

*** ** * ** ***

### Committed Certificate and Private-Key Files

In addition to detecting key material embedded in code, Mend SAST flags certificate and private-key files committed directly to source control:

* **PEM private key files** (`.pem`, `.key`) --- flagged when the file contains a `-----BEGIN PRIVATE KEY-----` or `-----BEGIN RSA PRIVATE KEY-----` header.

* **PFX / PKCS#12 certificate containers** (`.pfx`, `.p12`) --- committing these files to source control is always a misconfiguration, regardless of whether the contents are readable. These generate a distinct finding: **"Certificate bundle committed to source control."**

*** ** * ** ***

### **API Provider Tokens**

These provide access to various SaaS provider APIs:

* **GitHub** (PAT, OAuth, App Token, Refresh Token)

* **GitLab** (PAT)

* **Stripe** (Publishable \& Secret Keys)

* **Slack** (Access Token, Webhook)

* **Twilio** (API Key)

* **Mailgun** (API Key, Signing Key)

* **SendGrid** , **Sendinblue** , **Postman** , **Databricks** , **Dropbox** , **Shippo** , **Lob** , **Typeform**, etc.

* **New Relic** (User API Key, Browser Token)

* **Dynatrace** , **Intercom** , **Linear** , **Bitbucket** , **Atlassian** , **Fastly** , **Clojars** , **Contentful**, etc.

This includes a large number of specific SaaS provider keys (see "Custom API Providers" below for exhaustive list).

*** ** * ** ***

### **OAuth Clients and Secrets**

Used for applications performing OAuth authentication:

* **Adobe**

  * Client ID \& Secret

* **Asana**

  * Client ID \& Secret

* **Atlassian**

  * API Token

* **Bitbucket**

  * Client ID \& Secret

* **Discord**

  * Client ID, Secret, and API Key

* **Facebook**

  * Token

* **Twitter**

  * Token

* **LinkedIn**

  * Client ID \& Secret

* **Intercom**

  * Client Secret

*** ** * ** ***

### **Custom or Lesser-known API Provider Tokens**

These include vendor-specific or niche services:

* **Shopify**

* **PyPI**

* **Doppler**

* **Beamer**

* **Clojars**

* **Contentful**

* **Databricks**

* **Discord**

* **Duffel**

* **Easypost**

* **Finicity**

* **Flutterwave**

* **Frame.io**

* **GoCardless**

* **Grafana**

* **HubSpot**

* **Ionic**

* **Linear**

* **Mailchimp**

* **Mapbox**

* **MessageBird**

* **Npm**

* **Postman**

* **RubyGems**

* **SendGrid**

* **Sendinblue**

* **Shippo**

* **Twitch**

*** ** * ** ***

### **Miscellaneous Secrets**

These may not fit standard categories but are covered by specific regex rules:

* **Private Signing Keys**

* **Webhook URLs** (e.g., Slack Webhooks)

* **JWT-style or Bearer tokens embedded in code**

*** ** * ** ***

### **CI/CD and Package Registry Tokens**

These secrets are used to authenticate with build, deployment, or artifact management systems:

* **PyPI** -- Upload token

* **Clojars** -- API token

* **npm** -- Access token

* **RubyGems** -- API token

* **GitHub \& GitLab** -- Personal Access Tokens (used in CI/CD)

* **Pulumi** , **Terraform (HashiCorp)** -- Infrastructure as Code deployment tokens

> These secrets are often embedded in build pipelines to publish or pull packages or deploy services.

*** ** * ** ***

### **Webhook Signing Keys**

These are used to **verify the integrity of incoming webhooks**:

* **Mailgun** -- Webhook signing key

* **Slack** -- Webhook URL (used to receive data)

While webhook URLs can act as secrets, signing keys are explicitly used for **security validation**, not just access.

*** ** * ** ***

### **Mobile SDK or Embedded Client Keys**

Some tokens are typically **used in client-side or mobile apps**:

* **Stripe Publishable Keys** -- Marked as `Low` severity

* **Mapbox Public Keys**

* **Flutterwave Public Keys**

* **Lob Publishable API Keys**

> These keys are meant to be exposed in frontend/mobile apps but still tracked due to misuse potential or misclassification.

*** ** * ** ***

### **Client Identifiers (non-secret but sensitive)**

Some fields like `Client ID` are technically **not secret**, but they:

* Appear in rules (e.g. LinkedIn, Adobe, Discord)

* Are flagged because leaking them could assist an attacker in phishing or spoofing OAuth workflows

> These are tracked to prevent **partial disclosure** that may combine with other secrets.

*** ** * ** ***

### **Potentially Sensitive Identifiers**

While not secrets in themselves, some rules match **identifiers that, when leaked, may facilitate further discovery or abuse**:

* **AWS Account ID**

* **GitHub App/Refresh Tokens**

* **Dropbox Short/Long-lived Tokens**

> These are high-value identifiers even if they don't unlock access directly, and may be abused in chaining attacks.

*** ** * ** ***

### **Test Environment Secrets**

Many tokens are prefixed with:

* `test_`, `sandbox_`, `dev_`, etc.

Examples include:

* `duffel_test_`

* `FLWSECK_TEST`

* `sk_test_` / `pk_test_` (Stripe)

* `shippo_test_`

## Supported Configuration and Script Files

Below is a list of some of the prominent configuration files scanned for exposed credentials:

`.bks`

`.cfg`

`.conf`

`.config`

`.env`

`.jks`

`.json`

`.keystore`

`.npmrc`

`.p12`

`.pem`

`.pfx`

`.pbxproj`

`.plist`

`.properties`

`.ps1`

`.rc`

`.template`

`.tf`

`.tfstate`

`.tfvars`

`.toml`

`.xcconfig`

`.xml`

`.yaml`

`.yml`

---
version: "Latest"
language: "en"
---
# Code Secret Scanning

## Overview

Mend SAST Secret Scanning provides a comprehensive security overview, by introducing the capability to:

1) **Scan** both source code and configuration files to detect exposed credentials, based on patterns.

2) **View** the results alongside standard SAST results.

### Configuration Files

Below is a list of some of the more prominent configuration files scanned for exposed credentials.

* JSON

* XML

* .properties

* .yaml

* .config

For the full list, visit the [Code Secrets Appendix](https://docs.mend.io/platform/latest/code-secret-rules.md#Secrets-Configuration-Files).

## Getting it done

### Secret Scanning as part of a Regular SAST Scan

To add secret detection to your regular SAST scan, enable the `--secrets-detection` command line parameter in addition to the regular `mend code` command in the [Mend CLI](https://docs.mend.io/platform/latest/scan-your-custom-code-sast-with-the-mend-cli.md).

When unspecified, secret scanning as part of your SAST scan is disabled.  
**Note:** This mode is also supported in the [Developer Platform](https://docs.mend.io/integrations/latest/mend-developer-platform.md) and [Mend for GitHub.com](https://docs.mend.io/integrations/latest/configure-mend-for-github-com-for-sast.md).

Here's what a SAST scan with secrets detection enabled would look like in the terminal:  
![image-20250617-073256.png](https://docs.mend.io/__attachments/a_4bb4d37288b57bb9e7d65a8ac9d6592c598ab6a2aafcca9d0379aed0e063ef81/image-20250617-073256.png?cb=229e8402fab5716f1841cd5e6d5f0e8d)
Example of Mend CLI SAST Scan with Secrets Detection

### Viewing Results

The results of the secret scanning will appear in the platform UI alongside other Code findings.

They will be differentiated from other code findings by the value "Secrets" in the **Language** column.

Noteworthy values of secret scanning findings:

1. **CWE Name** - 2 possible values:

A. Hardcoded Password/Credentials (CWE-798)

B. Secret in Configuration File (CWE-260)

2. **Severity -** Always **Medium**.

3. **Sink** - The type of secret detected, e.g., Postman API Token, AWS Access Key ID, etc.

4. **Language** - "Secrets".

![image-20250614-134027.png](https://docs.mend.io/__attachments/a_f4539ab20a4179f84b0515262f8cbbfe9d8191081722b5c7c407b81fd4350115/image-20250614-134027.png?cb=474de0a36d22449f6349172b048fbf77)

Clicking anywhere on a row of a detected secret will spawn a drawer with more in-depth information about the secret:  
![image-20250616-121348.png](https://docs.mend.io/__attachments/a_68609e17c0c59e827b8162ef3050eb44ad41d8875fe503e97f00eab7f90f6e1b/image-20250616-121348.png?cb=befc3357d2f3964017a6ea0fa6ee7d5f)  
**Note:**

* All secret findings are labelled as 'Medium' severity.

* Mend.io does not anonymize detected secrets.

### Automation Workflows around Secret Detection

You can create Automation Workflows around secret detection to trigger policy violations and fail builds, in a similar fashion to every other Code finding.

Visit the [Automation Workflows documentation](https://docs.mend.io/platform/latest/automate-your-workflows-in-the-mend-platform.md) for more details.  
![image-20250614-141709.png](https://docs.mend.io/__attachments/a_41248262c141a182db9bc663787cdbb242ccf65bfa2fadbb2d06846d5eb370ff/image-20250614-141709.png?cb=0643143c2e4dd5d08f9cfdec9f4205f5)
Example - Automation Workflow Triggered by Detection of CWE-260: Secret in Configuration File

---
version: "Latest"
language: "en"
---
# Coldfusion

In this article, we cover Coldfusion support and vulnerability detection for Mend SAST.

## Mend SAST-supported Coldfusion file types

| **File Type** |
|---------------|
| .cfm          |

## Mend SAST-supported Coldfusion frameworks

| **Framework** |
|---------------|
| N/A           |

## Mend SAST-supported Coldfusion vulnerability types

The Coldfusion vulnerability types detected by SAST are provided below and are organized by CWE ID within each of their identified severities.

### Coldfusion high-severity vulnerability types

| **CWE** |  **Vulnerability Type**  |
|---------|--------------------------|
| CWE-22  | Path/Directory Traversal |
| CWE-78  | Command Injection        |
| CWE-79  | Cross-Site Scripting     |
| CWE-89  | SQL Injection            |

---
version: "Latest"
language: "en"
---
# Configure Mend for Jira Cloud

## Overview

The Mend Integration for Jira Cloud allows you to manage how security findings are reported and mapped between the Mend AppSec Platform and your Jira projects. You can onboard multiple Mend organizations and configure how issues are created across them, all from a single Jira Cloud integration. This provides a unified experience, eliminating the need to manage separate plugin instances for each organization.

## Getting it done

### Manage your Mend Organizations and Mappings

1. After onboarding your Mend Organization(s), you'll be navigated to the **Organizations** page where you can manage your connected Mend organizations and configure the mappings of each one.

![image-20250504-231232.png](https://docs.mend.io/__attachments/a_aa6329ab252c3a4c06af76c2a1b6044f986c80671152539bca77eafd01f8f346/image-20250504-231232.png?cb=e9bcaf03fe1bb11468f3fb0f132a7b78)

2. Clicking on a connected organization opens a pop-up window with three configuration sections:

   1. **Overview** --- Provides a summary of the connected Mend organization. It includes key integration details such as organization UUID, connection status, mode (e.g., Create Issue), timestamps for integration and updates, and the user who last modified the settings. This is your central reference for the integration status and setup metadata.

      ![image-20250409-002255.png](/__attachments/a_2270e3726de406e48e680fe21c700082586911036c5e5d1ba303397050a2a831/image-20250409-002255.png?cb=83c3700976af6fec043746c2069076ea)
   2. **Mapping** --- Allows you to define how Mend applications and projects are linked to Jira Cloud projects. By default, all items map to a single Jira project, but you can add specific exceptions using the "**Add Mapping** " option. This ensures issues are created in the right context for each project or application. Click **Save** to activate the selected mappings.

      ![image-20250409-002401.png](/__attachments/a_da6f3b014f2e70c9c4bcca86fb64c1663c839be1ff04a4c1a775e87d11951644/image-20250409-002401.png?cb=7df7b275d3797f66c80e3480b399c2eb)
   3. **Labels**--- Enables the configuration of Jira labels for issues created through the Mend integration. Labels can include Mend attributes, free-text values, or existing Jira labels. When labels are defined at both the integration and project levels, they are automatically merged into a single consolidated list.

      ![image-20250825-125929.png](/__attachments/a_361bcfeb1bd4e44f0a2e7f44761158322e3bafc9fc9b3c3df718b0501904f846/image-20250825-125929.png?cb=12022d4017169031b5543be95d2c8a04)
   4. **Advanced Settings** --- Includes advanced configuration actions. Here, you can switch the integration mode (e.g., to Jira Security Dashboard), update the activation key to re-integrate with Mend, or remove the organization entirely from the Jira Cloud plugin.

      ![image-20250409-002220.png](/__attachments/a_900d53d04571cd59e26dd99e1bbd33b230067c7535636cc521221034388ed5db/image-20250409-002220.png?cb=c1bb00d9d354aea5b3cf3069b5600a96)

**Note:** Alternatively, you can click the **three-dot menu** (⋮) on the right side of the organization entry. This opens a contextual menu where you can access additional actions, such as editing the mappings, updating the activation key, or removing the organization.  
![image-20250409-001634.png](https://docs.mend.io/__attachments/a_dec4ae0382540e91e40513305b4f89c2fce16064366af9d87d0521ce03f75284/image-20250409-001634.png?cb=a36f5ff8fd675ca9443696a75e4a27d7)

### Work Item Type Mapping

You can customize the Work Item Type fields Mend uses to create issues by adding, editing, or deleting mappings of Mend attributes to existing Jira fields for a selected issue type within a Jira project.

The supported work item types to configure are:

* \[**Default**\] Mend Types (Dependencies, Code, Containers)

* Task

* Sub-Task

* Story

* Bug

* Epic

1. Navigate to the "**Work Item Type Mapping**" tab, where you will see your Jira projects, their default Work Item Type, the number of Mend organizations linked to this Jira project, and the last updated date of this configuration.

2. To customize the Work Item Type, click on the Jira project name or the pencil button.

![image-20250825-124915.png](https://docs.mend.io/__attachments/a_45de2ec01da0f26defab6fd781322f7ad31f2ff160e994a99f4f299e1c8e84ea/image-20250825-124915.png?cb=29acf3ef4f3187758f2160cca9b298ec)

2. The default Work Item Type is "Mend Types", but you can select each supported type from the list.

![image-20250825-130019.png](https://docs.mend.io/__attachments/a_8ad60ba826b4731229726cfa3035ce271f1eeae5e3ac05abfef14ea01235b302/image-20250825-130019.png?cb=10ba581d2ac073d733558696260510fd)

3. When selecting a Work Item Type, you can configure the field values and use Mend attributes for the supported field types.

![image-20250825-125847.png](https://docs.mend.io/__attachments/a_81029a3a4b9a43133ca2d011b86d47d012e25d249d9c60786101341a6779e728/image-20250825-125847.png?cb=c10dcd3bc052706937d4c8fdc0d7edbd)

4. Click **Save** to apply the changes for all future Jira issues created through the integration.

**Notes:**

* Changes to a work item type will apply to all tickets that will be created for this Jira project.

* Mend Work Item Types are pre-configured and cannot be customized.

* Jira field types with pre-defined options, such as Dropdown, Multiple Selection, or List, **aren't** supported for customization with Mend attributes.

* Mend doesn't support work item types with mandatory fields that cannot be set via the integration.

* **Violations \& Violated workflows**are volatile and if the Jira issue is created before the Violation workflow completes the values might not be accurate. We currently do not support Jira issue updates, so values in the description may not be correct over time.

#### Supported Custom Field Types for Mapping

|---------------|------------------|---------------|
| `TEXT`        | `GROUP`          | `PROJECT`     |
| `URL`         | `MULTIGROUP`     | `ISSUE`       |
| `SELECT`      | `VERSION`        | `CUSTOM`      |
| `MULTISELECT` | `MULTIVERSION`   | `MULTITEXT`   |
| `DATE`        | `COMPONENT`      | `LABELS`      |
| `DATETIME`    | `MULTICOMPONENT` | `MULTINUMBER` |
| `USER`        | `NUMBER`         | `CHECKBOXES`  |
| `MULTIUSER`   | `RADIO`          | `PRIORITY`    |

#### Supported Attributes List

| **Attribute Name** |         **Format**         |                              **Example Value(s)**                               |
|--------------------|----------------------------|---------------------------------------------------------------------------------|
| Org Name           | Plain text                 | Mend                                                                            |
| Application Name   | Plain text                 | Online Storefront                                                               |
| Project Name       | Plain text                 | frontend-ui                                                                     |
| Org UUID           | Value, Key:Value           | 3e4-54rff-546-654654, org_uuid: 3e4-54rff-546-654654                            |
| App UUID           | Value, Key:Value           | app_uuid: ab12-34cd-56ef                                                        |
| Project UUID       | Value, Key:Value           | project_uuid: xy98-76zy-12wx                                                    |
| Severity           | Plain text                 | High, Medium, Low                                                               |
| Violating          | Value, Key:Value (Boolean) | true, Violating: true                                                           |
| Fix Available      | Value, Key:Value (Boolean) | true, Fix available: true                                                       |
| Reachable          | Value, Key:Value (Boolean) | true, Reachable: true                                                           |
| Exploitable        | Valu, Key:Value (Boolean)  | true, Exploitable: true                                                         |
| Malicious          | Value, Key:Value (Boolean) | true, Malicious: true                                                           |
| Scan Engine        | Plain text                 | Dependencies (SCA), Code (SAST), Containers                                     |
| Created By         | Contextual text            | Manual: [john.doe@mend.io](mailto:john.doe@mend.io), Workflow: Auto Remediation |

### Onboard Mend Organizations

The Mend Integration for Jira Cloud supports connecting and managing multiple Mend organizations from a single Jira Cloud plugin. This provides a unified view and experience, enabling you to manage issue creation across various Mend organizations without switching between separate plugin instances.

Follow these steps to enable and configure the multi-org view within the Jira Cloud plugin:

1. After installing the [Mend Integration for Jira Cloud](https://marketplace.atlassian.com/apps/1226253/mend-integration-for-jira-cloud?tab=overview&hosting=cloud), as described [here](https://docs.mend.io/platform/latest/install-mend-for-jira-cloud.md#Install-From-Atlassian-Marketplace), you'll see the following screen:

   ![image-20250408-161614.png](https://docs.mend.io/__attachments/a_5b33b9ce5cc98d52cdd99bc094d6860390f8058c06427fdc3c747bfadab156ea/image-20250408-161614.png?cb=da659f22d29602ac9fad6a8bfd902a9e)
2. On the **Add an Organization** page, add your activation key from [the installation step](https://docs.mend.io/platform/latest/install-mend-for-jira-cloud.md#Grab-your-Activation-Key) into the **Mend Platform Activation Key** section.

3. Select which **Vulnerability Notification Preference** you prefer:

   1. **Create Issues:** Using a pre-defined workflow from your organization in the Mend Platform, automatically create Jira issues for findings that meet the conditions of the workflow, or create issues manually.

   2. **Jira Security Dashboard (beta) - SCA Only**: Monitor your Jira projects with a centralized view of security issues and risks across your organization.

4. Assign your **Default Jira Cloud Project** to where the issues will be created (Relevant only to "create issues" mode).

5. Click on **Add Organization** to activate the Mend for Jira Cloud plugin.

---
version: "Latest"
language: "en"
---
# Configure Policy Violations with Automation Workflows

## Overview

The Mend Platform's Automation Workflow feature enables you to define and manage policy violations effectively. By leveraging advanced violation settings like **Violation SLA** and **Violation Priority** , you can prioritize and address issues efficiently, ensuring your organization remains secure and compliant.

Additionally, you can configure workflows to **fail the pipeline build** immediately when a violation is detected, ensuring that critical issues are addressed promptly during the development process.

This article outlines how to configure policy violations when creating Workflow, including how to create and customize violation settings to suit your organization's needs. For detailed guidance on viewing and managing existing violations, see [Viewing Violating Findings](https://docs.mend.io/platform/latest/view-violating-workflows-and-findings.md).

## Getting it done

### Setting Up Policy Violations

Policy violations in the Mend Platform are [created through the Automation Workflow.](https://docs.mend.io/platform/latest/create-an-automation-workflow-in-the-mend-platform.md) These workflows let you automate responses to specific triggers, such as security risks or compliance breaches. To enhance this process, the platform introduces **Violation Priority** , **Violation SLA** , and **Fail Pipeline on Violation**, which provide:

* **Violation Priority**: Classify and prioritize violations based on their importance, allowing focused allocation of resources to critical issues.

* **Violation SLA**: Defined timeframes for resolving policy violations, ensuring timely remediation.

* **Fail Pipeline on Violation:** Enable the option to fail the pipeline build when a violation is detected ([Exit Code 9](https://docs.mend.io/platform/latest/mend-cli-exit-codes.md) in the CLI).

Together, these settings empower you to streamline your violation management process and maintain a strong security posture.

### Configuring Violation Settings in Workflows

To define SLA and Priority attributes for violations triggered by a Workflow, follow these steps:

1. Log into the Mend Platform.

2. Click **Workflows** in the top navigation.

3. Choose what type of Workflow you would like to create: (1) From Template (2) Create a Blank Workflow

![image-20250104-232603.png](https://docs.mend.io/__attachments/a_9bdb4e7aed6d2141f80a9dc8f5d1b67490ecb033ac6ce945daf6d9750412e90c/image-20250104-232603.png?cb=de8c7fdb1d674678b538e2dc2ca48cd5)
You can either select a pre-defined workflow template from Mend or create your own custom workflow.

4. You'll be navigated to the Create Workflow screen.

5. Once "**Create Violation** " is selected as the [Workflow Action](https://docs.mend.io/platform/latest/workflow-configuration-parameters.md#Workflows-Action-options), the Violation Settings menu will show up with the Priority, SLA, and Fail Pipeline on Violation options.

![image-20250104-233008.png](https://docs.mend.io/__attachments/a_8af4e2d821c52b66ede085988e095c2a848a196c91face9fb2bf8753120bf662/image-20250104-233008.png?cb=965518464b893019789beaa609624a6a)

**Violation Priority -**These classifications allow you to prioritize violations according to their potential impact.

* Select a severity level: Critical, High (default), Medium, or Low.

**Violation SLA -**Violation SLA ensures that violations are addressed within a set timeframe, helping to maintain security standards.

* Select an SLA value: 15 Days, 30 Days, 60 Days, 90 Days, 180 Days, None or Custom.

* The 'Custom' option opens a custom SLA days picker, accepting integers between 1 and 1000.

**Fail Pipeline on Violation -** Enabling this setting will fail the pipeline when a violation is found depending on the pipeline setup ([Exit Code 9](https://docs.mend.io/platform/latest/mend-cli-exit-codes.md) in the CLI).

### Managing Violations in the Violations Table

Once violations are created, you can view and manage them in the **Violations Table**. The table includes columns for SLA and Priority, providing additional tools for effective violation management.  
![image-20250104-235341.png](https://docs.mend.io/__attachments/a_1ad9ba6ee75c2f9e377e7e20898e21f05697473133d1e7ba0c75c79dee572d97/image-20250104-235341.png?cb=c9bc10a0e86a10d86d25a9a5aaa18e79)

#### **View and Filter Violations**

Use the SLA and Priority columns to filter, sort, and prioritize violations (e.g., filter for overdue violations using the **SLA** column filter).  
![image-20250104-235503.png](https://docs.mend.io/__attachments/a_8907d33d8059be46555f2dcd8235c77c0afc570d38a8899aa749a12fbd7e0997/image-20250104-235503.png?cb=d8e1cda152993df7a0d7a1d4b439ae29)

#### **Manually Adjust SLA**

You can modify the SLA directly in the table for one or multiple violations. You can set specific due dates or remove SLA tracking by selecting **None**.  
**Notes:**

* Only users with the roles of Admins or Security Managers have permission to adjust SLA manually.

* Manual changes to SLA cannot be reverted to the original value.

![image-20250104-235755.png](https://docs.mend.io/__attachments/a_7838b1b54b31fe5175db7e7590e42acf86065075e56f3c9a24c478f1e055d84a/image-20250104-235755.png?cb=833515ea339e62f647ea8e998fd197b1)  
For more information on viewing violation details, please refer to [View your Violating Findings](https://docs.mend.io/platform/latest/view-violating-workflows-and-findings.md).

## Special Cases and Guidance

1. **Editing Workflows -**

* Changes to SLA or Priority in a Workflow apply only to new violations detected after the next scan.

* Existing violations are unaffected unless you explicitly enable the Apply updates to existing violations in future scans option when editing the Workflow.

2. **Pre-Existing Violations -**

* SLA: For violations created before this feature's introduction, the SLA attribute defaults to None. You can manually adjust this value in the Violations table (for existing entries).

* Priority: The default priority level for pre-existing violations is set to High, based on the assumption that these violations likely correspond to critical or high-priority issues.

* To update the priority level, modify the workflow settings and enable the application of updates to existing violations in future scans. This will override the Priority value for affected violations.

3. **Workflows Without Initial SLA and Priority -**

* If violations are created by such Workflows, the following defaults apply:

  * SLA: None.

  * Priority: High.

  * You can manually adjust these values in both Workflow settings (for future scans) and the Violations table (for existing entries).

4. **Renaming a Workflow -**

* Renaming is instantly reflected in all associated violations and tables, without affecting SLA or Priority.

5. **New Violations with Defined Attributes -**

* SLA and Priority values defined in the Workflow are applied to newly created violations unless the user chooses otherwise. Adjustments to these Workflow settings will only affect subsequent scans, ensuring no disruption to historical data.

---
version: "Latest"
language: "en"
---
# Configure your private Amazon Elastic Container Registry (ECR) in the Mend Platform

## Overview

The Mend container image registry scanning solution can integrate with your private ECR using your provided access and secret keys.

## Getting it done

### Prerequisites before you scan ECR with Mend Container

* Your Mend user must be an organization administrator.

* Your Amazon ECR user that owns the access and secret keys provided to Mend for authentication must have an IAM policy attached with the necessary actions for all registry resources. See the [Amazon ECR setup](https://docs.mend.io/legacy-sca/latest/configure-private-ecr-with-mend#ConfigureyourprivateAmazonElasticContainerRegistry(ECR)withMend-PrerequisitesbeforeyouscanECRwithMend) section of this document for instructions.

### Amazon ECR setup

++**Step 1: Create the access and secret keys in AWS:**++

1. Navigate to your **AWS Management Console** and open the **IAM console**.

2. Select **Users** and click on the user that will be used for the integration.

3. Navigate to the **Security Credentials** tab → **Access keys** section and click on **Create access key**.

4. Once you finish, keep the access and secret keys on hand for the integration.

++**Step 2: Create the policy in AWS:**++

1. Navigate to your **AWS Management Console** and open the **IAM console**.

2. In the navigation pane on the left, select **Policies** and click **Create**.

3. Specify the required actions:

    "ecr:GetAuthorizationToken",
    "ecr:BatchCheckLayerAvailability",
    "ecr:BatchGetImage",
    "ecr:DescribeRepositories",
    "ecr:GetDownloadUrlForLayer",
    "ecr:GetRepositoryPolicy",
    "ecr:ListImages",
    "ecr:ListTagsForResource",
    "ecr:DescribeImages"

++**Step 3: Attach the policy in AWS:**++

1. Navigate to your **AWS Management Console** and open the **IAM console**.

2. Select **Users** and click on the user that owns the access and secret keys generated in Step 1.

3. Navigate to the **Permissions** tab and click on **Add permissions** → **Add permissions**.

4. For the **Permissions options** , select **Attach policies directly**.

5. Select the created policy from Step 2 and click on **Next**.

6. Click on **Add Permissions** to attach the policy to the user.

### Set up your private ECR configuration via the Mend Platform UI

1. In the Mend Platform UI, navigate to ![image-20240319-192945.png](https://docs.mend.io/__attachments/a_3af49ea3daa2512d08afb5a3dd1135cb6fc65790cdcfb58e174e419983c25268/3c0e5b44-c5cc-425c-ba3c-05ff2986b798?cb=e41593bc985552bd37bd21f3f5ca4365) → **Integrations.**

2. Scroll down to the '**Registries** ' section and click '**Amazon ECR** ' to open the setup wizard.

   ![image-20240320-084200.png](https://docs.mend.io/__attachments/a_8fa5d3030601c93b95b9ddeff9753ad26fb54c2099b9483a5cd45d6f992b1683/image-20240320-084200.png?cb=177c45286b65f44ad44f3bd0eabc06c1)

#### The Setup Wizard

##### Step 1 - **General Details**

Fill in the **General Details** fields:  
![image-20240727-114722.png](https://docs.mend.io/__attachments/a_475207bd35d1dac8088cfd6658858a3f387a36d255a4467807cbd65e085d7269/image-20240727-114722.png?cb=1bd9ea8317d33fd8c4325fecd5147b77)

a. Display Name

b. Description (optional)

c. Environment (multi-selection is supported)

Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_1cc8f3548ceff31f25269a2536b3c61ab4e3013fdf6edb0462cc72535ceb3838/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 2 - Authentication.

##### Step 2 - **Authentication**

Fill in the required **Authentication** information:  
![image-20240727-114141.png](https://docs.mend.io/__attachments/a_7295b710aed56db3e20df32944fee1919fcb4c706fe73387ad0fe3cef677a79c/image-20240727-114141.png?cb=b4d8429d12d7c0a2db77193aabc668de)

a. Region

b. Access Key

c. Secret Key

Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_1cc8f3548ceff31f25269a2536b3c61ab4e3013fdf6edb0462cc72535ceb3838/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 3 - Configuration.

##### Step 3 - **Configuration**

Fill in the **Configuration** information to define your scan schedule:

![image-20250714-161726.png](https://docs.mend.io/__attachments/a_49378d0b8189d3b772c0f7e968e05c2f4c794c555b334ab579f41f45fe27adc8/image-20250714-161726.png?cb=9123d1ce34f22fc8bcbbc06c1058d46b)

* **Enable Schedule** - Toggle off to disable scheduling.

* **Scan Time**

* **Frequency**

* **Scan on Connect** - While toggled on, it means a scan will be triggered automatically once the integration setup is completed.

Scheduling image registry scans is crucial for maintaining the security and integrity of your container images. By default, a scan interval of *7 days* will be applied. You can change the scan interval in 1-day increments or select specific days of the week when you wish for scans to be executed.  
**Note:** After the first scan (in which the latest 10 tags are scanned), in every scheduled scan only newly pushed images from the registry or changed images will be scanned. This is because [vulnerability and package updates occur automatically](https://docs.mend.io/platform/latest/review-container-scan-findings-organization.md#Security-Updates-Cadence) in an asynchronous manner, keeping the security information up-to-date without requiring new scans.

Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_1cc8f3548ceff31f25269a2536b3c61ab4e3013fdf6edb0462cc72535ceb3838/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 4 - Summary, to view the summary of your setup as a final step before adding your registry.

##### Step 4 - Pull and Scan Inventory

Define which **repositories** and **tags** should be pulled and scanned using include/exclude filters:  
![image-20250523-132552.png](https://docs.mend.io/__attachments/a_097051f8913fd6eb07c9fec8427cdf09b3d27fb0fff8faf028108ae8a27ce17d/image-20250523-132552.png?cb=96fe7eb3350339bafc935cb5e9322af6)

**All Images** will be the default. When changing this to **Selected Images** as shown below, click **Add Conditions**to add Include and/or Exclude conditions, for both Repositories and Tags.  
![image-20250523-132537.png](https://docs.mend.io/__attachments/a_27fe1e0d670e461d54e6e5198515ed55a2adb752de0429cff81a9cee23cce59b/image-20250523-132537.png?cb=5befc6284e265b110fbdf5ebd5f5679e)

##### Step 5 - Summary

In this step, the summary of your input from steps 1-3 will be displayed. You can go back to the previous screens of the wizard to make changes, by clicking the 'Back' button at the bottom right corner of the screen. If you wish to confirm your configuration and add your registry, click the '**Done'** button:  
![image-20240727-114442.png](https://docs.mend.io/__attachments/a_98639d1fb77665f3b6831c8af34063f9b3721991e31db1e6cd30945f2f1dc8f6/image-20240727-114442.png?cb=86ffabf374c26855e33ecd78cccc0a1b)

A **Registry Added Successfully** message will pop-up at the bottom-left corner of the user interface once the integration credentials and configuration have been verified:  
![image-20240328-191507.png](https://docs.mend.io/__attachments/a_5c40e52f893bfb487daf9948b88b83aab6186225249910e5ef9a925872708ca2/image-20240328-191507.png?cb=b90ba11ef254a16c57f34fb93b0d4e76)  
**Note**: Before adding your registry, a connectivity check will be performed automatically, to ensure the credentials are valid and the registry is accessible for the integration.

## Reference

### Private ECR parameters

|------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Parameter**    | **Description**                                                                                                                                                                                                                                                                          |
| **Display Name** | Type the name of your registry. This will be displayed in the **Integrations** dashboard.                                                                                                                                                                                                |
| **Description**  | Optional. Provide any text. We recommend providing information that will help you remember the integration and/or the relevant registry.                                                                                                                                                 |
| **Region**       | Select the AWS region where your ECR is hosted. The region options are: * us-east-(1-2) * us-west-(1-2) * af-south-1 * ap-east-1 * ap-south-1 * ap-northeast-(1-3) * ap-southeast-(1-2) * ca-central-1 * eu-central-1 * eu-west-(1-3) * eu-south-1 * eu-north-1 * me-south-1 * sa-east-1 |
| **Environment**  | Label your ECR with the environments types that you manage (multiple options can be selected). The environment options are: * Production * Dev * QA * Staging                                                                                                                            |
| **Access Key**   | Provide your ECR access Key.                                                                                                                                                                                                                                                             |
| **Secret Key**   | Provide your ECR secret Key.                                                                                                                                                                                                                                                             |

### Amazon ECR resources

Visit Amazon's documentation below for more information on the topics related to the Mend private ECR integration:

* [Managing access keys (console)](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html#Using_CreateAccessKey)

* [Creating IAM policies (console)](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_create-console.html)

  * [API Reference → Actions](https://docs.aws.amazon.com/AmazonECR/latest/APIReference/API_Operations.html)

* [Adding and removing IAM identity permissions](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_manage-attach-detach.html)

---
version: "Latest"
language: "en"
---
# Configure your private Microsoft Azure Container Registry (ACR) in the Mend Platform

## Overview

The Mend container image registry scanning solution can integrate with your private ACR using your provided Azure Active Directory (AD) service principal.

## Getting it done

### Prerequisites before you scan ACR with Mend Container

* Your Mend user must be an organization administrator.

* Your Azure AD **service principal** must have the necessary access to the ACR you wish to integrate. See the **ACR authentication setup** section of this document for instructions.

* If your ACR is behind a firewall, you must allowlist the Mend IP addresses to ensure connectivity. See [IP Addresses used by Mend.io](https://docs.mend.io/platform/latest/ip-addresses-used-by-mend-io.md) for the full list.

### ACR authentication setup

To properly integrate Mend with your ACR, you will need to provide your service principal's username and password for authentication:

1. Log in to your Azure account or use the Azure CLI.

2. In Azure, create a new service principal. More information on how to do this can be found in Azure's documentation: [++Azure Container Registry authentication with service principals++](https://learn.microsoft.com/en-us/azure/container-registry/container-registry-auth-service-principal).

3. During creation, add the following permission to your service principal: `acrpull`.

   This allows the service principal to `docker pull `an image, that has not been quarantined, from the relevant registry. More information on the `acrpull` permission can be found in the ACR repository's documentation: [++ACR Roles \& Permissions++](https://github.com/Azure/acr/blob/main/docs/roles-and-permissions.md).

4. Once your service principal is created, obtain its username and password via the Azure CLI. We've provided an example of how to accomplish this from Azure's documentation below:

       ## Azure documentation example ##

       ACR_NAME=$containerRegistry
       SERVICE_PRINCIPAL_NAME=$servicePrincipal

       ACR_REGISTRY_ID=$(az acr show --name $ACR_NAME --query "id" --output tsv)

       PASSWORD=$(az ad sp create-for-rbac --name $SERVICE_PRINCIPAL_NAME --scopes $ACR_REGISTRY_ID --role acrpull --query "password" --output tsv)
       USER_NAME=$(az ad sp list --display-name $SERVICE_PRINCIPAL_NAME --query "[].appId" --output tsv)

       echo "Service principal ID: $USER_NAME"
       echo "Service principal password: $PASSWORD"

Congratulations! You are now ready to integrate your private ACR within the Mend Platform.  
**Note:** By default, the Azure service principal's password is valid for **one year**. Make sure you renew this password to keep your ACR integration with Mend up and running.

#### Set up your private ACR configuration via the Mend Platform UI

1. In the Mend Platform UI, navigate to ![image-20240319-192945.png](https://docs.mend.io/__attachments/a_6c490da1fb2b6ab85d505ede7e007250cb714b8457e2bc34658263612aa74cea/5351baa8-20ac-482b-bd0f-b9c9e9ca7971?cb=e41593bc985552bd37bd21f3f5ca4365) → **Integrations.**

2. Scroll down to the '**Registries** ' section and click '**Microsoft Azure ACR'**

   ![image-20240320-121352.png](https://docs.mend.io/__attachments/a_67cf5b6f178f245f75da3ae47fc460e2f1b3ea9fe7c71af9fc443ae5d366bd6d/image-20240320-121352.png?cb=9bfcedf0b0e4e7beaf699b2eb0fffa6f)

#### The Setup Wizard

##### Step 1 - **General Details**

Fill in the **General Details** fields:  
![image-20240727-120839.png](https://docs.mend.io/__attachments/a_907d5936c2683a35d4452604102d639198de9f9456dd83d5c88fbee8681ea1ba/image-20240727-120839.png?cb=a6b33a1e340748345b662dea5ffe3dd9)

a. Display Name

b. Description (optional)

c. Registry URL

d. Environment (multi-selection is supported)

Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_7f903b419b2f54ed5cecab2d483b12ac2ea045168cb736139d6a4ba8d0495771/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 2 - Authentication.

##### Step 2 - **Authentication**

Fill in the **Authentication** information:  
![image-20240727-120956.png](https://docs.mend.io/__attachments/a_ec9e4858343055295b1f2ef722ba214e85ee1faa9b593afcd1c933c6852e0706/image-20240727-120956.png?cb=caad807f26e88419acc53a355865a5ea)

a. Service Principal ID

b. Service Principal Password

Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_7f903b419b2f54ed5cecab2d483b12ac2ea045168cb736139d6a4ba8d0495771/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 3 - Configuration.

##### Step 3 - **Configuration**

Fill in the **Configuration** information to define your scan schedule:  
![image-20250714-161652.png](https://docs.mend.io/__attachments/a_726571d3d8dc9f203864e92c69f0ba84f7c49118011d4a577f5da6ae84e9b31d/image-20250714-161652.png?cb=9123d1ce34f22fc8bcbbc06c1058d46b)

* **Enable Schedule** - Toggle off to disable scheduling.

* **Scan Time**

* **Frequency**

* **Scan on Connect** - While toggled on, it means a scan will be triggered automatically once the integration setup is completed.

Scheduling image registry scans is crucial for maintaining the security and integrity of your container images. By default, a scan interval of *7 days* will be applied. You can change the scan interval in 1-day increments or select specific days of the week when you wish for scans to be executed.  
**Note:** After the first scan (in which the latest 10 tags are scanned), in every scheduled scan only newly pushed images from the registry or changed images will be scanned. This is because [vulnerability and package updates occur automatically](https://docs.mend.io/platform/latest/review-container-scan-findings-organization.md#Security-Updates-Cadence) in an asynchronous manner, keeping the security information up-to-date without requiring new scans.

Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_7f903b419b2f54ed5cecab2d483b12ac2ea045168cb736139d6a4ba8d0495771/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 4 - Summary, to view the summary of your setup as a final step before adding your registry.

##### Step 4 - Pull and Scan Inventory

Define which **repositories** and **tags** should be pulled and scanned using include/exclude filters:  
![image-20250523-132552.png](https://docs.mend.io/__attachments/a_daa98e1057b8fb6438ad2226667ff79667d15301fd83efe1517c1f102d531e69/image-20250523-132552.png?cb=96fe7eb3350339bafc935cb5e9322af6)

**All Images** will be the default. When changing this to **Selected Images** as shown below, click **Add Conditions**to add Include and/or Exclude conditions, for both Repositories and Tags.  
![image-20250523-132537.png](https://docs.mend.io/__attachments/a_f8b2873377574b569e40dac98b021905300996fdc9843c5b6f8dd14e3eb279a8/image-20250523-132537.png?cb=5befc6284e265b110fbdf5ebd5f5679e)

##### Step 5 - Summary

In this step, the summary of your input from steps 1-3 will be displayed. You can go back to the previous screens of the wizard to make changes, by clicking the 'Back' button at the bottom right corner of the screen. If you wish to confirm your configuration and add your registry, click the '**Done'** button:  
![image-20240727-114442.png](https://docs.mend.io/__attachments/a_d65fb73204ee948fe37126020cd6f6f8768683d8c16d4cca4979836293990cc3/image-20240727-114442.png?cb=86ffabf374c26855e33ecd78cccc0a1b)

A **Registry Added Successfully** message will pop-up at the bottom-left corner of the user interface once the integration credentials and configuration have been verified:  
![image-20240328-191507.png](https://docs.mend.io/__attachments/a_629ba173ebe90c1e7bab048c8c5082f3f20c2205bafbd638ae805b45e3539644/image-20240328-191507.png?cb=b90ba11ef254a16c57f34fb93b0d4e76)  
**Note**: Before adding your registry, a connectivity check will be performed automatically, to ensure the credentials are valid and the registry is accessible for the integration.

## Reference

### Private ACR parameters

|         **Parameter**          |                                                                    **Description**                                                                    |
|--------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Display Name**               | Type the name of your registry. This will be displayed in the **Integrations** dashboard.                                                             |
| **Description**                | Optional. Provide any text. We recommend providing information that will help you remember the integration and the relevant registry.                 |
| **Registry URL**               | Provide your ACR URL. The format of the URL typically looks like: `https://<yourregistryname>.azurecr.io`                                             |
| **Environment**                | Select the type of environment of your private ACR (multiple options can be selected). The environment options are: * Production * Dev * QA * Staging |
| **Service Principal ID**       | Provide your Azure service principal ID.                                                                                                              |
| **Service Principal Password** | Provide your Azure service principal password.                                                                                                        |

---
version: "Latest"
language: "en"
---
# Configure your private Google Artifact Registry (GAR) in the Mend Platform

## Overview

The Mend container image registry scanning solution can integrate with your private Google Artifact Registry (GAR).

## Getting it done

### Prerequisites before you scan GAR with Mend Container

* Your Mend.io user must be an organization administrator.

* As part of the setup, you will be required to authorize Mend Container to access your registry using a [++service account JSON key file++](https://cloud.google.com/container-registry/docs/advanced-authentication). A typical JSON token blob should look like this:

    {
      "type": "service_account",
      "project_id": "my_project_id",
      "private_key_id": "XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX",
      "private_key": "-----BEGIN PRIVATE KEY-----\nXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX==\n-----END PRIVATE KEY-----\n",
      "client_email": "XXXXXXXXXXXXXXX@XXXXXXXXXXXXXX.iam.gserviceaccount.com",
      "client_id": "XXXXXXXXXXXXXXXXXXXXXXXXX",
      "auth_uri": "https://accounts.google.com/o/oauth2/auth",
      "token_uri": "https://oauth2.googleapis.com/token",
      "auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
      "client_x509_cert_url": "https://www.googleapis.com/robot/v1/metadata/x509/XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX.iam.gserviceaccount.com"
    }

### Set up your private GAR configuration via the Mend Platform UI

1. In the platform UI, navigate to ![image-20240319-192945.png](https://docs.mend.io/__attachments/a_bd769e8b660887add5983cf83e0eb391a985ab70ebe80f89edd89b59f719673e/5351baa8-20ac-482b-bd0f-b9c9e9ca7971?cb=e41593bc985552bd37bd21f3f5ca4365) → **Integrations.**

2. Scroll down to the **Registries** section and click **Google Artifact Registry.**

   ![image-20251210-135812.png](https://docs.mend.io/__attachments/a_7e9a8d8d82cfa4e98d38c1d50923455f66e106715bcffcecbe44d28680717018/image-20251210-135812.png?cb=c9f39f3338b3e13b16b554645a0e8d0f)

### The Setup Wizard

#### Step 1 - **General Details**

Fill in the **General Details** fields:  
![image-20251210-140016.png](https://docs.mend.io/__attachments/a_089abf0fb9a605839d66fb35da86fd8435733181f56b6740e471de6631258885/image-20251210-140016.png?cb=1582af0c525eeb6a63024d0af8da3f8f)

a. Display Name

b. Description (optional)

c. Address - The registry endpoint, e.g., [gcr.io](http://gcr.io/), us-central1-docker.pkg.dev, etc.

d. Environment (multi-selection is supported)

Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_e0ce2d92079846188c1307765a49a3bdd8dfe9177eaa91f5dff4d22c7cadc0d4/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 2 - Authentication.

#### Step 2 - **Authentication**

Upload a [Google Cloud service account key file in JSON format](https://docs.cloud.google.com/container-registry/docs/advanced-authentication).  
![image-20251210-140526.png](https://docs.mend.io/__attachments/a_aa07f6f1f1b5bb0693a055178c1d78cf791f824ff7e1a0c65356a705c473b701/image-20251210-140526.png?cb=821a863eb28dfab9140729b274d2dd0a)

Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_e0ce2d92079846188c1307765a49a3bdd8dfe9177eaa91f5dff4d22c7cadc0d4/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 3 - Configuration.

#### Step 3 - **Configuration**

Fill in the **Configuration** information to define your scan schedule:  
![image-20250714-161652.png](https://docs.mend.io/__attachments/a_9cd73cf30466613b409ae6e55c42ad7bf57c091d3229b79780f05cf57988d006/image-20250714-161652.png?cb=9123d1ce34f22fc8bcbbc06c1058d46b)

* **Enable Schedule** - Toggle off to disable scheduling.

* **Scan Time**

* **Frequency**

* **Scan on Connect** - While toggled on, it means a scan will be triggered automatically once the integration setup is completed.

Scheduling image registry scans is crucial for maintaining the security and integrity of your container images. By default, a scan interval of *7 days* will be applied. You can change the scan interval in 1-day increments or select specific days of the week when you wish for scans to be executed.  
**Note:** After the first scan (in which the latest 10 tags are scanned), in every scheduled scan only newly pushed images from the registry or changed images will be scanned. This is because [vulnerability and package updates occur automatically](https://docs.mend.io/platform/latest/review-container-scan-findings-organization.md#Security-Updates-Cadence) in an asynchronous manner, keeping the security information up-to-date without requiring new scans.

Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_e0ce2d92079846188c1307765a49a3bdd8dfe9177eaa91f5dff4d22c7cadc0d4/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 4 - Summary, to view the summary of your setup as a final step before adding your registry.

#### Step 4 - Pull and Scan Inventory

Define which **repositories** and **tags** should be pulled and scanned using include/exclude filters:  
![image-20250523-132552.png](https://docs.mend.io/__attachments/a_a02b1d322e4fdd52b1e930d96f8ec2be5354bb67c124a792f8609a39f7dd8905/image-20250523-132552.png?cb=96fe7eb3350339bafc935cb5e9322af6)

**All Images** will be the default. When changing this to **Selected Images** as shown below, click **Add Conditions**to add Include and/or Exclude conditions, for both Repositories and Tags.  
![image-20250523-132537.png](https://docs.mend.io/__attachments/a_5dedf92ac6fef0dd2ccd5d11e864c497aee19d4cc9686177bc493df79469ac01/image-20250523-132537.png?cb=5befc6284e265b110fbdf5ebd5f5679e)

#### Step 5 - Summary

In this step, the summary of your input from steps 1-3 will be displayed. You can go back to the previous screens of the wizard to make changes, by clicking the 'Back' button at the bottom right corner of the screen. If you wish to confirm your configuration and add your registry, click the '**Done'** button:  
![image-20240727-114442.png](https://docs.mend.io/__attachments/a_0499a12683a9814603c18b5b1ec56879371e8f3df7728c26d8260a1a5aa0f49d/image-20240727-114442.png?cb=86ffabf374c26855e33ecd78cccc0a1b)

A **Registry Added Successfully** message will pop-up at the bottom-left corner of the user interface once the integration credentials and configuration have been verified:  
![image-20240328-191507.png](https://docs.mend.io/__attachments/a_e17635948e983b11446483ae985c37bc121283766aa80f357d49e3c755322f6f/image-20240328-191507.png?cb=b90ba11ef254a16c57f34fb93b0d4e76)  
**Note**: Before adding your registry, a connectivity check will be performed automatically, to ensure the credentials are valid and the registry is accessible for the integration.

---
version: "Latest"
language: "en"
---
# Configure your private JFrog Artifactory Container Image Registry in the Mend Platform

## Overview

The Mend container image registry scanning solution can integrate with your private **JFrog Artifactory** (Cloud or Self-Hosted)using your provided JFrog Artifactory user.

## Getting it done

### Prerequisites before you scan Artifactory with Mend Container

* Your Mend user must be an organization administrator.

* Your JFrog Artifactory user provided for the integration must have/be in a user group that has **read permissions** to the relevant repositories in your JFrog Artifactory instance. For more information on JFrog's permissions, please read their documentation here: [Introduction to Permissions](https://jfrog.com/help/r/jfrog-platform-administration-documentation/introduction-to-permissions).

* Docker API v2 is mandatory and must be enabled for the integration to work.

#### Additional Prerequisites for JFrog Artifactory Self-Hosted

> 1. **Expose Artifactory URL:**
>
>
>    Make your self-hosted Artifactory accessible over the internet.
>
>
>    Example: [artifactory.yourcompany.com](http://artifactory.yourcompany.com/)
>
> 2. **Open Network Access:**
>
>    1. Allow outbound access from Mend.io cloud scanners. Mend.io will provide its IP ranges as needed.
>
>    2. Confirm there are no firewall or VPN restrictions blocking access.
>
> 3. **Enable Docker Repository:**
>
>    1. Set up a local or virtual Docker repository.
>
>    2. Ensure the repository is configured to allow external Docker clients to pull images.
>
> 4. **Provide Read Access:**
>
>
>    Create a user or token with read permissions on the Docker repository.
>
>
>    An access token is preferred for enhanced security.
>
> 5. **Test the Pull:**
>
>
>    Verify that the following commands can be successfully executed:
>
>    1. ```docker login <your-artifactory-url>```
>
>    2. ```docker pull <your-artifactory-url>/<repo>/<image>:<tag>```

### Set up your private JFrog Artifactory configuration in the Mend Platform UI

1. In the Mend Platform UI, navigate to ![image-20240319-192945.png](https://docs.mend.io/__attachments/a_fff5f2c053f39f5f8d36eceda23f7317d84444e65c05fe752bbb930fdceaf7e1/e756f765-0830-4b04-8fcf-71e8fb12a46e?cb=e41593bc985552bd37bd21f3f5ca4365) → **Integrations.**

2. Scroll down to the '**Registries** ' section and click '**JFrog Artifactory'**

   ![image-20250507-140742.png](https://docs.mend.io/__attachments/a_fbd02d9e284d54f91f8d6685dda715ca99b8687a9f590c771aab312d227010ea/image-20250507-140742.png?cb=b5c9712c9e8c4e88e360fd660cf0ee81)

#### The Setup Wizard

##### Step 1 - **General Details**

Fill in the **General Details** fields:  
![image-20250507-140858.png](https://docs.mend.io/__attachments/a_134b25d74d0bda74c114b573915353fe9877d9443b9d414e939dca2d8ac2095a/image-20250507-140858.png?cb=231dba335b1e46693d18f83cda5972d4)

a. Display Name

b. Description (optional)

c. Artifactory URL

d. Environment (multi-selection is supported)

Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_752a70c72855dacd0eb45e019de6c93b5f85092145e21c0a80f9c9473975e370/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 2 - Authentication.

##### Step 2 - **Authentication**

Fill in the **Authentication** information:  
![image-20250507-141043.png](https://docs.mend.io/__attachments/a_b703d088dbc4f6c30fe68a9ba45f7787da7ce76e2eafea529aed2ef84e46dbc5/image-20250507-141043.png?cb=32a0c1907b4536c1fd972ae73945ac68)

Option 1 - User Name \& Password

Option 2 - User Name \& Access Token

Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_752a70c72855dacd0eb45e019de6c93b5f85092145e21c0a80f9c9473975e370/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 3 - Configuration.

##### Step 3 - **Configuration**

Fill in the **Configuration** information to define your scan schedule:  
![image-20250714-161804.png](https://docs.mend.io/__attachments/a_2161b293de6f8e7da0c80eb08d55e35e9157b798ff31a15b5799a113c3ec5efc/image-20250714-161804.png?cb=9123d1ce34f22fc8bcbbc06c1058d46b)

* **Enable Schedule** - Toggle off to disable scheduling.

* **Scan Time**

* **Frequency**

* **Scan on Connect** - While toggled on, it means a scan will be triggered automatically once the integration setup is completed.

Scheduling image registry scans is crucial for maintaining the security and integrity of your container images. By default, a scan interval of *7 days* will be applied. You can change the scan interval in 1-day increments or select specific days of the week when you wish for scans to be executed.  
**Note:** After the first scan (in which the latest 10 tags are scanned), in every scheduled scan only newly pushed images from the registry or changed images will be scanned. This is because [vulnerability and package updates occur automatically](https://docs.mend.io/platform/latest/review-container-scan-findings-organization.md#Security-Updates-Cadence) in an asynchronous manner, keeping the security information up-to-date without requiring new scans.

Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_752a70c72855dacd0eb45e019de6c93b5f85092145e21c0a80f9c9473975e370/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 4 - Summary, to view the summary of your setup as a final step before adding your registry.

##### Step 4 - Pull and Scan Inventory

Define which **repositories** and **tags** should be pulled and scanned using include/exclude filters:  
![image-20250523-132552.png](https://docs.mend.io/__attachments/a_3eff2b2fe782bd0ee86a69123ba256991102fc7f885971ba1ec0b5bf7ad7a0fb/image-20250523-132552.png?cb=96fe7eb3350339bafc935cb5e9322af6)

**All Images** will be the default. When changing this to **Selected Images** as shown below, click **Add Conditions**to add Include and/or Exclude conditions, for both Repositories and Tags.  
![image-20250523-132537.png](https://docs.mend.io/__attachments/a_613b58fa6466740e2815c00e0b0c3cc7c206c87bb718157ff37a886da8639c86/image-20250523-132537.png?cb=5befc6284e265b110fbdf5ebd5f5679e)

##### Step 5 - Summary

In this step, the summary of your input from steps 1-3 will be displayed. You can go back to the previous screens of the wizard to make changes, by clicking the 'Back' button at the bottom right corner of the screen. If you wish to confirm your configuration and add your registry, click the '**Done'** button:  
![image-20240727-122527.png](https://docs.mend.io/__attachments/a_ae6d2f94be4b7eac6ed39decf0a92fb28619a09ab17f3f1093edafa930e3e9be/image-20240727-122527.png?cb=86ffabf374c26855e33ecd78cccc0a1b)

A **Registry Added Successfully** message will pop-up once the integration credentials and configuration have been verified:  
![image-20240328-191804.png](https://docs.mend.io/__attachments/a_f56201a44d2182199a87342b08376d70aeaffa65b54680b8e3e55e7d1d16ea65/image-20240328-191804.png?cb=b90ba11ef254a16c57f34fb93b0d4e76)  
**Note**:

* Before adding your registry, a connectivity check will be performed automatically, to ensure the credentials are valid and the registry is accessible for the integration.

* In order to avoid scanning outdated images, our image registry integration is designed to focus on the most current data by scanning only the ***latest 10 versions*** from each repository.

## Reference

### Private JFrog Artifactory parameters

|    **Parameter**    |                                                                               **Description**                                                                                |
|---------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Display Name**    | Type the name of your registry. This will be displayed in the **Integrations** dashboard.                                                                                    |
| **Description**     | Optional. Provide any text. We recommend providing information that will help you remember the integration and the relevant registry.                                        |
| **Artifactory URL** | Provide your JFrog Artifactory Registry URL. The format of the URL typically looks like: `https://<yourregistryname>.jfrog.io`                                               |
| **Environment**     | Select the type of environment of your private JFrog Artifactory Registry (multiple options can be selected). The environment options are: * Production * Dev * QA * Staging |
| **User Name**       | Provide your JFrog Artifactory username.                                                                                                                                     |
| **Password**        | Provide your JFrog Artifactory password.                                                                                                                                     |

---
version: "Latest"
language: "en"
---
# Configure the scan engine to fetch from Mend Integration for ServiceNow (SAST vs. SCA)

**Note:** Mend integration with ServiceNow is currently in open beta. To join the beta program, please contact your Customer Success Manager at [++Mend.io++](http://mend.io/).

## Overview

The Mend.io AVR Integration for ServiceNow fetches **Applications** , **Projects** , **Code Findings (SAST)** , and **Dependency Findings (SCA)**in a predefined sequence.

Sometimes users want to fetch **only SAST** or **only SCA**. To do this, you must deactivate the unwanted integration and adjust the sequence accordingly.  
**Note:** All integrations in the sequence must belong to the **same Source Instance** . If you have multiple Mend.io platform connections (multiple Source Instances), ServiceNow generates duplicate integration sets. Ensure you update the integration under the **correct Source Instance**before making changes.

## Getting it done

### Scenario 1: Fetch Only SCA (Dependencies)

**Deactivate SAST (Code Findings)**

1. Navigate to: **Mend.io AVR Integration → Administration → AVR Integrations**.  
![image-20251210-123753.png](https://docs.mend.io/__attachments/a_ee6f70041b6384a07b49b13e0ea74d9aa38322a2fbe2a5f4634e15b62d5d96ad/image-20251210-123753.png?cb=28c0ec3caeb7a0973c2956584aee3947)

2. Add **Active** , **Next Integration** , and **Source Instance**fields to the list view -- This ensures you are modifying the correct integration set.  
![image-20251210-132950.png](https://docs.mend.io/__attachments/a_b60d8a39a0390004751bec81a60753d31dd231a906e6140a8659e456e6f922f8/image-20251210-132950.png?cb=ee3af3189701e604a446f530dcacd4d4)

3. Locate the **"Mend.io Code Findings Import"** record for the **same Source Instance**as your Application and Project imports.  
![image-20251210-133038.png](https://docs.mend.io/__attachments/a_4dac0fc8c4f89b15c3d4094f5c2b652b16568e3211f1ad8fa9cef30c13ff1141/image-20251210-133038.png?cb=5e24fb06669c42a4555019918eb5a8a3)

4. Set **Active = false**to deactivate SAST (Code Findings).  
![image-20251210-133453.png](https://docs.mend.io/__attachments/a_20e3bc34fcd5109605e1f130ffcff9d95f968448f3e943a2ce360172a609c0ff/image-20251210-133453.png?cb=ab18725a877002e147935c3891c52148)

5. Now update the sequence: ○ Find the integration record where **"Mend.io Code Findings Import"** is listed in the **Next Integration** field. (Usually **"Mend.io Projects Import"** , under the *same Source Instance*)  
![image-20251210-133521.png](https://docs.mend.io/__attachments/a_c6baa291be8d796273cd16192bce99a8ca79775b612202dba78ad4bc92dcbbfe/image-20251210-133521.png?cb=fa85dbf99ca9f06a92c639dda2be507e)

6. Open that record (e.g., *Mend.io Projects Import* ) and update the **Next Integration** to skip Code Findings: **Next Integration = Mend.io Dependency Findings Import**(Make sure this Dependency Findings record also belongs to the same Source Instance)  
![image-20251210-133823.png](https://docs.mend.io/__attachments/a_25aeed347701556b65368e3cbb8309bf55420688fe95445bad3afae36b25f6fb/image-20251210-133823.png?cb=0450ec14d85e3ca1595bc14aea02d280)

This completes the adjustment for fetching **only SCA**.  
![image-20251210-133817.png](https://docs.mend.io/__attachments/a_34e115021a46f02ccc4188443585f6605a57c2d7a10f474128b1f4eb9abdddce/image-20251210-133817.png?cb=3e361d416bd397e54274d13797ddcc62)

### Scenario 2: Fetch Only SAST (Code Findings)

**Deactivate SCA (Dependency Findings)**

1. Navigate to: **Mend.io AVR Integration → Administration → AVR Integrations**.  
![image-20251210-125616.png](https://docs.mend.io/__attachments/a_3d53d4f1b5903fb7c868f0a802a69e41f8c8f5415ef42beaa3a843e90a02299b/image-20251210-125616.png?cb=445c952ea709ef00e18ab2703df8ccdf)

2. Add **Active** , **Next Integration** , and **Source Instance**to the list view -- This ensures you work on the correct Source instance.  
![image-20251210-134208.png](https://docs.mend.io/__attachments/a_8136ff4b39c3efc3e368526e97971baa34345843a386b6a30dee61f5132683cf/image-20251210-134208.png?cb=ee3af3189701e604a446f530dcacd4d4)

3. Locate **"Mend.io Dependency Findings Import"** under the **same Source Instance**as your Applications/Projects/Code Findings Import (SAST imports).  
![image-20251210-134245.png](https://docs.mend.io/__attachments/a_35d68ae8c3f9b53a6e9c9ee9b64949735443be6538bb652c7fa91d1f2f99c539/image-20251210-134245.png?cb=5c83b778c77b51ab305f37a2ebea2953)

4. Set **Active = false**to deactivate SCA (Dependency Findings).  
![image-20251210-134311.png](https://docs.mend.io/__attachments/a_28077961b4cda03f4b3242b2abc0a40f8da0f2b2e201eeedd5f5100ff1452ac9/image-20251210-134311.png?cb=28e192b63266be575be43839661fc60f)

5. Identify the record that lists **"Mend.io Dependency Findings Import"** in its **Next Integration** field. (Typically **"Mend.io Code Findings Import"**under the same Source Instance)  
![image-20251210-134410.png](https://docs.mend.io/__attachments/a_f3b8ef1078ae10cd90d4c69f613e1ddb2e521bdbf721076ed155f2d821690056/image-20251210-134410.png?cb=dd37c013b52cff7c73ce458958598856)

6. Open that record (e.g., *Mend.io Code Findings Import* ) and remove **"Mend.io Dependency Findings Import"** from the **Next Integration**field. -- This ensures the import flow does not attempt to run SCA.  
![image-20251210-134447.png](https://docs.mend.io/__attachments/a_27e4d6ee8c0be9d6688d0655bc8619d963b34df17cf14e26b1669be5d7522551/image-20251210-134447.png?cb=a4c5ac293d2c52562fd9a0fb532859ca)

Now the integration will fetch **only SAST**.  
**Notes:**

* When multiple Mend.io **Source Instances**are configured, ServiceNow creates multiple SAST/SCA/Application/Project imports.

* Always ensure you update the integrations under **the same Source Instance**.

![image-20251210-134518.png](https://docs.mend.io/__attachments/a_09a69567d79c91f53b44879ba33ca8ad52e0e5b2d432c10c8eb47deb683f019e/image-20251210-134518.png?cb=0781352da6a4f48fe068bff0c58f36ee)

* Changing SAST in instance A and SCA in instance B will not work, as they belong to different integration chains.

---
version: "Latest"
language: "en"
---
# Configure Single Sign-On (SSO) for the Mend Platform

## Overview

Integrate your enterprise-level Single Sign-On (SSO) solutions seamlessly with the Mend Platform UI to streamline user management and enhance your organization's access security.  
**Note:**

* Enforcing SAML SSO Login **prevents your users from logging in using other methods**.

* Your SAML configuration in the Mend Platform is effective in the Legacy SCA application as well. Pay attention to this if you are configuring SAML in the Mend Platform while your users log into the **Legacy SCA application** using other methods.

## How does SSO with the Mend Platform work?

Mend supports SP-Initiated (Service Provider Initiated) Single-Sign-On using SAML version 2.0.

The identity provider (IdP) connects between the service provider and the user. Examples of IdPs include Okta and Microsoft ADFS.

## Use Case

The following illustration describes the functionality of Mend as a service provider in exchanging authentication and authorization data:  
![image-20231123-173232.png](https://docs.mend.io/__attachments/a_6bbad044cb0d53c0c2be02c0cd438087af1ecd6220bbff653be164e138cfee23/image-20231123-173232.png?cb=c3fcd54421329e964e279abd1f39c4a8)

In Mend, the system parses the SAML permissions sent from the IDP. A SAML-enabled login does not include caching.

## Getting it done

**Note:** Before getting started with the steps to configure and enable SSO for the Mend Platform, we ***strongly recommend*** reading through the **Prerequisites** and **Boundaries** sections of this article.

### Prerequisites before configuring SSO for the Mend Platform

* To set up an *account* SSO within the Mend Platform, you must be a user with account-level **Admin** role permissions.

* To set up an *organization* SSO within the Mend Platform, you must be a user with organization-level **Admin** role permissions.

* If you are transitioning from organization-level SAML configuration to account-level SAML configuration, you must first **remove the existing** SAML setup from the organization level.

  Failing to do so may result in configuration conflicts or login issues during the migration.

### Configure SSO in your IdP

To configure your IdP for SSO with the Mend Platform, you will need to create a SAML 2.0 application within your IdP's platform. Make sure to include the information below in the relevant application fields during your IdP-side configuration steps:

* **SSO URL** : `https://login-<your_mend_instance_environment>/login/callback?connection=wss-con-<orgUUID>`

  * Example: `https://login-saas.mend.io/login/callback?connection=wss-con-<orgUUID>`

  * In Okta, as an example, the same string will also be used for **'Recipient URL'** and **'Destination URL'**.

* **Audience URI** : `urn:auth0:<your_mend_environment's_subdomain>-<2nd_level_domain>:wss-con-<orgUUID>`

  * Example: `urn:auth0:saas-mend:wss-con-<orgUUID>`

### Configure SSO in the Mend Platform UI

**Note:**

* Enforcing SAML SSO Login **prevents your users from logging in using other methods**.

* Your SAML configuration in the Mend Platform is effective in the Legacy SCA application as well. Pay attention to this if you are configuring SAML in the Mend Platform while your users log into the **Legacy SCA application** using other methods.

Configuring SSO within the Mend Platform UI is done via:

++**For**++ ++***account***++ ++**SSO:**++

1. Click on **Settings** (:mp_cogicon:) → **Account** → **Account Management**:

   ![image-20251019-162310.png](https://docs.mend.io/__attachments/a_f9628a4d5d5fa2c086add30dcfc1928dac25da57c6e77f05d91de0d02e628b1a/image-20251019-162310.png?cb=cbf312743d474783d90ba41bc289b5a2)
2. Click on **SAML Integration**:

   ![image-20231030-172424.png](https://docs.mend.io/__attachments/a_59b6218afbed451b735036badcec7b67514c208f971f4801f6694ac0a5d0d4ae/image-20231030-172424.png?cb=b0101a006c6455fc4abcc356f0e215aa)
3. Within the **SAML Integration** page, click on **Edit**:

   ![image-20231030-172003.png](https://docs.mend.io/__attachments/a_d0188ab417caeaaaa13386ace20c8e4bcf476e99b37a0587a3c74153ce169406/image-20231030-172003.png?cb=bb7237b2f754eb34e1512114d4ba0c8c)

++**For**++ ++***organization***++ ++**SSO:**++

1. Click on **Settings** (:mp_cogicon:) → **Organization** → **Administration**:

   ![image-20251019-162323.png](https://docs.mend.io/__attachments/a_211adb1e03a750e5f27f397b63c5125efb62b86bccd4675d14c2b782d6449bbf/image-20251019-162323.png?cb=bb8a60c1b72affe1be81955910e4bcd5)
2. Select **SAML Integration**:

   ![image-20251019-162332.png](https://docs.mend.io/__attachments/a_8d4ffd3fc79457d94138b3e3b260f2b95383d67cfece97c2e87d96fb0be1735f/image-20251019-162332.png?cb=6551e407f8fcc3553d61e42864bb49f7)
3. Within the **SAML Integration** page, click on **Edit**:

   ![image-20231030-172003.png](https://docs.mend.io/__attachments/a_d0188ab417caeaaaa13386ace20c8e4bcf476e99b37a0587a3c74153ce169406/image-20231030-172003.png?cb=bb7237b2f754eb34e1512114d4ba0c8c)

#### Integration Information

In the **Integration Information** section, you can find the **Callback URL** , **Entity ID** and **Metadata Link** for integrating your Idp's platform with the Mend Platform. Also, you have the option to enable **IDP-Initiated SSO Behavior** .

You also have the option to **Enforce SAML SSO Login** so your users can only sign in via SAML SSO, disabling password-based login altogether.

Another option is to **automatically create users during the first SSO login**, which ensures new users are created automatically the first time they sign in with SSO. When disabled, users must be added manually by an administrator.  
**Note:** IdP-Initiated flows carry a security risk and are therefore not recommended. The recommendation is to use SP-Initiated flows whenever possible.  
![image-20251019-161805.png](https://docs.mend.io/__attachments/a_78f1679a327bb9fe4a55e6b681234fd660c2532249b23d7d457d41ca4c22ce88/image-20251019-161805.png?cb=2d05afb4469815ca74db9c5f330a8664)

#### Metadata

Updating SAML certificates can be done in one of the following ways:

* **Enter URL** - for specifying the metadata URL of the certificate XML

* **Upload File** - for uploading the certificate XML file from a location on the file system

* **Enter XML** - for pasting the certificate XML directly into the UI

![image-20251120-063816.png](https://docs.mend.io/__attachments/a_36be9f4b6b5d3a1c0f016aa0bac19ca70b6a4634015cbbfda0576005766cd58a/image-20251120-063816.png?cb=95a5635a00c9fe8e8bfd4b30971bcef0)  
**Note:** Pay attention to the expiration date (indicated at the top) and make sure to update the SAML certificate before it expires, to avoid login issues for your users.

##### Metadata URL

In the **Metadata** section, add your *IdP SAML application's Metadata URL* (the syntax of this URL varies across IdP platforms):  
![image-20240326-133031.png](https://docs.mend.io/__attachments/a_3841c85b938a2e561a2a021e5436621cc8e39f7657247814dd9bba064b38ae4d/image-20240326-133031.png?cb=74e2d76e86a5125b38f8f8dd7ce612bb)

The Mend AppSec Platform supports metadata URLs from the main identity providers, including:

* Auth0

* AWS SSO

* Duo Security

* Google

* IBM

* JumpCloud

* Microsoft Azure AD

* Okta

* OneLogin

* Ping Identity

* Salesforce

**Note:** In case a metadata link doesn't fall into one of these categories, the SAML integration creation will fail with the message: `Invalid SAML metadata URL`

###### Metadata URL Validation

Here are some notable measures the Mend Platform takes to validate the metadata supplied by the admin, to ensure a secure and smooth SAML integration experience:

* Only HTTPS URLs are accepted; invalid or unsafe sources are rejected.

* Metadata fetch is proxied, scanned, size-limited, and validated for XML/SAML schema.

* Invalid XML or missing SAML elements produce clear error messages.

* Only extracted metadata fields are stored; raw XML is discarded.

* Optional preview of parsed metadata is available after validation.

#### Email Domains

In the **Email Domains** section, click on **+ Add New Domain** to add the email domain(s) used by your organization:  
![image-20251019-161958.png](https://docs.mend.io/__attachments/a_50fa97cc5b96813c6c192a0db7b145fbaefc36b0ae15f9d5f09f693c4ffe3360/image-20251019-161958.png?cb=565bc0d409a0dccc5a91a52233f88d62)

#### Key Attributes

In the **Key Attributes** section, add the attributes from your IdP that match the Mend Platform key attributes provided (**Name, Email, Group, and Role**). You can typically find these attributes by viewing your IdP's SAML assertion. Below is a simple example:  
![image-20251019-162005.png](https://docs.mend.io/__attachments/a_c410f37ac0d792d3fb983aef5b46d5ba802a482ae16c0b9a778bfa523af57983/image-20251019-162005.png?cb=176153e02843d9a9a50cb6f46985362d)

#### Role Mapping

In the **Role Mapping** section, click on **+** **Add role** to assign SSO users to defined roles in the Mend Platform.  
![image-20251019-162055.png](https://docs.mend.io/__attachments/a_f8164b918a49d06ba600ab6775454662390d38d0b6b5c46bcb8477a89fe60a7b/image-20251019-162055.png?cb=282888d9f0e6b2ea539805d23d3860ea)

### SAML Certificate Expiration Notifications

When a certificate's expiration date is 60 days away or less, organization/account administrators will be notified of the expiration date via the following methods:

* A corresponding banner at the top of the SAML Integration page.

* A toaster message that pops up when expiration is 60, 30, 15 and 7 days away.

  * Note: In the last 7 days before expiration, the message will reappear on every login.

* Email (sent to users with the Account / Organization Admin role).

**The notifications will stop once a new certificate is uploaded or after expiration occurs.**  
![image-20251219-105517.png](https://docs.mend.io/__attachments/a_63ab49c0ef34117032c51de5d120227b4ad851b100d1deb46f589eafcf86f96f/image-20251219-105517.png?cb=bdca2aa7fd4d782d51d6baa3978b7592)
SAML Certificate Expiration Banner

---
version: "Latest"
language: "en"
---
# Configure Single Sign-On (SSO) with Microsoft Entra ID for the Mend Platform

## Overview

This is a step-by-step guide for setting up our SAML Integration offering with the Identity Provider (IdP), Entra ID. Mend offers SAML integration for two purposes:

1. Authentication for login

2. Role Management (optional)

This article covers SAML integration for Authentication only. Information regarding Role Management can be found here: [SAML 2.0 Integration](https://docs.mend.io/platform/latest/configure-single-sign-on-sso.md)

### Common SAML Terminology Referred to in Entra ID

* **Assertion Consumer Service (ACS) URL:** This is referred to as the **Reply URL**within the "Set up Single Sign-On with SAML" page when creating the Entra Enterprise application.

* **Entity ID:** This is referred to as the**Identifier** within the "Set up Single Sign-On with SAML" page when creating the Entra ID application.

* **Microsoft Entra Identifier:** This information is provided in the 4th section of the "Set up Single Sign-On with SAML"page.

* **Metadata:** For our purposes in this article, this information is provided in the 3rd section of the "Set up Single Sign-On with SAML" page.

#### Prerequisites

* Please confirm you have the proper permissions in the Azure Portal to create an Entra Enterprise Application and assign users and groups to it appropriately.

* Please confirm you are a Mend Admin in order to create the SAML integration within your Mend organization.

## Getting it done

1. In the Azure Portal, navigate or search for **"Microsoft Entra ID"** . Navigate to **"Manage"** on the left-hand side and click **"Enterprise Applications"**:

   ![image-20240820-133752.png](https://docs.mend.io/__attachments/a_215ddba13bf436fe3cebe7f55a401d7e38c11888e50c5dc0fa4652828852161c/image-20240820-133752.png?cb=fb2c26f77d59804361260e7718608eef)
2. Click **"New Application"** and select **"Create your own application"** :

   ![image-20240820-133850.png](https://docs.mend.io/__attachments/a_9c4a521723c381814e91a4048fae2947844d18b89ab1ea575c8a10814ccadd86/image-20240820-133850.png?cb=9ffd99d657ec71b23b0bd3207b4b6fa1)

   ![image-20240820-133949.png](https://docs.mend.io/__attachments/a_c088ebc9a49e1f5701a444c33b0ea639b244c744800cb45999d46817ec17b818/image-20240820-133949.png?cb=9f16434256427e34731055bd3e470768)
3. Give your application a name and select **"Integrate any other application you don't find in the gallery (Non-gallery)"** :

   ![image-20240820-134041.png](https://docs.mend.io/__attachments/a_df900113cb79d4204f455d44ea6669065cd8a170050f8ad75832fba783fdbf21/image-20240820-134041.png?cb=a9f4d2edce7fd381420d6a3951ca3f2b)
4. Select **"Set up single sign on"** and then **"SAML"**:

   ![image-20240807-211814.png](https://docs.mend.io/__attachments/a_2a00156179c70bfc729d237eb1d54289adccdf64d6b0f9f45b0127a1f3a7d45b/image-20240807-211814.png?cb=b65d47db6ddb16f816ccf52a0a65a168)  
   ![image-20240807-211853.png](https://docs.mend.io/__attachments/a_b9803dd123505eec13139970ff3e2c59d592219b52b7d5aa7c68f59b2ab7bd1e/image-20240807-211853.png?cb=c6488a3ee1ea4d108ad4f3769c268a23)
5. Enter the following information:

   1. **Identifier (Entity ID)** : `urn:auth0:<environment>:wss-con-<orgUuid>`

      1. This value can be found in the SAML Integration page on the Mend Platform, labelled as "Entity ID".

   2. **Reply URL (Assertion Consumer Service URL)** : `https://login-<environment>/login/callback?connection=wss-con-<orgUUid>`

      1. This value can be found in the SAML Integration page on the Mend Platform, labelled as "Callback URL".

   3. If you would like to do role and group mapping, then set the appropriate claims in the **"Attributes \& Claims"** section.

The **Sign On URL** is only required for SP-initiated login. Use your Mend Platform URL for this field if needed.

6. Copy the **"App Federation Metadata URL"** and save that in a spot for later.

7. Now, heading over to the Mend Platform, access the Mend organization that you wish to integrate with SAML and navigate to Configure → Administration → **SAML Integration** sidebar option:

   ![image-20241103-130918.png](https://docs.mend.io/__attachments/a_6f68033d5b063b58c6a73bbfdcb5d89019e6aab923d39a2a89743313f96cf630/image-20241103-130918.png?cb=db673aa62b51e6298fdd8051f0c3c7a7)
8. Within the SAML Integration tab, you will see the following required settings:

   1. **Signing Certificate URL** : This is going to be the Metadata URL under the **Sign On**section of the SAML Application we have just created.

      ![image-20240326-132524.png](/__attachments/a_aaa35c309ea8ae4908f3a946055d78ea763d72dc880084fa53cf0b4b2c1f940b/image-20240326-132524.png?cb=8c8df165903484b8692f93960d842cfc)

      The signing certificate URL will be in the format: `https://login.microsoftonline.com/<tenant-id>/federationmetadata/<federation-version>/federationmetadata.xml?appid=<app-id>`
   2. **Email Domains section:** In the **Email Domains** section add the email domain(s) used by your organization.

      ![image-20240820-160203.png](/__attachments/a_4d834cf4010119ff3af47b299b3e720ce0b4549a293600400ea7beb3ec41e4ac/image-20240820-160203.png?cb=845a2a93d2c4e04db978e27298034840)
   3. **Key Attributes section** : In the **Key Attributes** section, add the attributes from your IdP that match the Mend Platform key attributes provided (**Name, Email, Group, and Role** ). These were set earlier when creating the **Enterprise Application**. Below is a simple example:

      ![image-20240326-132537.png](/__attachments/a_33c8b0cbdb1021c1e4a456b907a9c50530105084a8bb1c5ca253c82856a2f791/image-20240326-132537.png?cb=a8e06c4c075706cc7b5b2d95279cade6)

      These fields would typically be set as follows:

      Name = givenname

      EmailAddress = emailaddress

      Group = \<your group claim\> (typically in the format of a URL)

      Role = \<your role claim\> (typically in the format of a URL)
   4. **Group Claims:**To ensure that group names are human-readable within the Mend Platform, configure Azure Entra ID to emit Cloud-only group display names.

      ![image-20250309-221412.png](/__attachments/a_a104c8575129176a2c4a2447ea9d64b5beb4b83f33c477fb5c6b78fe1d401cfa/image-20250309-221412.png?cb=5cfc3332192be077d22e5dc4ecfdeaf8)

      After saving, you will get your claim name (in the format of a URL) which you would then put in the Key Attributes section above.
   5. Depending on your Entra ID SSO configuration, retrieve either the **group name** or **group ID** of the group that is sent in the SAML Assertion and enter this into Mend Platform:

      * If your configuration sends **group names** , use the **exact group name** as shown in Entra ID.

      * If your configuration sends **group IDs**, use the corresponding group ID value.

        ![83756be3-f932-476b-b892-8abbb9df15b0#media-blob-url=true&id=b9e397ad-164d-450a-b849-628a17defee1&collection=&contextId=108315&mimeType=image%2Fpng&name=image-20230224-170245.png&size=24633&width=865&height=626&alt=](/__attachments/a_34e392cde2421957dfe517cbef25473e9cf4e1186bcc534705885074659d60df/83756be3-f932-476b-b892-8abbb9df15b0%23media-blob-url=true&id=b9e397ad-164d-450a-b849-628a17defee1&collection=&contextId=108315&mimeType=image%252Fpng&name=image-20230224-170245.png&size=24633&width=865&height=626&alt=?cb=450e5552c50c0bdb781b687f4fbd236c)
   6. **Role Mapping Section** : In the **Role Mapping Section**, enter the group ID/group name retrieved from the previous step and map them to the groups created inside the Mend Platform.

      ![image-20240820-170651.png](/__attachments/a_ad619598a6b41fb40a3034bbe11ff0936df618735f709d431b066e44d0f7cc8f/image-20240820-170651.png?cb=0d76f752fc655dc9afb8d0f2253c37c5)
9. Once finished, select **Save** in the top right-hand corner of the page and the settings will be applied, and a prompt informing you the settings have been successfully saved will appear, confirming the integration has been successful.

10. An assigned user or group of the application will be able to use the Mend Platform by specifying hte relevant `<environment>` URL in the browser (e.g. <https://saas.mend.io/app>).

---
version: "Latest"
language: "en"
---
# Configure Single Sign-On (SSO) with Okta for the Mend Platform

## Overview

This is a step-by-step guide for setting up our SAML Integration offering with the Identity Provider (IdP), Okta. Mend offers SAML integration for two purposes:

1. Authentication for login

2. Role Management (optional)

This article covers SAML integration for Authentication only. Information regarding Role Management can be found here: [SAML 2.0 Integration](https://docs.mend.io/platform/latest/configure-single-sign-on-sso.md)

### Common SAML Terminology Referred to in Okta

* **Assertion Consumer Service (ACS) URL:** This is referred to as the **Single sign on URL**within the Configure SAML page when creating the Okta application.

* **Mend Entity ID:** This is referred to as the**Audience URI (SP Entity ID)** within the Configure SAML page when creating the Okta application. This is also referred to as the **Audience Restriction** setting within the General → SAML Settings of your created Okta application.

* **Okta Entity ID:** This information is provided via the **Identity Provider Issuer**setting within the Sign On → View Setup Instructions page of your created Okta application.

* **Metadata:** For our purposes in this article, this information is provided via the **View SAML setup instructions**option within the Sign On tab of your created Okta application.

#### Prerequisites

* Please confirm you have the proper permissions to create an application within your Okta organization.

* Please confirm you are a Mend Admin in order to create the SAML integration within your Mend organization.

## Getting it done

1. Within the Okta application, navigate to the Applications → **Applications** tab:  
![image-20240326-131626.png](https://docs.mend.io/__attachments/a_2a1aaec2b9549a73c0d6bf59c442810dc305162b60d8e508156853a07d23fb53/image-20240326-131626.png?cb=12a0b85a7997d54bfb59fe854e218d78)

2. Within the **Applications** page, click on **Create App Integration:**  
![image-20240326-131651.png](https://docs.mend.io/__attachments/a_357ea4a66e3b8a9b5482e85018cce1b2727ee8f2b9963dc6a4179ebfa4f92e4d/image-20240326-131651.png?cb=ad0c15c8363845ce7168a239f3d98123)

3. A pop-up window will appear, asking you to select a Sign-in method. Select the **SAML 2.0** option, then click **Next**:  
![image-20240326-132033.png](https://docs.mend.io/__attachments/a_25d5e3cd7c9b00e6858c89fecd8e805df669b175ed139e6a6633fab5b2825e81/image-20240326-132033.png?cb=211be8b600897de6e0ed7fb2185a5e06)

4. This will bring you to the **General Settings** page, where it will ask you to name the application and add an App logo. We recommend naming it Mend for consistency, as seen in the screenshot here:

5. This will bring you to the second step, the Configure SAML page. Here, it will ask you for the SAML configuration from the Mend side. Please see the required information below:

   ![image-20240326-132055.png](https://docs.mend.io/__attachments/a_1edcaad48a19615bce3df93362737b8b69fa3f1d5b6cda9fd0d7a92425ac28a4/image-20240326-132055.png?cb=7615a8ab324c17de34aac6579929ddcd)

- **Single sign-on URL:** `https://login-<environment>/login/callback?connection=wss-con-<orgUUid>`  
The Single sign-on URL can be found in the SAML Integration page on the Mend Platform, labelled as 'Callback URL'.

- **Audience URI (SP Entity ID):** `urn:auth0:<environment>:wss-con-<orgUuid>`  
The Audience URI can be found in the SAML Integration page on the Mend Platform, labelled as 'Entity ID'.

Since this test Organization is in our SaaS environment, my SAML settings in Okta will look like this:  
![image-20240326-132119.png](https://docs.mend.io/__attachments/a_b19e4f52e9d3a1ef21fe6d7ca0e6248321075bb010845c4cdb25878439e78627/image-20240326-132119.png?cb=0700b1cc1631129512899dbdde1388a8)

6. Scroll down to the bottom of the page and click **Next**.

7. We are now at the last step of creating the Mend application in Okta, the Feedback page. Since you are creating an internal application, you will want to select the "I'm an Okta customer adding an internal app" option, as seen here:

![image-20240326-132150.png](https://docs.mend.io/__attachments/a_f17021cc8ef1d2e687f341634f6966f287a9d30b9c2bc3d974bb832e1196fc1a/image-20240326-132150.png?cb=dc4a60145c890cb4c20b3c37b2562075)

The rest of the information here is optional to fill in. Scroll down to the bottom of this page and click **Finish.**

8. This will open up the **Sign On** tab of your newly created Mend application. You will want to scroll down until you see the **Metadata Details** section; keep this information in mind for later:

   ![image-20240326-132340.png](https://docs.mend.io/__attachments/a_0e0f61ee16b63d918437617642d3766c57a3a9a1ecd56ac5839bf46d0a951081/image-20240326-132340.png?cb=6059919a1d8acade094cbe986b3ca9d4)
9. Now, heading over to the Mend Platform, access the Mend organization that you wish to integrate with SAML and navigate to Configure → Administration→ **SAML Integration** sidebar option:

   ![image-20240326-132215.png](https://docs.mend.io/__attachments/a_07dabc19adc036e3a91f545649c7336184cbd13380f96cd194f46538ccd271e6/image-20240326-132215.png?cb=c5e345306280b6eae64ee0b56bcba151)
10. Within the SAML Integration tab, you will see the following required settings:

a. **Signing Certificate URL** : This is going to be the Metadata URL under the **Sign On**section of the SAML Application we have just created.  
This will be in the format https://dev-\<Unique-OKTA-ID\>.okta.com/app/\<Unique-SAML-Key\>/SSO/SAML/Metadata  
![image-20240326-132524.png](https://docs.mend.io/__attachments/a_996262b8920baff3f629ac1da1aa7d89294bd7e9a0a3a5a9b34f6b9be7825d6e/image-20240326-132524.png?cb=8c8df165903484b8692f93960d842cfc)

b. **Email Domains section:** In the **Email Domains** section add the email domain(s) used by your organization:  
![image-20240326-132531.png](https://docs.mend.io/__attachments/a_c2d173ff0abf08a071eeb99b91682980d8cada1708784850b07effbb917a18d6/image-20240326-132531.png?cb=91826b82f34442daecc4f103638d1329)

c. **Key Attributes section** : In the **Key Attributes** section, add the attributes from your IdP that match the Mend Platform key attributes provided (**Name, Email, Group, and Role**). You can typically find these attributes by viewing your IdP's SAML assertion. Below is a simple example:  
![image-20240326-132537.png](https://docs.mend.io/__attachments/a_41d7b49fc87ef704602c9706dcad3282cf24fd8d022528046baa7000d363b44c/image-20240326-132537.png?cb=a8e06c4c075706cc7b5b2d95279cade6)

d. **Role Mapping Section:** In the **Role Mapping Section,**select the groups that are defined in Okta and map them to the groups created inside the Mend Platform.  
![image-20240326-132552.png](https://docs.mend.io/__attachments/a_67aa0dd9614d58b5db23f3321ddc42ac109f6661b54b6dd7af9974ad44ef3859/image-20240326-132552.png?cb=1bb87535d89dd41eb2ce2b7447765c09)

11. Once finished, select **Save** in the top right-hand corner of the page and the settings will be applied, and a prompt informing you the settings have been successfully saved will appear, confirming the integration has been successful.

12. An assigned user of the application will be able to use the Mend Platform, by specifying the relevant `<environment>` URL in the browser (e.g. https://saas-eu.mend.io)

### Mend Platform and Okta (SSO)

This video provides a brief overview and demonstrates how to configure Single Sign-On (SSO) with Okta for the Mend Platform.

---
version: "Latest"
language: "en"
---
# Configure the Mend CLI for Container Images

## Overview

Configuring the Mend CLI for a Container Image scan can be done via command line parameters.  
![:light_bulb_on:](https://docs.mend.io/__attachments/a_421ca70b6fef34ea37ab3303b88dbd585aa298da1b4522dede6b97f8f3841ea7/atlassian-light_bulb_on?cb=485b9fcaee6e0d0eefa559cab514727e)  
**Tip** : For inline assistance, use the `mend image -h` or `mend image --help` commands.

## Getting it done

### Configure the Mend CLI Container Image scan via command line parameters

You can configure the Mend CLI Container Image scan at runtime by adding flags to the `mend image` command. The usage of the `mend image` command is as follows:

    mend image <image_name[:image_tag]> [flags]

![CN_config.gif](https://docs.mend.io/__attachments/a_67d86a0897fbaf944f59aad1e9d001fbffa32e3f1044a20968db51293b9d8cf0/CN_config.gif?cb=7ff4f8729d59ada23fed9492a6d86234)

### Getting Started Examples

    # Getting started quickly
    mend image <image:tag>

    # Scanning tar format images
    mend image --tar myimage.tar

    # Adding Scope to the scanned image (To be reflected in Mend UI)
    mend image <image:tag> --scope "*//Test-Application//MyProject"

    # export results via the CLI
    ## json export
    mend image <image:tag> --format json --filename ./image_results.json

    ## sbom (spdx-json) export
    mend image <image:tag> --format spdx-json --filename ./image_results_sbom.json

    # CLI Output filtering (terminal output only)
    ## filter by severity
    mend image <image:tag> --filter critical,high

    ## filter out base layers
    mend image <image:tag> --exclude-base-layers

## Reference

### Mend CLI Container Image parameters

#### Mend CLI Container Image - General scan parameters

|      **Parameter**       |                                                                                                                                                                                                                                                                                                                                            **Description**                                                                                                                                                                                                                                                                                                                                             |                                                **Mend CLI Default Behavior**                                                |
|--------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------|
| `--basedir`              | **Optional.** Provide an alternative location for the local image download function of the Mend CLI scan. The format is: mend image <image_name[:image_tag]> --basedir /path/to/your/directory **Note:** * Regardless of the `--basedir` parameter, the full image tarball is always temporarily saved in the system's `/tmp` directory for SBOM analysis. If `/tmp` has limited space, the scan may fail. * This flag is to be set on a per-scan basis and is most appropriate for scanning larger images that may impact the space where the .mend folder resides. * This parameter is for the scan function only. The .mend folder will still remain and includes all its subfolders, i.e. logging. | This flag is committed by default. The Mend CLI scans your container images using the .mend folder.                         |
| `--tar`                  | **Optional**. Scan the specified container image TAR file with the Mend CLI. ***Note*** *: the tar file should include a .tar suffix*                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | This flag is omitted by default. The Mend CLI scans container images via the `imagename:tag `format.                        |
| `--local-pull`           | Pull Docker images from the local machine only, bypassing remote pulls.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | The Mend CLI pulls Docker images from a remote registry, according to the URL, or from Docker Hub in case of public images. |
| `--skip-security-checks` | **Optional.** A flag of type *string* allowing users to select which security checks will be skipped. Options: `secret`, `reachability`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | No security checks will be skipped.                                                                                         |

#### Mend CLI Container Image - Log parameters

|                        **Parameter**                        |                                                                                                                                                                                                                                                                                                                                                                  **Description**                                                                                                                                                                                                                                                                                                                                                                   |                                     **Mend CLI Default Behavior**                                     |
|-------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------|
| **Environment Variable** : `MEND_BASEDIR` / `MEND_BASE_DIR` | **Optional**. Select a different directory to store the CLI's binaries, logs and configuration files.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | The default location for the CLI's binaries, logs and configuration files is `~/.mend`.               |
| **Environment Variable:** `MEND_LOG_LEVEL`                  | **Optional**. Define the verbosity of the Mend CLI scan log files. The available values are: * `INFO` - Includes basic scan behavior. * `DEBUG` - Includes verbose information that is needed for diagnosing issues. * `WARNING` - Includes unexpected behaviors that happened during the CLI scan, but it was still able to complete successfully. * `ERROR` - Includes information on CLI functionalities that are not working and are preventing it from working properly. **Note:** * The `MEND_LOG_LEVEL` variable only impacts the generated log file and does not affect the terminal output of the CLI. * ***For troubleshooting, we recommend setting the*** `MEND_LOG_LEVEL`***to*** `DEBUG`***as it provides the most log verbosity.*** | * The Mend CLI log files are set to the `INFO` log-level value. * Successful scan logs are not saved. |

#### Mend CLI Container Image - Policy parameters

|  **Parameter**  |                                                                                          **Description**                                                                                           |                                                                                                                       **Mend CLI Default Behavior**                                                                                                                       |
|-----------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| `--fail-policy` | **Optional** . Enable the Mend CLI policy check to fail the scan if a container image component is found that violates a policy defined within your Mend organization, returning an `Exit Code 9`. | The policy check is enabled and findings are provided in the Cloud Native UI. To show policy violations in the CLI terminal output, make sure to add the "`--show policy`" flag to your scan command. The Mend CLI scan does not fail, even if a policy violation occurs. |

#### Mend CLI Container Image - Report parameters

| **Parameter** |                                                                                                                                                                      **Description**                                                                                                                                                                       | **Mend CLI Default Behavior**  |
|---------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------|
| `--filename`  | **Optional** . Generate a report locally of the Mend CLI Container Image scan results using the defined file name. The `--filename` and `--format` parameters are used together for the creation of this file. When used alone, a .txt file will be created.                                                                                               | Report generation is disabled. |
| `--format`    | **Optional** . When used together with `--filename`, define the format of the locally generated report file. When used alone, the output will be printed to the terminal. The supported values are: * `json` * `sarif` * `xml` **SBOM export: (CycloneDX, SPDX)** * cyclonedx-xml * cyclonedx-json * spdx-json * spdx-tv * spdx-yaml * spdx-csv * spdx-xml | Report generation is disabled. |

**Examples**

    # SARIF export to a file
    mend image alpine --format sarif --filename ./alpine-sarif.sarif

    # SPDX SBOM export, json format
     mend image alpine --format spdx-json --filename ./alpine-spdx.json

#### Mend CLI Container Image - Terminal view parameters

|     **Parameter**      |                                                                                                                                                                                    **Description**                                                                                                                                                                                     |                                                                    **Mend CLI Default Behavior**                                                                    |
|------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| `--exclude-base-layer` | **Optional**. Filter out security findings from the base layers of the container image, allowing you to focus only on your application layers when reviewing your results in the CLI. **Note:**This behavior only affects the Mend CLI terminal output. The full image scan results are still uploaded to the Cloud Native Application.                                                | The CLI terminal output displays the full image scan results (base + application layers).                                                                           |
| `--filter`             | **Optional** . Filter vulnerability results by the [CVSS score severity](https://www.first.org/cvss/v3.0/specification-document#Qualitative-Severity-Rating-Scale) value. The supported values are: * `critical - `CVSS 3 score of 9.0 - 10.0 * `high - `CVSS 3 score of 7.0-8.9 * `medium - `CVSS 3 score of 4.0-6.9 * `low - `CVSS 3 score of 0.1-3.9 * `none` - CVSS 3 score of 0.0 | All vulnerability severity levels are shown in the scan results.                                                                                                    |
| `-h, --help`           | **Optional** . Display the available parameters for the `mend image` command.                                                                                                                                                                                                                                                                                                          | N/A                                                                                                                                                                 |
| `--non-interactive`    | **Optional**. Mend CLI will run in non-interactive mode, suppressing the use of colors, progress bar, and any other graphic features in STDOUT.                                                                                                                                                                                                                                        | Mend CLI output to STDOUT includes the use of colors and progress bars, which are irrelevant in non-interactive sessions and may cause issues in some environments. |
| `--show`               | **Optional.** Define a comma-separated list of the types of security findings you want to display in your terminal output. The available values are: * `vuln` * `secret` * `license` * `policy`                                                                                                                                                                                        | `vuln,secret`                                                                                                                                                       |

#### Mend CLI Container Image - Upload parameters

|       **Parameter**        |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                    **Mend CLI Default Behavior**                                                                                                                                                                                                                                                                                                                                                                    |
|----------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| `--no-upload`              | **Optional.**Run the Mend CLI scan offline. This parameter disables the upload of the scan results to the Mend Application.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | The Mend CLI will update your results within the Mend Application → Cloud Native UI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| `-s, --scope`              | **Optional**. Set the scan scope for your image by specifying the hierarchy for the Mend Cloud Native UI. The supported formats are: * **Full hierarchy** : `-s ORG//APP//PROJ` * **Partial hierarchy** : `-s APP//PROJ` * **Single hierarchy** : `-s PROJ` Examples of `--scope` configuration: * Application-Project scope: mend image my:image -s MyApp//MyProj * Org-Application-Project scope with spaces: mend image my:image -s "My Org//My App//My Proj" `*` can be used as a wildcard to autocomplete the scope by the authentication context of the user, for example: mend image <Image:Tag> -s "*//My-App//My-Proj" For Mend CLI scans that do not update the Mend Application, the `--scope` parameter is still used to direct the Mend CLI on the scope to use for the policy check. **Notes:** * Only organization administrators can set scopes and view the Cloud Native UI. * Non-org admin users can still scan images with the Mend CLI, but won't have their results sent to the Cloud Native UI if `--scope` is set. * As a result of running a Mend CLI scan with the `--scope` parameter, an empty project with the same name is also created in the Mend SCA UI. Deleting this project in the Mend SCA UI will delete the project within the Cloud Native UI. * If your Org/App/Proj names include spaces, make sure to set the `--scope` value within commas ("`My Project`"). * You are able to set the Org scope to any Mend organization that the current user signed in (via `mend auth login`) has access to. * If you set an application or project name in `--scope` that does not exist in the organization before the run, it will be created in the Mend Cloud Native UI after the Mend CLI completes the scan. | Within the Mend Cloud Native UI, scans are tiered under an organization → application → project hierarchy. If `--scope` is not set, the scan results will be sent and categorized within the Mend Cloud Native UI as follows: * The **organization** currently logged into from the `mend auth login` command setup. ![:light_bulb_on:](https://docs.mend.io/__attachments/a_421ca70b6fef34ea37ab3303b88dbd585aa298da1b4522dede6b97f8f3841ea7/atlassian-light_bulb_on?cb=485b9fcaee6e0d0eefa559cab514727e) **Tip** : Use the Mend CLI `mend auth info` command to see what organization you are connected to. * An **application** will be created and named after the image's `<Registry-Name>/<RepoName`\>. * A **project** will be created and named after the image's `<RepoName>`. |
| **Command Line:** `--tags` | **Optional** . Add tag(s) to the scanned project/application in the `key:value` format. Example: `--tags "version:1.2.3, project:auth-service"` Custom tags are displayed in the UI at the scan level and reflect the last scan's tags at the project level, for all scan engines (e.g., SCA, SAST etc.) * Maximum number of tags allowed per scan - **Unlimited** * Maximum length for each tag - **Unlimited** * Maximum length for all tags combined - **Unlimited** **Note:**Only applicable for the Mend AppSec Platform.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | No label applied                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |

#### Mend CLI Container Image - Offline parameters

*Container Reachability* is not available in **local scan mode.**

++**Offline local scan**++  

|   **Parameter**    |                                                                            **Description**                                                                            |      **Mend CLI Default Behavior**      |
|--------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------|
| `--local`          | **Optional** . Save your scan results locally. The default file is saved in the ***.mend*** folder. Specific path can be defined using the **--export-results** flag. | Scan results will not be saved locally. |
| `--export-results` | **Optional.** To be used with the `--local` flag to save the scan results locally in the machine.                                                                     |                                         |

**Usage Example:**

    # Save scan results locally (offline scan mode)
    mend image alpine --local --export-results ./alpine-scan

**Local Scan output:** the following message should appear `Scan completed in local mode. Results file saved to: <export-file-path> `

`SBOM file saved to: <export-file-path>`

++**Upload Offline local scan results**++  

| **Parameter** |                                                                     **Description**                                                                      |                 **Mend CLI Default Behavior**                 |
|---------------|----------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------|
| `--update`    | **Optional** . Update the Mend application with your scan results. Should be followed by the **--file** flag to specify the specific local scan results. | The Mend application will get updated with your scan results. |
| `--file`      | **Optional**. Specify a path to the local scan results file.                                                                                             |                                                               |

**Usage Example:**

    # Save scan results locally (offline scan mode)
    mend image alpine --local --export-results ./alpine-scan

    # Upload offline scan results
    mend image --update --file ./alpine-scan --scope "*//alpine-base//alpine"

Once the results are uploaded, you'll get a scan summary print to the terminal with the scan statistics.

**Default scope:** Application = `My Product`, Project= `<full-image-name>`

To control the scope, use the `--scope` flag

### Mend CLI Container Image-supported distributions

The following distributions are supported by the Mend CLI for Container Image scans:  

|                    **Distribution**                     |                                                                                                                                                                                                                         **Supported Versions**                                                                                                                                                                                                                         |           **Mend-supported detection**           |
|---------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------|
| AlmaLinux                                               | * [Alma Linux 8](https://wiki.almalinux.org/release-notes/#almalinux-8) * [Alma Linux 9](https://wiki.almalinux.org/release-notes/#almalinux-os-9)                                                                                                                                                                                                                                                                                                                     | * Vulnerability detection * OS license detection |
| Alpine                                                  | * [Alpine 2](https://www.alpinelinux.org/releases/) * [Alpine 3.0](https://www.alpinelinux.org/releases/)                                                                                                                                                                                                                                                                                                                                                              | * Vulnerability detection * OS license detection |
| Amazon Linux                                            | * [Amazon Linux 1 (AMI)](https://aws.amazon.com/amazon-linux-ami/) * [Amazon Linux 2](https://aws.amazon.com/amazon-linux-2/?amazon-linux-whats-new.sort-by=item.additionalFields.postDateTime&amazon-linux-whats-new.sort-order=desc) * [Amazon Linux 2022](https://docs.aws.amazon.com/linux/al2022/release-notes/relnotes.html)                                                                                                                                     | * Vulnerability detection * OS license detection |
| Azure Linux (CBL-Mariner)                               | * 1.0 * 2.0 * 3.0                                                                                                                                                                                                                                                                                                                                                                                                                                                      | * Vulnerability detection * OS license detection |
| CentOS                                                  | * [CentOS 6](https://wiki.centos.org/Manuals/ReleaseNotes/CentOS6.0) * [CentOS 7](https://wiki.centos.org/action/show/Manuals/ReleaseNotes/CentOS7.2009?action=show&redirect=Manuals%2FReleaseNotes%2FCentOS7) * [CentOS 8](https://wiki.centos.org/action/show/Manuals/ReleaseNotes/CentOS8.2111?action=show&redirect=Manuals%2FReleaseNotes%2FCentOSLinux8)                                                                                                          | * Vulnerability detection * OS license detection |
| Debian                                                  | * [Debian 7 (wheezy)](https://www.debian.org/releases/wheezy/) * [Debian 8 (jessie)](https://www.debian.org/releases/jessie/) * [Debian 9 (stretch)](https://www.debian.org/releases/stretch/) * [Debian 10 (buster)](https://www.debian.org/releases/buster/) * [Debian 11 (bullseye)](https://www.debian.org/releases/bullseye/) * [Debian 12 (bookworm)](https://www.debian.org/releases/bookworm/) * [Debian 13 (trixie)](https://www.debian.org/releases/trixie/) | * Vulnerability detection * OS license detection |
| Distroless                                              | All versions of Distroless are supported.                                                                                                                                                                                                                                                                                                                                                                                                                              | Vulnerability detection                          |
| Oracle Linux                                            | * [Oracle Linux 5](https://yum.oracle.com/oracle-linux-5.html) * [Oracle Linux 6](https://docs.oracle.com/en/operating-systems/oracle-linux/6/) * [Oracle Linux 7](https://docs.oracle.com/en/operating-systems/oracle-linux/7/) * [Oracle Linux 8](https://docs.oracle.com/en/operating-systems/oracle-linux/8/) * [Oracle Linux 9](https://docs.oracle.com/en/operating-systems/oracle-linux/9/)                                                                     | * Vulnerability detection * OS license detection |
| openSUSE                                                | * [Leap 15](https://en.opensuse.org/Archive:15.0) * [Leap 42](https://en.opensuse.org/Archive:42.1) * [Tumbleweed](https://en.opensuse.org/Portal:Tumbleweed)                                                                                                                                                                                                                                                                                                          | * Vulnerability detection * OS license detection |
| PhotonOS                                                | * [Photon 1](https://vmware.github.io/photon/assets/files/html/1.0-2.0/) * [Photon 2](https://vmware.github.io/photon/assets/files/html/1.0-2.0/) * [Photon 3](https://vmware.github.io/photon/docs-v3/) * [Photon 4](https://vmware.github.io/photon/docs-v4/) * [Photon 5](https://vmware.github.io/photon/docs-v5/)                                                                                                                                                 | * Vulnerability detection * OS license detection |
| Red Hat Enterprise Linux (RHEL)                         | * [RHEL 5](https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/5) * [RHEL 6](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6) * [RHEL 7](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7) * [RHEL 8](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8) * [RHEL 9](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9)                                    | * Vulnerability detection * OS license detection |
| Rocky Linux                                             | * [Rocky Linux 8](https://docs.rockylinux.org/release_notes/#rocky-8) * [Rocky Linux 9](https://docs.rockylinux.org/release_notes/#rocky-9)                                                                                                                                                                                                                                                                                                                            | * Vulnerability detection * OS license detection |
| SUSE Linux Enterprise Server (SLES)                     | * [SLES 11](https://www.suse.com/support/kb/doc/?id=000019587#SLES11) * [SLES 12](https://www.suse.com/support/kb/doc/?id=000019587#SLES12) * [SLES 15](https://www.suse.com/support/kb/doc/?id=000019587#SLE15) * Micro 5.0-5.4                                                                                                                                                                                                                                       | * Vulnerability detection * OS license detection |
| Ubuntu                                                  | All [Canonical-maintained](https://ubuntu.com/) versions of Ubuntu are supported.                                                                                                                                                                                                                                                                                                                                                                                      | * Vulnerability detection * OS license detection |
| [Wolfi](https://github.com/wolfi-dev/wolfictl/releases) | N/A                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | * Vulnerability detection * OS license detection |

### Mend CLI Container Image-supported registries

![:light_bulb_on:](https://docs.mend.io/__attachments/a_421ca70b6fef34ea37ab3303b88dbd585aa298da1b4522dede6b97f8f3841ea7/atlassian-light_bulb_on?cb=485b9fcaee6e0d0eefa559cab514727e)  
**Tip** : Looking for our private container image registry integration? Visit our documentation: [Integrate your private container image registries with Mend](https://docs.mend.io/legacy-sca/latest/integrate-private-registries-with-mend.md).

**Notes:**

* **Supported image frameworks** : docker, [OCI](https://opencontainers.org/)

* If the image name is not locally available, Mend CLI checks [++DockerHub++](https://hub.docker.com/) by default and pulls the version (tag) of that image from the Docker registry.

* In case the full image URL is presented, the scanner will pull the image from the specified source. For example:

      mend image mcr.microsoft.com/mssql/server:2022-latest

  Will pull the image from the Microsoft Public Registry.
* **Required** : If you are scanning an image from a private registry, you will need to connect to the registry beforehand with the `docker login `command before the Mend CLI scan and have` `[Docker daemon](https://docs.docker.com/get-started/overview/#the-docker-daemon) running.

* Local scans can be done with or without a Docker Daemon running, if the daemon is up, it should be with the default socket open.

### Mend CLI Container Image-supported languages

The following runtime environments, frameworks, and languages are supported by the Mend CLI for Container Image scans:

* JavaScript (Node.js)

* C/C++ (Conan)

* C# (.NET framework)

* Go

* Java

* PHP

* Python

* Ruby

### Mend CLI Container Image exit codes

**Note** : For a comprehensive overview of Mend CLI Container Image exit codes, please refer to our [Mend CLI Exit Codes article](https://docs.mend.io/platform/latest/mend-cli-exit-codes.md).

---
version: "Latest"
language: "en"
---
# Configure the Mend CLI for IaC

## Overview

Configuring the Mend CLI for a IaC scan can be done via command line parameters.

## Getting it done

### Configure the Mend CLI IaC scan via command line parameters

You can configure the Mend CLI IaC scan at runtime by adding flags to the `mend iac` command. The usage of the `mend iac` command is as follows:

    mend iac my-iac-folder [flags]

![2024-08-07_15-08-34 (1)-20240807-190907.gif](https://docs.mend.io/__attachments/a_4eb83d01ca6a56209377459821578b1178c8d17699cc62a9e014e3e82ab2eb6a/2024-08-07_15-08-34%20(1)-20240807-190907.gif?cb=8394273a8b1fd5ef0905cd558f5b062c)

## Reference

### Mend CLI IaC parameters

#### Mend CLI IaC - Report parameters

|         **Parameter**          |                                                                                                            **Description**                                                                                                            | **Mend CLI Default Behavior**  |
|--------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------|
| **Command Line:** `--filename` | **Optional** . Generate a report locally of the Mend CLI Container Image scan results using the defined file name. The `--filename` and `--format` parameters are used together for the creation of this file.                        | Report generation is disabled. |
| **Command Line:** `--format`   | **Optional** . When used together with `--filename`, define the format of the locally-generated report file. When used alone, define the format of the terminal output. The supported values are: * `json` * `sarif` * `xml` * `text` | Report generation is disabled. |

#### Mend CLI IaC - Terminal view parameters

|             **Parameter**             |                                                                                                                                                                              **Description**                                                                                                                                                                              |                                                                 **Mend CLI Default Behavior**                                                                  |
|---------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Command Line:** `--filter`          | **Optional** . Filter findings by the [CVSS score severity](https://www.first.org/cvss/v3.0/specification-document#Qualitative-Severity-Rating-Scale) value. The supported values are: * `critical - `CVSS 3 score of 9.0 - 10.0 * `high - `CVSS 3 score of 7.0-8.9 * `medium - `CVSS 3 score of 4.0-6.9 * `low - `CVSS 3 score of 0.1-3.9 * `none` - CVSS 3 score of 0.0 | All vulnerability severity levels are shown in the scan results.                                                                                               |
| **Command Line:** `-h, --help`        | **Optional** . Display the available parameters for the `mend iac` command.                                                                                                                                                                                                                                                                                               | N/A                                                                                                                                                            |
| **Command Line:** `--non-interactive` | **Optional**. Mend CLI will run in non-interactive mode, suppressing use of colors, progress bar and any other graphic features in STDOUT.                                                                                                                                                                                                                                | Mend CLI output to STDOUT includes use of colors and progress bars, which are irrelevant in non-interactive session and may cause issues in some environments. |

#### Mend CLI IaC - Upload parameters

|          **Parameter**          |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |                                                                                                                                                                                                                                                                                                                                                                                          **Mend CLI Default Behavior**                                                                                                                                                                                                                                                                                                                                                                                           |
|---------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Command Line:** `--no-upload` | **Optional.**Run the Mend CLI scan offline. This parameter disables the upload of the scan results to the Mend Application.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | The Mend CLI will update your results within the Mend Platform Application.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Command Line:** `-s, --scope` | **Optional**. Set the scan scope for your image by specifying the hierarchy for the Mend Platform Application. The supported formats are: * **Full hierarchy** : `-s ORG//APP//PROJ` * **Partial hierarchy** : `-s APP//PROJ` * **Single hierarchy** : `-s PROJ` Examples of `--scope` configuration: * Application-Project scope: mend iac my-iac-folder -s MyApp//MyProj * Org-Application-Project scope with spaces: mend iac my-iac-folder -s "My Org//My App//My Proj" For Mend CLI scans that do not update the Mend Application, the `--scope` parameter is still used to direct the Mend CLI on the scope to use for the policy check. **Notes:** * Only organization administrators can set scopes and view the Mend Platform Application. * Non-org admin users can still scan images with the Mend CLI, but won't have their results sent to the Mend Platform Application if `--scope` is set. * As a result of running a Mend CLI scan with the `--scope` parameter, an empty project with the same name is also created in the Mend SCA UI. Deleting this project in the Mend SCA UI will delete the project within the Mend Platform Application. * If your Org/App/Proj names include spaces, make sure to set the `--scope` value within commas ("`My Project`"). * You are able to set the Org scope to any Mend organization that the current user signed in as (via `mend auth login`) has access to. * If you set an application or project name in `--scope` that does not exist in the organization prior to the run, it will be created in the Mend Mend Platform Application after the Mend CLI completes the scan. | Within the Mend Platform Application, scans are tiered under an organization → application → project hierarchy. Scan results are available only on the CLI output at this stage. If `--scope` is not set, the scan results will be sent and categorized within the Mend Platform Application as follows: * The **organization** currently logged into from the `mend auth login` command setup. ![:light_bulb_on:](https://docs.mend.io/__attachments/a_2250af593b6dd5244f228c8cbe9ede89b2d6e3eac5c0951e6bb262a651dc77d4/atlassian-light_bulb_on?cb=485b9fcaee6e0d0eefa559cab514727e) **Tip** : Use the Mend CLI `mend auth info` command to see what organization you are connected to. * An **application** will default to `My IAC Application` * A **project** will be created and named after the folder's name `<FolderName>`. |

#### Mend CLI IaC - Offline parameters

|        **Parameter**         |                                                                            **Description**                                                                            |                 **Mend CLI Default Behavior**                 |
|------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------|
| **Command Line:** `--local`  | **Optional** . Save your scan results locally. The default file is saved in the ***.mend*** folder. Specific path can be defined using the **--export-results** flag. | Scan results will be saved locally.                           |
| **Command Line:** `--update` | **Optional** . Update the Mend application with your scan results. Should be followed by the **--file** flag to specify the specific local scan results.              | The Mend application will get updated with your scan results. |
| **Command Line:** `--file`   | **Optional**. Specify a path to the local scan results file.                                                                                                          |                                                               |

### Mend CLI IaC-supported frameworks

The following frameworks are supported by the Mend CLI for IaC scans:

* Terraform .tf (Multi Cloud)

* Cloud Formation (AWS)

* K8s (YAML)

* Helm

* Dockerfiles

### Mend CLI IaC exit codes

**Note** : For a comprehensive overview of Mend CLI IaC exit codes, please refer to our [Mend CLI Exit Codes article](https://docs.mend.io/platform/latest/mend-cli-exit-codes.md).

---
version: "Latest"
language: "en"
---
# Configure the Mend CLI for SAST

## Overview

Configuring the Mend CLI for a SAST scan can be done via command line parameters or environment variables,.  
![:light_bulb_on:](https://docs.mend.io/__attachments/a_2250af593b6dd5244f228c8cbe9ede89b2d6e3eac5c0951e6bb262a651dc77d4/atlassian-light_bulb_on?cb=485b9fcaee6e0d0eefa559cab514727e)  
**Tip** : For inline assistance, use the `mend code -h` or `mend code --help` commands.

## Use cases for scanning your Code with the Mend CLI

Let's look at the following real-life examples that industry personas commonly run into:

* As an AppSec Manager, you are in charge of the decision-making for selecting a tool that can detect **custom code weaknesses** in your teams' **applications** and **provide remediation suggestions.** You also want to **define your organization's policies** that can be utilized to control your teams' builds. Finally, you want to **monitor the security posture** of your organization's custom code in the form of **dashboards**.

* As a DevOps Engineer, you are tasked with **implementing a security tool** into your teams' **CI/CD solutions** that can provide insights on code weaknesses in your teams' applications directly within the pipeline console.

**Mend's Answer:**Utilizing the Mend CLI SAST scan, you can effortlessly assess your custom code for security weaknesses and components that violate your organization's defined policies. The results are conveniently presented in a well-organized table format within the Mend CLI or via dashboards in the Mend SAST Application, and can also be exported into reports in various supported file formats.

## Configure the Mend CLI SAST scan via command line parameters

You can configure the Mend CLI SAST scan at runtime by adding flags to the `mend code` command. The usage of the `mend sast` command is as follows:

    mend code [flags]

![eb470fbc-d638-44f8-ab14-4330117779d3.gif](https://docs.mend.io/__attachments/a_52a5aec7a345811493ba2eef8b1753cd7681b088e25b87c6e83c4590bd760a7e/eb470fbc-d638-44f8-ab14-4330117779d3.gif?cb=22da66d9b69e5cd15aaaa8cf34edef93)

### Configure the Mend CLI SAST scan via environment variables

You can configure the Mend CLI SAST scan by defining environment variables. To define the variables in your environment, you can:

* Set environment variables prior to the Mend CLI run to *persist between sessions*:

  * In MacOS and Linux, use a shell startup script

  * In Windows, use the `setx` command.

    * `setx VARIABLE "MYVALUE"`

* Set environment variables prior to the Mend CLI run, for the *current session only*:

  * In MacOS and Linux, use the `export `command.

    * `export VARIABLE=value`

  * In Windows, use the `set` command.

    * `set VARIABLE=value`

## Reference

### Mend CLI SAST parameters

The Mend CLI SAST parameters provided below are organized alphabetically within each of their relevant contexts.  
**Note:** Not all configuration types (`Command Line, Environment Variable`) exist for each parameter. The configuration type(s) will have `"N/A"` for a parameter if it is not available.

#### Mend CLI SAST - General scan parameters

|                                                                              **Parameter**                                                                              |                                                                                                                                                                                                                      **Description**                                                                                                                                                                                                                      |                      **Mend CLI Default Behavior**                       |
|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------|
| **Command Line:** `-d, --dir` **Environment Variable:** `MEND_SAST_TARGET_DIRECTORY`                                                                                    | **Optional**. Specify the target directory for the Mend CLI SAST scan.                                                                                                                                                                                                                                                                                                                                                                                    | Current directory ("`.`") will be scanned.                               |
| **Command Line:** `-e, --engines` **Environment Variable:** `MEND_SAST_ENGINES`                                                                                         | **Optional**. Specifies which SAST engines should be used by their IDs. Omit this parameter for auto-recognition. For more information on supported langauges and their engine IDs, please visit the**Mend CLI SAST-supported languages and engine IDs** section within this documentation.                                                                                                                                                               | The parameter is omitted, enabling language auto-recognition.            |
| **Command Line** : `-n, --name` **Environment Variable** : `MEND_SAST_SCAN_NAME`                                                                                        | **Optional**. Specify the scan name. Auto-generated if omitted.                                                                                                                                                                                                                                                                                                                                                                                           | The parameter is omitted, causing the scan name to be auto-generated.    |
| **Command Line** : `--num-cpu` **Environment Variable** : `CPU_NUMBER`                                                                                                  | **Optional**. Specify the number of processor units for multicore processing. On Linux CFS, quota is applied.                                                                                                                                                                                                                                                                                                                                             | Dynamic, based on the number of available CPUs.                          |
| **Command Line** : `--retries` **Environment Variable** : `MEND_SAST_SCAN_RETRIES`                                                                                      | **Optional.** Specify the number of automatic scan retries in case of failures. Retries ignore files where the scan got stuck in the previous attempt.                                                                                                                                                                                                                                                                                                    | `0`                                                                      |
| **Command Line:** `--secrets-detection`                                                                                                                                 | **Optional.** For adding secret detection to your regular SAST scan.                                                                                                                                                                                                                                                                                                                                                                                      | When unspecified, secret scanning as part of your SAST scan is disabled. |
| **Command Line:** `--algo-langs` `--quantum-unsafe-langs` (closed beta) **Environment Variable**: `MEND_SAST_ALGO_LANGS` `MEND_SAST_QUANTUM_UNSAFE_LANGS` (closed beta) | **Optional.**Configure which languages each detector should scan. Example: mend code --algo-langs js,java,python --quantum-unsafe-langs java * The table below lists all available language codes * If a flag is omitted, the detector runs with its **default behavior** (auto-detect languages from the codebase) * The special value `none` disables a detector entirely. Example: `--algo-langs none` * Language codes are comma-separated, no spaces |                                                                          |

#### Mend CLI SAST - Engine generation parameters

When Mend introduces a new detection engine generation, the previous generation remains the default for existing customers to keep results consistent. The engine generation parameters support a gradual rollout, letting you validate the new generation on selected projects before enabling it as the default across the organization.  
**Note:** To make a new engine generation the default for an organization reach out to Mend Support or Customer Success.  

|                                                         **Parameter**                                                          |                                                                                                     **Description**                                                                                                     |                      **Mend CLI Default Behavior**                       |
|--------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------|
| **Command Line:** `--java-engine-generation` **Env Variable:** `MEND_SAST_JAVA_ENGINE_GENERATION`                              | **Optional.** Specifies which generation of Java detection engine is used to perform the scan. The available parameters are: * `1` - Use Java engine generation 1 * `2` - Use Java engine generation 2                  | The default for new organizations is Gen 2, which is recommended to use. |
| **Command Line:** `--js-engine-generation` (short notation: `--js`) **Env Variable:** `MEND_SAST_JS_ENGINE_GENERATION`         | **Optional.**Specifies which generation of JavaScript detection engine is used to perform the scan. The available parameters are: * `1` - Use JavaScript engine generation 1 * `2` - Use JavaScript engine generation 2 | The default for new organizations is Gen 2, which is recommended to use. |
| **Command Line:** `--csharp-engine-generation`(short notation: `--cs`) **Env Variable:** `MEND_SAST_CSHARP_ENGINE_GENERATION`  | **Optional.** Specifies which generation of C# detection engine is used to perform the scan. The available parameters are: * `1` - Use C# engine generation 1 * `2` - Use C# engine generation 2                        | The default for new organizations is Gen 2, which is recommended to use. |
| **Command Line:** `--cpp-engine-generation`(short notation: `--cpp`) **Env Variable:** `MEND_SAST_CPP_ENGINE_GENERATION`       | **Optional.** Specifies which generation of C/C++ detection engine is used to perform the scan. The available parameters are: * `1` - Use C/C++ engine generation 1 * `2` - Use C/C++ engine generation 2               | The default for new organizations is Gen 2, which is recommended to use. |
| **Command Line:** `--go-engine-generation`(short notation: `--go`) **Env Variable:** `MEND_SAST_GO_ENGINE_GENERATION`          | **Optional.** Specifies which generation of Golang detection engine is used to perform the scan. The available parameters are: * `1` - Use Go engine generation 1 * `2` - Use Go engine generation 2                    | The default for new organizations is Gen 2, which is recommended to use. |
| **Command Line:** `--python-engine-generation` (short notation: `--py`) **Env Variable:** `MEND_SAST_PYTHON_ENGINE_GENERATION` | **Optional.** Specifies which generation of Python detection engine is used to perform the scan. The available parameters are: * `1` - Use Python engine generation 1 * `2` - Use Python engine generation 2            | The default for new organizations is Gen 2, which is recommended to use. |

#### Mend CLI SAST - Incremental scan parameters

|                                         **Parameter**                                         |                                                                                          **Description**                                                                                           |       **Mend CLI Default Behavior**        |
|-----------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------|
| **Command Line:** `--baseline-storage` **Environment Variable:** `MEND_SAST_BASELINE_STORAGE` | **Optional** . Define the directory path of the baseline for future incremental scans. See `--upload-baseline` for more details                                                                    | Incremental scans are disabled by default. |
| **Command Line:** `-i, --inc` **Environment Variable:** `MEND_SAST_INCREMENTAL_SCAN`          | **Optional** . Enable incremental scanning, which sets the Mend CLI to only check for code changes from the previous scan. This parameter requires an existing baseline (see `--upload-baseline`). | Incremental scans are disabled by default. |
| **Command Line** : `--no-baseline` **Environment Variable**:                                  | **Optional**. Disable the creation of a baseline dump.                                                                                                                                             | Incremental scans are disabled by default. |
| **Command Line** : `--upload-baseline` **Environment Variable** : `MEND_SAST_UPLOAD_BASELINE` | **Optional**. Define the scan as a baseline for future incremental scans. The baseline will include minimum relevant fragments of code representation in order to enable incremental scans.        | Incremental scans are disabled by default. |

**Note:**

* If **--inc** is used together with **--upload-baseline**, a full scan is executed when the previous baseline was created with an older version of the engine.

#### Mend CLI SAST - Log parameters

![:light_bulb_on:](https://docs.mend.io/__attachments/a_2250af593b6dd5244f228c8cbe9ede89b2d6e3eac5c0951e6bb262a651dc77d4/atlassian-light_bulb_on?cb=485b9fcaee6e0d0eefa559cab514727e)  
**Tip:** The Mend CLI SAST scan logs can be found locally in the `.mend/logs/sast` directory.  

|                                 **Parameter**                                 |                                                                                                                                                                                                                                                                                                                                                                  **Description**                                                                                                                                                                                                                                                                                                                                                                   |                                     **Mend CLI Default Behavior**                                     |
|-------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------|
| **Environment Variable** : `MEND_BASEDIR` / `MEND_BASE_DIR`                   | **Optional**. Select a different directory to store the CLI's binaries, logs and configuration files.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | The default location for the CLI's binaries, logs and configuration files is `~/.mend`.               |
| **Environment Variable:** `MEND_LOG_LEVEL`                                    | **Optional**. Define the verbosity of the Mend CLI scan log files. The available values are: * `INFO` - Includes basic scan behavior. * `DEBUG` - Includes verbose information that is needed for diagnosing issues. * `WARNING` - Includes unexpected behaviors that happened during the CLI scan, but it was still able to complete successfully. * `ERROR` - Includes information on CLI functionalities that are not working and are preventing it from working properly. **Note:** * The `MEND_LOG_LEVEL` variable only impacts the generated log file and does not affect the terminal output of the CLI. * ***For troubleshooting, we recommend setting the*** `MEND_LOG_LEVEL`***to*** `DEBUG`***as it provides the most log verbosity.*** | * The Mend CLI log files are set to the `INFO` log-level value. * Successful scan logs are not saved. |
| **Command Line** : `--no-logs` **Environment Variable** : `MEND_SAST_NO_LOGS` | **Optional**. Disable the submission of the Mend CLI SAST scan logs to Mend.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | The parameter is omitted, causing the scan logs to be uploaded to Mend.                               |
| **Command Line** : N/A **Environment Variable** : `MEND_SAST_STORAGE_LIMIT`   | **Optional.** Define the amount of disc size in megabytes that is used for storing logs. If this limit is reached, the log files will be deleted automatically, starting with the oldest created date.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | `2048 MB`                                                                                             |

#### Mend CLI SAST - Report parameters

|                                     **Parameter**                                      |                                                                                                                                                   **Description**                                                                                                                                                   |                       **Mend CLI Default Behavior**                        |
|----------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------|
| **Command Line:** `--filename` **Environment Variable:** `MEND_SAST_REPORT_FILENAME`   | **Optional** . The SAST report filename. File extensions are automatically appended. See `-r, --report` and `--formats` parameters for report creation.                                                                                                                                                             | Report creation is not enabled.                                            |
| **Command Line:** `--formats` **Environment Variable:** `MEND_SAST_REPORT_FORMATS`     | **Optional** . SAST report file formats. This parameter requires enabling report creation (see `-r, --report`). The available parameter values are: * `html` * `pdf` * `xml` * `json` * `csv` * `sarif`                                                                                                             | Report creation is not enabled.                                            |
| **Command Line:** `-r, --report` **Environment Variable:** `MEND_SAST_GENERATE_REPORT` | **Optional** . Enable the creation of reports containing the scan results. See `--formats` parameter for supported file formats.                                                                                                                                                                                    | Report creation is not enabled.                                            |
| **Command Line:** N/A **Environment Variable:** `MEND_SAST_REPORT_LEVEL`               | **Optional.**Specify the granularity level of the generated report file. The available parameter values are: * `"short"` - Short technical report that does not include vulnerability data flows. * `"summary"` - Summary report with no individual vulnerability details. * `"technical"` - Full technical report. | The report is created with the Mend SAST report type set to `"technical"`. |
| **Command Line:** N/A **Environment Variable:** `MEND_SAST_REPORT_TYPE`                | **Optional.**Specify the type of the generated compliance report. The available parameter values are: * `"CAPEC"` * `"Default"` * `"HIPAA"` * `"HITRUST"` * `"NIST"` * `"OWASP2025"` * `"OWASP2021"` * `"OWASP2017"` * `"PCI"` * `"PCI4.0"` * `"SANS"` * `"MISRA"`                                                  | The report is created with the Mend SAST report level set to `"Default"`.  |

#### Mend CLI SAST - Terminal view parameters

|                            **Parameter**                            |                                                              **Description**                                                               |                                                                 **Mend CLI Default Behavior**                                                                  |
|---------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Command Line:** `-h, --help` **Environment Variable:** N/A        | **Optional** . Display the available parameters for the `mend code` command.                                                               | Use this parameter on-demand to display the available parameters for the `mend code` command.                                                                  |
| **Command Line:** `--non-interactive` **Environment Variable:** N/A | **Optional**. Mend CLI will run in non-interactive mode, suppressing use of colors, progress bar and any other graphic features in STDOUT. | Mend CLI output to STDOUT includes use of colors and progress bars, which are irrelevant in non-interactive session and may cause issues in some environments. |

#### Mend CLI SAST - Scan Performance parameters

|                                              **Parameter**                                              |                                                                                                       **Description**                                                                                                        |                                      **Mend CLI Default Behavior**                                      |
|---------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------|
| **Command Line:**N/A **Environment Variable:** `MEND_SAST_MAX_FILE_SIZE`                                | Sets a maximum file size above which a file will be ignored during the scan. Default is 1024 KB                                                                                                                              | **Command Line:**N/A **Environment Variable:** `MEND_SAST_MAX_FILE_SIZE`                                |
| **Command Line:** N/A **Environment Variable:** `MEND_SAST_PATH_EXCLUSIONS`                             | Specifies a comma separated list of paths that are excluded from the analysis, typically test code or library paths. **Note:** Path exclusions specified for a scan in the CLI are only applicable for that particular scan. | **Command Line:** N/A **Environment Variable:** `MEND_SAST_PATH_EXCLUSIONS`                             |
| **Command Line:** `--no-default-exclusions` **Environment Variable:** `MEND_SAST_NO_DEFAULT_EXCLUSIONS` | If specified, default path exclusions predefined by Mend (which ignore e.g. library directories) are not taken into account.                                                                                                 | **Command Line:** `--no-default-exclusions` **Environment Variable:** `MEND_SAST_NO_DEFAULT_EXCLUSIONS` |
| **Command Line:** N/A **Environment Variable:** `MEND_SAST_CONFIG_MAX_TYPE_ANALYSIS_STEPS`              | **Optional**. Configure the number of analysis steps of the type analysis for the Gen 2 engines. Default: Unlimited                                                                                                          | **Command Line:** N/A **Environment Variable:** `MEND_SAST_CONFIG_MAX_TYPE_ANALYSIS_STEPS`              |

#### Mend CLI SAST - Timeout parameters

|                                **Parameter**                                 |                                                                                        **Description**                                                                                        |                                             **Mend CLI Default Behavior**                                              |
|------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------|
| **Command Line:** N/A **Environment Variable:** `MEND_SAST_TIMEOUT_LANGUAGE` | **Optional**. Define the timeout in minutes per language. If a language violates the defined timeout value, the Mend CLI will skip the language and continue on, resulting in a partial scan. | 480 minutes per language                                                                                               |
| **Command Line:** N/A **Environment Variable:** `MEND_SAST_TIMEOUT_FILE`     | **Optional.** Define the timeout in seconds per individual file. If a file violates the defined timeout value, the Mend CLI will skip the file and continue on, resulting in a partial scan.  | Default values: * 60 seconds for any Gen 1 language * 600 seconds for any Gen 2 language Maximum value: * 1800 seconds |
| **Command Line:** N/A **Environment Variable:** `MEND_SAST_TIMEOUT_TOTAL`    | **Optional**. Define the number of minutes that running a scan will trigger Exit Code 9. **Note:**MEND_SAST_THRESHOLD_RUNTIME is still supported to maintain backward compatibility.          | 480 minutes                                                                                                            |

#### Mend CLI SAST - Upload parameters

|-----------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Parameter**                                                                           | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | **Mend CLI Default Behavior**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **Command Line** : `-s, --scope` **Environment Variable**: N/A                          | **Optional**. Set the scan scope for your project by specifying the hierarchy for the Mend Application. The supported formats are: * **Full hierarchy** : `-s "ORG//APP//PROJ"` * **Partial hierarchy** : `-s "APP//PROJ"` * **Single hierarchy** : `-s "PROJ"` Examples of `--scope` configuration: * Application-Project scope with single quotes: mend code -s 'MyApp//MyProj' * Org-Application-Project scope with double quotes: mend code -s "My Org//My App//My Proj" The wild card character "\*" can be used for any of the hierarchy levels. The default **Mend CLI**behavior will be used for any "\*". * Product-Project scope using "\*": mend code -s '*//MyProj' "CLI" will be the **product** used or created in place of the "\*". * Org-Product-Project scope using "\*": mend code -s "*//My Prod//*" The **organization** currently logged into from the `mend auth login` command setup will be used for the first "\*" and for the second "\*", the **project** will be created and named after either: * The folder specified in the `--dir` command. * If `--dir` is not specified, the name will be the directory where the Mend CLI ran from. **Notes:** * Make sure to set the `--scope` value within either single or double quotes (`'My Project'` or `"My Project"`). * You are able to set the Org scope to any Mend organization that the current user signed in as (via `mend auth login`) has access to. * If you set an application or project name in `--scope` that does not exist in the organization prior to the run, it will be created in the Mend Application after the Mend CLI completes the scan if you have the necessary permissions/role. | Within the Mend Application, scans are tiered under an organization → application → project hierarchy. If `--scope` is not set, the scan results will be sent and categorized within the Mend Application as follows: * The **organization** currently logged into from the `mend auth login` command setup. ![:light_bulb_on:](https://docs.mend.io/__attachments/a_2250af593b6dd5244f228c8cbe9ede89b2d6e3eac5c0951e6bb262a651dc77d4/atlassian-light_bulb_on?cb=485b9fcaee6e0d0eefa559cab514727e) **Tip** : Use the Mend CLI `mend auth info` command to see what organization you are connected to. * An **application** will be created and named "`CLI`". * A **project** will be created and named after either: * The folder specified in the `--dir` command. * If `--dir` is not specified, the name will be the directory where the Mend CLI ran from. |
| **Command Line** : `--snippet-size` **Environment Variable** : `MEND_SAST_SNIPPET_SIZE` | **Optional.** Specify the size of source code snippets (lines of code) submitted to the Mend Application. If `--snippet-size` is set to 0, no source code snippets will be uploaded to Mend.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | `10`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Command Line:** `--tag``s` **Environment Variable** : `MEND_SAST_TAGS`                | **Optional** . Add tag(s) to the scanned project/application in the `key:value` format. Example: `--tags "version:1.2.3, project:auth-service"` Custom tags are displayed in the UI at the scan level and reflect the last scan's tags at the project level, for all scan engines (e.g., SCA, SAST etc.) * Maximum number of tags allowed per scan**- 20** * Maximum length for each tag **- 100** for `key` and **100** for `value` * Maximum length for all tags combined - **no limit** * Valid characters - **A-z, 0-9, '.', '_', '-'** **Note:** * Only applicable for the Mend AppSec Platform. * This parameter supersedes the deprecated parameters `--label-proj` and `--label-app`.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | No label applied                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **Command Line:** `--label-proj <label>`                                                | **Optional**. Add a unified platform project label to the scanned project. Set of comma-separated labels is also supported. **Note:** * Label will be assigned only when --update flag is used.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | Deprecated                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Command Line:** `--label-app <label>`                                                 | **Optional**. Add a unified platform application label to the scanned application. Set of comma-separated labels is also supported. **Note:** * Label will be assigned only when --update flag is used.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Deprecated                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |

### Mend CLI SAST-supported languages and engine IDs

The following languages and their associated engine IDs (see `-e, --engines` parameter) are supported by the Mend CLI for SAST scans:  

|       **Engine ID**        |                                                 **Language**                                                  |
|----------------------------|---------------------------------------------------------------------------------------------------------------|
| `101`                      | [Java](https://docs.mend.io/platform/latest/java.md)                                                                              |
| `102`                      | [C#](https://docs.mend.io/platform/latest/c-sharp.md)                                                                             |
| `3`                        | [PHP](https://docs.mend.io/platform/latest/php.md)                                                                                |
| `104`                      | [Python](https://docs.mend.io/platform/latest/python.md)                                                                          |
| `5`                        | [Ruby](https://docs.mend.io/platform/latest/ruby.md)                                                                              |
| `6`                        | [ASP Classic/Visual Basic/VBScript](https://docs.mend.io/platform/latest/asp-classic-visual-basic-vbscript.md)                    |
| `7`                        | [VB.Net](https://docs.mend.io/platform/latest/vb-net.md)                                                                          |
| `108`                      | [JavaScript / Node.js](https://docs.mend.io/platform/latest/javascript-node-js.md) / [TypeScript](https://docs.mend.io/platform/latest/typescript.md) |
| `9`                        | [PLSQL](https://docs.mend.io/platform/latest/plsql.md)                                                                            |
| `10`                       | [Android Java](https://docs.mend.io/platform/latest/android-java.md)                                                              |
| `11`                       | [iOS Objective-C](https://docs.mend.io/platform/latest/ios-objective-c.md)                                                        |
| `12` (Gen 1) `112` (Gen 2) | [C/C++ (Gen 1)](https://docs.mend.io/platform/latest/c-c-gen-1.md) [C/C++ (Gen 2)](https://docs.mend.io/platform/latest/c-c-gen-2.md)                 |
| `13`                       | [ColdFusion](https://docs.mend.io/platform/latest/coldfusion.md)                                                                  |
| `14`                       | [Groovy](https://docs.mend.io/platform/latest/groovy.md)                                                                          |
| `15`                       | [TypeScript](https://docs.mend.io/platform/latest/typescript.md)                                                                  |
| `16`                       | [Cobol](https://docs.mend.io/platform/latest/cobol.md)                                                                            |
| `17`                       | [ABAP](https://docs.mend.io/platform/latest/abap.md)                                                                              |
| `18`(Gen 1) `118` (Gen 2)  | [Go (Gen 1)](https://docs.mend.io/platform/latest/go.md) [Go (Gen 2)](https://docs.mend.io/platform/latest/go-gen-2.md)                               |
| `19`                       | [Swift](https://docs.mend.io/platform/latest/swift.md)                                                                            |
| `20`                       | [Apex](https://docs.mend.io/platform/latest/apex.md)                                                                              |
| `21`                       | [Kotlin](https://docs.mend.io/platform/latest/kotlin.md)                                                                          |
| `22`                       | [Xamarin (C#)](https://docs.mend.io/platform/latest/xamarin-c.md)                                                                 |
| `23`                       | [Kotlin Mobile](https://docs.mend.io/platform/latest/kotlin.md)                                                                   |
| `24`                       | [R](https://docs.mend.io/platform/latest/r-language.md)                                                                           |
| `125`                      | [Rust](https://docs.mend.io/platform/latest/rust.md)                                                                              |

### Mend CLI SAST exit codes

| **Exit Code** |                                                            **Reason**                                                             |
|---------------|-----------------------------------------------------------------------------------------------------------------------------------|
| `1`           | An invalid configuration parameter was passed when executing the CLI. Check for typos in the parameters.                          |
| `2`           | Unable to access the update or license details from the Mend server URL. Check for internet connection.                           |
| `4`           | Unable to detect a supported language within the project based on the file extensions provided.                                   |
| `7`           | Could not create a cache subdirectory in the same location as the Mend CLI. Check that the Mend CLI permissions include "create". |
| `9`           | Results contain too many vulnerabilities, which contravenes the defined policy.                                                   |
| `10`          | A scanning engine stalled or failed.                                                                                              |

---
version: "Latest"
language: "en"
---
# Configure the Mend CLI for SCA

## Overview

Configuring the Mend CLI for an SCA scan can be done via command line parameters.  
![:light_bulb_on:](https://docs.mend.io/__attachments/a_2250af593b6dd5244f228c8cbe9ede89b2d6e3eac5c0951e6bb262a651dc77d4/atlassian-light_bulb_on?cb=485b9fcaee6e0d0eefa559cab514727e)  
**Tip** : For inline assistance, use the `mend dep||dependencies -h` or `mend dep||dependencies --help` commands.

## Getting it done

### Configure the Mend CLI SCA scan via command line parameters

You can configure the Mend CLI SCA scan at runtime by adding flags to the `mend dep` or( \|\| ) the `mend` `dependencies` command. The usage of the `mend dep|dependencies` command is as follows:

    mend dep||dependencies [flags]

![mend_dep2.gif](https://docs.mend.io/__attachments/a_5fa3520ebdd8e5926b635558c7c841aa28ff88f8184e2b7045a5b199a9c3c406/mend_dep2.gif?cb=053debf2a77e34eee8c9c890c7f6c8d3)  
**Note:** Backwards compatibility is supported for the previously used `mend sca` command. However, we recommend switching to the updated command at your earliest availability.

## Reference

### Mend CLI SCA parameters

The Mend CLI SCA parameters provided below are organized alphabetically within each of their relevant contexts.

#### Mend CLI SCA - General scan parameters

|                                             **Parameter**                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |                                                                                                                                                                                                                                 **Mend CLI Default Behavior**                                                                                                                                                                                                                                  |
|--------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Command Line:** `-d, --dir`                                                                          | **Optional**. Specify the target directory for the Mend CLI SCA scan.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Current directory ("`.`") will be scanned.                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Command Line:** `--dev`                                                                              | **Optional.** This flag controls whether to include development dependencies in your scans. More information is available [below](https://docs.mend.io/platform/latest/configure-the-mend-cli-for-sca.md#Dev-Dependencies-in-the-CLI).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | Development dependencies are excluded from your scan.                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **Command Line:** `-e, --extended`                                                                     | **Optional**. Perform a file system scan for source files, in addition to the package manager-based dependencies resolution. **Note:** The Mend CLI SCA file system scan does not support the scanning of binaries (i.e. JAR, ZIP, DLL).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | Only the package manager dependency resolution is enabled.                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Command Line:** `--no-default-exclusions` **Environment Variable:** `MEND_DEP_NO_DEFAULT_EXCLUSIONS` | **Optional**. Disable the Mend pre-defined folder exclusions, allowing these folders to be included in the Mend CLI SCA scan.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | Mend pre-defined folder exclusions: `.git, test, tests, example, examples, doc, docs, packages, site-packages`                                                                                                                                                                                                                                                                                                                                                                                 |
| **Environment Variable:** `MEND_SCA_EXCLUDE_DEP_CLASS`                                                 | **Optional.** Define a list of comma-separated Gradle configurations to be excluded from the Mend CLI scan via case-sensitive pattern matching which supports the **\*** wildcard. Examples: |      Pattern      |                    Will Match                     |              Won't Match               | |-------------------|---------------------------------------------------|----------------------------------------| | `test`            | `test`                                            | `testCompile`, `unitTest`, `Test`      | | `test*`           | `test`, `testCompile`, `testImplementation`       | `unitTest`, `Test`, `TestCompile`      | | `*test`           | `test`, `retest`, `pretest`                       | `testCompile`, `unitTest`, `Test`      | | `*Test*`          | `myTest`, `integrationTestRuntime`, `androidTest` | `test`, `testCompile`                  | | `compile*Runtime` | `compileRuntime`, `compileClasspathRuntime`       | `compile`, `runtime`, `CompileRuntime` | | The CLI excludes Gradle configurations with **"test"** in their name (case-sensitive), regardless of whether this environment variable is used or not and regardless of the values specified for it. When the `--dev` flag is used in conjunction, it takes precedence, so the default exclusion of `test*` configurations is disabled, [allowing test dependencies to be included](https://docs.mend.io/platform/latest/configure-the-mend-cli-for-sca.md#Dev-Dependencies-in-the-CLI) in the resolution process. |
| **Environment Variable:** `MEND_SCA_EXCLUDE_SUBPROJECTS`                                               | **Optional.** This variable allows users to exclude subprojects/modules from their scanned projects. How to use: Set the environment variable in your environment with the modules you'd like to exclude. For Maven exclusions, use either: * `:artifactId` (when the artifactId is unique), or * `groupId:artifactId` (for disambiguation) **Example:** MEND_SCA_EXCLUDE_SUBPROJECTS=maven@:artifactId-a,groupId:artifactId-b Supported package managers: * Maven                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | No subproject exclusions.                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Environment Variable:** `MEND_SCA_PATH_EXCLUSIONS`                                                   | **Optional**. Define directories to be excluded from the Mend CLI scan via a comma-separated list using glob format. These directories will append the default exclusions (unless --no-default-exclusions is in use). **Note:** Using this variable will ***append*** the default exclusions. The default exclusions remain in effect unless --no-default-exclusions is used.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | No additional folders are excluded except for the default exclusions.                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **Command Line:** `--strict`                                                                           | **Optional**. Fail the Mend CLI SCA command if any resolution step fails.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | Scan will complete regardless of the resolution steps' success.                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Command Line:** `--reachability` **Environment Variable:** `MEND_SCA_REACHABILITY`                   | **Optional**. Compute reachability for each CVE. Reachability will be computed for supported programming languages only. The scan may take longer.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | No reachability scan will be performed. Minimal CLI version: 24.3.1                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **Environment Variable:** `MEND_SCA_REACHABILITY_CACHE`                                                | **Optional.** This environment variable controls whether caching will be used in the Reachability analysis of your scan, for improved performance. Set to *'false'* to disable; set to *'true'* to enable.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | **Enabled.** **Note:** In organizations hosted on dedicated instances caching is **disabled** by default.                                                                                                                                                                                                                                                                                                                                                                                      |
| `MEND_SCA_{PACKAGE_MANAGER}_RESOLVEDEPENDENCIES`                                                       | **Optional.** This environment variable controls whether a specific package manager resolver will be active. Example: To disable npm resolution, set `MEND_SCA_NPM_RESOLVEDEPENDENCIES=false`. For the full list of package managers, refer to the [Mend CLI Support Matrix](https://docs.mend.io/platform/latest/mend-sca-cli-support-matrix.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | All resolvers are **enabled.**                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **Environment Variable:** `MEND_PULL_GIT_HISTORY`                                                      | **Optional.** Set to `true` to enable. When enabled, improves scan performance and cache utilization for Mend AI scans.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | **Disabled.**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |

##### Development Dependencies

**Note:** When using the `--dev` flag, it is not possible to exclude any package managers from the list.

The `--dev` flag is optional and controls whether to include dependencies used during the development phase in your scans. These dependencies are typically not included in the final application build. The terminology for these dependencies may vary across package managers.  

| **Package Manager** |                          **Scopes**                          |
|---------------------|--------------------------------------------------------------|
| **Go** (Go modules) | `test` and `xTest`                                           |
| **Gradle**          | Configurations that include the word "test" (case-sensitive) |
| **Maven**           | `test` and `provided`                                        |
| **npm**             | `devDependencies`                                            |
| **Ruby**            | Non-production groups                                        |
| **sbt**             | `test`, `provided` and `optional` configurations             |
| **uv (Python)**     | The `dev` group (not supported in repository integrations)   |

#### Mend CLI SCA - Log parameters

![:light_bulb_on:](https://docs.mend.io/__attachments/a_2250af593b6dd5244f228c8cbe9ede89b2d6e3eac5c0951e6bb262a651dc77d4/atlassian-light_bulb_on?cb=485b9fcaee6e0d0eefa559cab514727e)  
**Tip** : The Mend CLI SCA scan logs can be found locally in the `.mend/logs/sca` directory.  

|                        **Parameter**                        |                                                                                                                                                                                                                                                                                                                                                                  **Description**                                                                                                                                                                                                                                                                                                                                                                   |                                                                                         **Mend CLI Default Behavior**                                                                                          |
|-------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Environment Variable** : `MEND_BASEDIR` / `MEND_BASE_DIR` | **Optional**. Select a different directory to store the CLI's binaries, logs and configuration files.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | The default location for the CLI's binaries, logs and configuration files is `~/.mend`.                                                                                                                        |
| **Environment Variable:** `MEND_LOG_LEVEL`                  | **Optional**. Define the verbosity of the Mend CLI scan log files. The available values are: * `INFO` - Includes basic scan behavior. * `DEBUG` - Includes verbose information that is needed for diagnosing issues. * `WARNING` - Includes unexpected behaviors that happened during the CLI scan, but it was still able to complete successfully. * `ERROR` - Includes information on CLI functionalities that are not working and are preventing it from working properly. **Note:** * The `MEND_LOG_LEVEL` variable only impacts the generated log file and does not affect the terminal output of the CLI. * ***For troubleshooting, we recommend setting the*** `MEND_LOG_LEVEL`***to*** `DEBUG`***as it provides the most log verbosity.*** | * The Mend CLI log files are set to the `INFO` log-level value. * Successful scan logs are not saved.                                                                                                          |
| **Command Line:** `--persist-logs`                          | * Sends all logs to the logs directory, adhering to the location defined by the `MEND_BASE_DIR` environment variable. * The logs will be written to the specified path after every SCA scan, **regardless of scan outcome or log level**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | When unspecified, logs only persist in any of the following 2 scenarios: 1. `MEND_LOG_LEVEL` is set to any level other than INFO. 2. `MEND_LOG_LEVEL` is set to INFO but the scan encountered issues/failures. |
| **Command Line:** `--print-to-console`                      | **Optional**. When enabled, Mend CLI SCA logs will be printed to the standard output (usually the terminal console). The logs (both file and console) will contain additional scan-related information, compared to the default.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Disabled.                                                                                                                                                                                                      |

#### Mend CLI SCA - Terminal view parameters

|             **Parameter**             |                                                                                                                       **Description**                                                                                                                       |                                                                 **Mend CLI Default Behavior**                                                                  |
|---------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Command Line:** `--format`          | **Optional**. Set the scan result format within the terminal. The supported formats are: * `text` - Output Mend CLI results within the terminal using formatted tables and lists. * `json` - Output Mend CLI results within the terminal using JSON syntax. | Mend CLI outputs scan results within the terminal in `text` format.                                                                                            |
| **Command Line:** `-h, --help`        | **Optional** . Display the available parameters for the `mend dep|dependencies` command.                                                                                                                                                                    | Use this parameter on-demand to display the available parameters for the `mend sca` command.                                                                   |
| **Command Line:** `--non-interactive` | **Optional**. Mend CLI will run in non-interactive mode, suppressing use of colors, progress bar and any other graphic features in STDOUT.                                                                                                                  | Mend CLI output to STDOUT includes use of colors and progress bars, which are irrelevant in non-interactive session and may cause issues in some environments. |

#### Mend CLI SCA - Upload parameters

|              **Parameter**               |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                     **Mend CLI Default Behavior**                                                                                                                                                                                                                                                                                                                                                                                                     |
|------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Command Line:** `-s, --scope`          | **Optional**. Set the scan scope for your project by specifying the hierarchy for the Mend Platform. The supported formats are: * **Full hierarchy** : `-s "ORG//APP//PROJ"` * **Partial hierarchy** : `-s "PROD//PROJ"` * **Single hierarchy** : `-s "PROJ"` Examples of `--scope` configuration: * Application-Project scope with single quotes: mend dep -s 'MyApp//MyProj' -u * Org-Application-Project scope with double quotes: mend dep -s "My Org//My App//My Proj" -u The wild card character "\*" can be used for any of the hierarchy levels. The default **Mend CLI**behavior will be used for any "\*". * Application-Project scope using "\*": mend dep -s '*//MyProj' -u "CLI" will be the **application** used or created in place of the "\*". * Org-Application-Project scope using "\*": mend dep -s "*//My App//*" -u The **organization** currently logged into from the `mend auth login` command setup will be used for the first "\*" and for the second "\*", the **project** will be created and named after either: * The folder specified in the `--dir` command. * If `--dir` is not specified, the name will be the directory where the Mend CLI ran from. For Mend CLI scans that do not update the Mend Platform, the `--scope` parameter is still used to direct the Mend CLI on the scope to use for Automation Workflow. **Note:** * Make sure to set the `--scope` value within either single or double quotes (`'My Project'` or `"My Project"`). * You are able to set the Org scope to any Mend organization that the current user signed in as (via `mend auth login`) has access to. * If you set an application or project name in `--scope` that does not exist in the organization prior to the run, it will be created in the Mend Platform after the Mend CLI completes the scan if you have the necessary permissions/role. | Within the Mend Platform, scans are tiered under an organization → application → project hierarchy. If `--scope` is not set, the scan results will be sent and categorized within the Mend Platform as follows: * The **organization** currently logged into from the `mend auth login` command setup. ![:light_bulb_on:](https://docs.mend.io/__attachments/a_2250af593b6dd5244f228c8cbe9ede89b2d6e3eac5c0951e6bb262a651dc77d4/atlassian-light_bulb_on?cb=485b9fcaee6e0d0eefa559cab514727e) **Tip** : Use the Mend CLI `mend auth info` command to see what organization you are connected to. * An **application** will be created and named "`CLI`". * A **project** will be created and named after either: * The folder specified in the `--dir` command. * If `--dir` is not specified, the name will be the directory where the Mend CLI ran from. |
| **Command Line:** `-u, --update`         | **Optional**. Update the inventory of the project within the Mend Platform. When using the `--update` option, always explicitly set `--scope` to ensure scan results are consistently organized in your intended location within the Mend Platform.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | * Scan results are not sent to the Mend Platform. * [++Automation workflows++](https://docs.mend.io/platform/latest/automate-your-workflows-in-the-mend-platform.md) apply regardless of the `--update` [parameter](#) used in the scan.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Command Line:** `--tags`               | **Optional** . Add tag(s) to the scanned project/application in the `key:value` format. Example: `--tags "version:1.2.3, project:auth-service"` Custom tags are displayed in the UI at the scan level and reflect the last scan's tags at the project level, for all scan engines (e.g., SCA, SAST etc.) * Maximum number of tags allowed per scan - **Unlimited** * Maximum length for each tag-**255** for `key` and **255** for `value` * Maximum length for all tags combined - **Unlimited** * Disallowed characters: `<`, `>`, `%`, `&` **Note:** * Only applicable for the Mend Platform. * This parameter supersedes the deprecated parameters `--label-proj` and `--label-app`.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | No label applied                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Command Line:** `--label-proj <label>` | **Optional**. Add a unified platform project label to the scanned project. Set of comma-separated labels is also supported. **Note:** * Label will be assigned only when --update flag is used.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | Deprecated                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **Command Line:** `--label-app <label>`  | **Optional**. Add a unified platform application label to the scanned application. Set of comma-separated labels is also supported. **Note:** * Label will be assigned only when --update flag is used.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Deprecated                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |

### Mend CLI SCA - Supported Languages

#### Mend CLI SCA dependency resolution

**Note:**

* Please refer to [Support Matrix](https://docs.mend.io/platform/latest/mend-sca-cli-support-matrix.md) for an exhaustive list of supported package managers.

* It is recommended to ignore pre-install scripts in your build, to reduce security risk associated with such scripts.

|     **Language**     | **Package Manager** |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         **Details**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
|----------------------|---------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| C/C++                | Conan               | **Prerequisites**: * Conan 2.x installed on the machine. * It is recommended to build the project prior to the Mend CLI scan. **Supported dependency file(s)**: * `conanfile.txt` * `conanfile.py` **Specifications**: The Mend CLI executes the `conan graph info` command to obtain the dependency tree.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| C#                   | NuGet               | **Prerequisites**: * Build your C# project prior to the Mend CLI scan using either the `nuget install` or `dotnet build` commands. **Supported dependency file(s)** : One of the following sets: * `.csproj` and `project.assets.json` * `.csproj` and `packages.config` and `packages.lock.json` * `packages.config` and `packages.lock.json` **Notes:** * By default, the Mend CLI filters out **System Packages**for NuGet projects. As a result, these packages will not appear in the scan results. * Consider using the **Mend Unified Agent,** which provides an option to include **System** **Packages** in the scan for NuGet projects. For more information please refer to our [Getting Started with the Unified Agent](https://docs.mend.io/legacy-sca/latest/getting-started-with-the-unified-agent.md) article.                                                                                                                                                                                                                                                                                  |
| Elixir               | Hex                 | **Prerequisites:** * Hex must be installed locally where the Mend CLI will run. * Build your Hex project prior to the Mend CLI scan using the mix deps.tree command. **Supported dependency file(s)** : `mix.exs`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Go                   | Go modules          | **Prerequisites**: * Go modules must be installed locally where the Mend CLI will run. **Supported dependency file(s)** : `go.mod`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Haskell              | Cabal               | **Prerequisites:** * Cabal must be installed locally where the Mend CLI will run. * Build your Cabal project prior to the Mend CLI scan using the cabal install command. **Supported dependency file(s)** : `*.cabal`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Java                 | Bazel               | **Prerequisites:** * Bazel must be installed locally where the Mend CLI will run. * Build your Bazel project prior to the Mend CLI scan using the bazel build command. **Supported dependency files(s):** `WORKSPACE` or `WORKSPACE.bazel` **Specifications**: Only Maven dependencies are supported                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Java                 | Gradle              | **Prerequisites**: * Build your project prior to the scan using the `gradle build` command. * Gradle can either be installed locally or called using wrapper (`gradlew`) on the machine where the Mend CLI will run. **Supported dependency file(s)** : `build.gradle` **Specifications**: * Gradle Wrapper is supported by the Mend CLI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Java                 | Maven               | **Prerequisites**: * Build your project prior to the scan using the `mvn clean install` command. * Maven can either be installed locally or called using a wrapper (`mvnw`) on the machine where the Mend CLI will run. **Supported dependency file(s)** : `pom.xml` **Specifications:** * Maven Wrapper is supported by the Mend CLI. * The `test` and `provided` dependency scopes are excluded by the Mend CLI scan. * Dependencies declared inside Maven `<profile>` blocks are not detected by `mend dependencies`. * Running a Maven build with a profile activated (e.g. `mvn clean install -Pmyprofile`) does not carry that activation forward to the CLI's subsequent dependency resolution. The CLI invokes `mvn dependency:list` independently, and profiles must be activated on that command to be included. * The Mend CLI does not currently support passing additional arguments (such as `-P`) to its underlying Maven invocations.                                                                                                                                       |
| JavaScript           | Bower               | **Prerequisites** * Bower must be installed locally where the Mend CLI will run. * Build your Bower project prior to the Mend CLI scan using the bower install command. **Supported dependency file(s)** : `bower.json`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| JavaScript           | npm                 | **Prerequisites**: * Build your JavaScript project prior to the Mend CLI scan to generate the corresponding lock file and/or create the `node_modules` folder. * If you use the `npm install` command, it is recommended to restrict pre-build scripts to minimize risk. Consider the following options: * Use `--ignore-scripts` * Use `--package-lock-only` to see the changes that will be made to `package-lock.json` before running `npm audit` and then a full install. **Supported dependency file(s)**: One of the following sets: * `package.json` and `package-lock.json` * `package.json` and node_modules folder * `package.json` and `npm-shrinkwrap.json` **Specifications:** * The Mend CLI supports both `lockfileVersion` `2` and `3` formats for the `package-lock.json` file. * The `dev` dependency scope is excluded by the Mend CLI scan. * Peer dependencies (`peerDependencies`) are included in the Mend CLI scan. * An `npm-shrinkwrap.json` will always be parsed. If a `package-lock.json` file exists alongside it, only `npm-shrinkwrap.json` will be parsed. |
| JavaScript           | pnpm                | **Supported dependency file(s)** : `package.json` with `pnpm-lock.yaml`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| JavaScript           | Yarn                | **Prerequisites**: * Build your project prior to the scan using the `yarn install` command to generate the corresponding lock file. **Supported dependency file(s)** : `package.json` and `yarn.lock`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| OCaml                | opam                | **Prerequisites:** * opam must be installed locally where the Mend CLI will run. * Build your opam project prior to the Mend CLI scan using the opam install command. **Supported dependency file(s)** : `*.opam` **Specficiations:** OCaml isn't supported on Windows                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| PHP                  | Composer            | **Prerequisites**: * Build your PHP project prior to the Mend CLI scan using the `composer install` command to generate the corresponding lock file(s). **Supported dependency file(s)** : `composer.json` and `composer.lock`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Python               | pip                 | **Prerequisites**: * Build your project prior to the scan using the `pip install` command. * pip must be installed locally where the Mend CLI will run. * If your pip project uses a virtual environment, run the Mend CLI within the activated environment. **Supported dependency file(s)** : `requirements.txt`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Python               | Poetry              | **Prerequisites** * Poetry must be installed locally where the Mend CLI will run. * Build your Poetry project prior to the Mend CLI scan using the `poetry install` command. **Supported dependency file(s)** : `pyproject.toml` with `poetry.lock`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Python               | uv                  | **Prerequisites** * The uv package manager must be installed and accessible on the machine running the scan. To verify, run: * `python --version` * `uv --version` * **Virtual Environment:** A virtual environment should be activated, and packages synchronized before scanning. An example workflow is: * `uv venv --python 3.11.3` (or desired Python version) * `uv sync --all-packages` * `source .venv/bin/activate` (to activate the virtual environment) **Supported dependency file(s)** : `uv.lock` with `pyproject.toml` **Specifications**: * Supported groups include `mandatory` and `dev`. * The `uv` script-locking feature is not supported. * Conda with `uv` is only supported when `environment.yaml` is on the same level as `uv.lock`. * uv workspaces are considered direct dependencies; this is consistent with how `uv tree` and `uv pip` list dependencies.                                                                                                                                                                                                    |
| Ruby                 | Bundler             | **Prerequisites**: * Build your Ruby project prior to the Mend CLI scan using the `bundle install` command to generate the corresponding lock file. * Bundler must be installed locally where the Mend CLI will run. **Supported dependency file(s)** : `Gemfile` and `Gemfile.lock`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| R                    | packrat             | **Supported dependency file(s)** : `DESCRIPTION` with `packrat.lock`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Rust                 | Cargo               | **Prerequisites:** * Cargo must be installed locally where the Mend CLI will run. **Supported dependency file(s)** : `Cargo.toml` with `Cargo.lock`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Scala                | sbt                 | **Prerequisites**: * Build your project prior to the scan using the `sbt compile` command. **Supported dependency file(s)** : `sbt` files **Specifications**: * sbt 1.X is supported. * Only `runtime` and `compile` dependencies are supported. * `target` and `project` folders in the same location as .sbt files are excluded from the scan. **NOTE:** sbt has various known and well documented [GitHub issues](https://github.com/sbt/sbt/issues). Some of these issues might also affect the success and/or accuracy of the Mend SCA scan.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Swift                | SPM                 | **Prerequisites**: * Build your project prior to the scan using the `swift package resolve` command to generate the corresponding lock file. **Supported dependency file(s)** : `Package.swift` **Specifications:** * The Mend CLI supports both `Package.resolved` `1` and `2` formats.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Swift \& Objective C | CoacoaPods          | **Supported dependency file(s)** : `Podfile` with `Podfile.lock`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |

#### Mend CLI SCA file system scan

**Note**: The Mend CLI SCA file system scan does not support the scanning of binaries (i.e. JAR, ZIP, DLL).

The Mend CLI scan supports the following languages and their **source** files for the SCA file system scan: [Supported File Formats - Source](https://docs.mend.io/platform/latest/supported-file-formats#SupportedFileFormats-Source).

### Mend CLI SCA exit codes

**Note** : For a comprehensive overview of Mend CLI SCA exit codes, please refer to our [Mend CLI Exit Codes article](https://docs.mend.io/platform/latest/mend-cli-exit-codes.md).

---
version: "Latest"
language: "en"
---
# Configure your private Docker Hub registry in the Mend Platform

## Overview

The Mend CLI container image registry scanning solution can integrate with your private Docker Hub registry with a provided username and password.

## Getting it done

### Prerequisites before you scan a private Docker Hub with Mend Container

* Your Mend user must be an organization administrator.

* Have an existing and active Docker Hub account. No additional permissions are necessary.

* Make sure that the user permissions include read permission to all requested repositories in the registry.

* Docker API v2 is mandatory and must be enabled for the integration to work.

### Set up your private Docker Hub registry configuration via the Mend Platform UI

1. In the Mend Platform, navigate to ![image-20240319-192945.png](https://docs.mend.io/__attachments/a_e5a484a27cfb1991d1032336e15f0551ad33a610f9665758b99b402c10aacaf6/e268e820-e8ef-4a28-a187-644a276a7142?cb=e41593bc985552bd37bd21f3f5ca4365) → **Integrations.**

2. Scroll down to the '**Registries** ' section and click '**Docker Hub** '

   ![image-20240320-123011.png](https://docs.mend.io/__attachments/a_301c9dfc334a95ba2c7f750aef27393e174a6fecec3cad834c167328d215bf34/image-20240320-123011.png?cb=37cbdaf20041d2e902d1c566f3488ca5)

#### The Setup Wizard

##### Step 1 - **General Details**

Fill in the **General Details** fields:  
![image-20240727-121559.png](https://docs.mend.io/__attachments/a_d7a2fc67a6e47b541f1194812e2708ab09739edfa80f867cfa719f8c7e9bd1d8/image-20240727-121559.png?cb=2192655874fb78f587d74fc00ae7e9f6)

a. Display Name

b. Description (optional)

c. Environment (multi-selection is supported)

Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_199a1309ae59c3caddb412c3b4ab11083599826f546523d9e8bdcd15c6538fdb/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 2 - Authentication.

##### Step 2 - **Authentication**

Fill in the **Authentication** information:  
![image-20241021-112400.png](https://docs.mend.io/__attachments/a_ba958a77beb92099da7e6da3990508ac9f168dbd5d91c6358f6f0cb914f294af/image-20241021-112400.png?cb=2d6ea7294ac2e4a71cb4691f57207666)

a. Choose your Access Method (User \& Password / PAT Token).

b. Fill in the user name and password/token, depending on your selection in (a) above.

c. Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_199a1309ae59c3caddb412c3b4ab11083599826f546523d9e8bdcd15c6538fdb/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 3 - Configuration.  
Docker PAT tokens start with the pattern: `dckr_pat`

More info can be found: <https://docs.docker.com/security/for-developers/access-tokens/>

##### Step 3 - **Configuration**

Fill in the **Configuration** information to define your scan schedule

![image-20250714-161532.png](https://docs.mend.io/__attachments/a_355cdcb26effbc79bc9650e061fc497f907b34b5154de9820c7d751bd6cebffa/image-20250714-161532.png?cb=9123d1ce34f22fc8bcbbc06c1058d46b)

* **Enable Schedule** - Toggle off to disable scheduling.

* **Scan Time**

* **Frequency**

* **Scan on Connect** - While toggled on, it means a scan will be triggered automatically once the integration setup is completed.

Scheduling image registry scans is crucial for maintaining the security and integrity of your container images. By default, a scan interval of *7 days* will be applied. You can change the scan interval in 1-day increments or select specific days of the week when you wish for scans to be executed.  
**Note:** After the first scan (in which the latest 10 tags are scanned), in every scheduled scan only newly pushed images from the registry or changed images will be scanned. This is because [vulnerability and package updates occur automatically](https://docs.mend.io/platform/latest/review-container-scan-findings-organization.md#Security-Updates-Cadence) in an asynchronous manner, keeping the security information up-to-date without requiring new scans.

Click the ![image-20240727-113029.png](https://docs.mend.io/__attachments/a_199a1309ae59c3caddb412c3b4ab11083599826f546523d9e8bdcd15c6538fdb/image-20240727-113029.png?cb=758fd8386ca812fed58f567ae63ce538) button at the bottom right to move on to Step 4 - Summary, to view the summary of your setup as a final step before adding your registry.

##### Step 4 - Pull and Scan Inventory

Define which **repositories** and **tags** should be pulled and scanned using include/exclude filters:  
![image-20250523-132552.png](https://docs.mend.io/__attachments/a_7a102e9a46b4d1897c25c3928d50d469b9a8f9868b1fb472183720890e4e1d25/image-20250523-132552.png?cb=96fe7eb3350339bafc935cb5e9322af6)

**All Images** will be the default. When changing this to **Selected Images** as shown below, click **Add Conditions**to add Include and/or Exclude conditions, for both Repositories and Tags.  
![image-20250523-132537.png](https://docs.mend.io/__attachments/a_fc93a1a0edf50d0574aace481a1d24e04ccbab2acb3e041cee3c87e70aa7fd55/image-20250523-132537.png?cb=5befc6284e265b110fbdf5ebd5f5679e)

##### Step 5 - Summary

In this step, the summary of your input from steps 1-3 will be displayed. You can go back to the previous screens of the wizard to make changes, by clicking the 'Back' button at the bottom right corner of the screen. If you wish to confirm your configuration and add your registry, click the '**Done'** button:  
![image-20240727-121851.png](https://docs.mend.io/__attachments/a_2845d3ba4d8e859cac312d81874c3092285f45f0796be8dd1b5eaadfbfdbc3ff/image-20240727-121851.png?cb=86ffabf374c26855e33ecd78cccc0a1b)

A **Registry Added Successfully** message will pop-up at the bottom-left corner of the user interface once the integration credentials and configuration have been verified:  
![image-20240328-191507.png](https://docs.mend.io/__attachments/a_dbdefa483a4a14cdbea97486ccdab1a22d7252cdc0400e70e97dd6657dcafed1/image-20240328-191507.png?cb=b90ba11ef254a16c57f34fb93b0d4e76)  
**Note**: Before adding your registry, a connectivity check will be performed automatically, to ensure the credentials are valid and the registry is accessible for the integration.

## Reference

### Private Docker Hub parameters

|------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Parameter**    | **Description**                                                                                                                                                                                           |
| **Display Name** | Type the name of your registry. This will be displayed in the **Integrations** dashboard.                                                                                                                 |
| **Description**  | Optional. Provide any text. We recommend providing information that will help you remember the integration and the relevant registry.                                                                     |
| **Environment**  | Select the type of environment of your private Docker Hub registry (multiple options can be selected). The environment options are: * Production * Dev * QA * Staging                                     |
| **User Name**    | Provide the relevant private Docker Hub registry username. **Note** : This is *not* the email address associated to the Docker Hub account. This setting is explicitly meant for the Docker Hub username. |
| **Password**     | Provide the relevant private Docker Hub registry user password.                                                                                                                                           |

---
version: "Latest"
language: "en"
---
# Connect Mend for Jira

**Note:** This cluster of Mend for Jira articles is for customers using the **Mend AppSec Platform** . Customers on Mend.io's **Legacy SCA application** should refer to the [Issue Tracker Integrations articles](https://docs.mend.io/legacy-sca/latest/issue-tracker-integrations.md).

## Overview

Mend.io provides the ability to integrate with issue tracking systems, in order to automatically create issues in those systems when an automation workflow match occurs. As a result, issues automatically open in the issue tracking system and are automatically filled with the relevant Mend information required to mitigate the risks triggering the creation of the issue.

## Use cases for integrating Mend.io with your Jira projects

When Mend performs a scan and identifies findings that violate your configured policies, our Jira integration automatically creates corresponding Jira tickets with in-depth details.

## Getting it done

[Install Mend for Jira Cloud](https://docs.mend.io/platform/latest/install-mend-for-jira-cloud.md)
* [Install Mend for Jira Data Center](https://docs.mend.io/platform/latest/install-mend-for-jira-data-center.md)
* [Automatic issue creation with Mend for Jira](https://docs.mend.io/platform/latest/mend-jira-plugin-automated-issue-creation.md)
* [Automatic issue update with Mend for Jira (Data Center)](https://docs.mend.io/platform/latest/automatic-issue-update-with-mend-for-jira-data-cen.md)

## Reference

### Supported Jira Services

Our issue tracker integration supports the following Jira environments:

* Jira Cloud

* Jira Data Center

---
version: "Latest"
language: "en"
---
# Connect to your organization with the Mend Platform API

## Overview

Introducing Mend API 3.0 - an indispensable tool that empowers you and your users to integrate with your organization in the Mend Platform Application. With a comprehensive set of endpoints and user-friendly documentation, our Mend API 3.0 simplifies data exchange, automates processes, and enhances system interoperability.

## Reference

* [Getting started with Mend API 3.0](https://docs.mend.io/platform/latest/getting-started-with-mend-api-3-0.md)

* [Mend API 3.0](https://api-docs.mend.io/platform/3.0)

---
version: "Latest"
language: "en"
---
# Container Image Secrets in Mend Container

## Overview

Secrets are any kind of sensitive or private data that gives authorized users permission to access your IT infrastructure. These include keys and credentials such as SSH keys and certificates, TLS keys, encryption keys, API keys, database credentials, and more.

Secrets should be kept strictly private as attackers can easily find and use them to access and control the assets they are meant to protect. Developers may leave hard-coded secrets in container images, especially during rapid development and deployment cycles, thereby putting your organization and infrastructure at risk.

The Mend CLI scans your images to find any secrets that have been left behind.  
**Note:**This article specifically covers the usage and support of the Mend CLI's OS license detection feature. For general information on the Container Image engine of the Mend CLI, check out these articles:

* [Scan your container images with the Mend CLI](https://docs.mend.io/legacy-sca/latest/scan-your-container-images-with-the-mend-cli.md)

  * [Configure the Mend CLI for Container Images](https://docs.mend.io/legacy-sca/latest/configure-the-mend-cli-for-container-images.md)

  * [View the results of your Mend CLI Container Image scan](https://docs.mend.io/legacy-sca/latest/view-container-image-cli-scan-results.md)

## Use cases for identifying container image secrets with the Mend CLI

* As an AppSec Manager, your organization must comply with various security policies and regulations that require sensitive data to be protected at all times. If secrets are exposed in container images, the organization could face penalties and reputational damage.

* As a DevOps Engineer, you are responsible for managing the company's internal tools and services. You create a container image that includes credentials for an internal system. If this image is leaked or compromised, an attacker could gain unauthorized access to the system.

**Mend's Answer**: By implementing Mend CLI's secret detection for your container images, you can ensure that any exposed secrets are identified and resolved before deployment.

## Getting it done

### Prerequisites before identifying container image secrets with the Mend CLI

The following prerequisites are required before running a Mend CLI Container Image scan:

1. [++Download the Mend CLI++](https://docs.mend.io/platform/latest/download-the-mend-cli.md)

2. [++Authenticate your login for the Mend CLI++](https://docs.mend.io/platform/latest/authenticate-your-login-for-the-mend-cli.md)

### Run the Mend CLI to identify your container image secrets

Secret detection is enabled by default. To initiate the Mend CLI Container Image scan, run the following command:

    mend image <image_name[:image_tag]>

### View the secrets detected by the Mend CLI Container Image scan

### Console results

The Mend CLI Container Image scan outputs a summary of the detected secrets ordered by their severity. To display the secrets in the terminal output, add` --show=secret` to the CLI command.

Example command: `mend image <image_name[:image_tag]> --show=secret`

Example output:  
![att_1_for_2706670154.png](https://docs.mend.io/__attachments/a_6f9059a9542e2b1a27cd61f6ba54d594118455691cc2251a2a26329b92dda94f/att_1_for_2706670154.png?cb=8f87835cc700511d27490f106dba83c7)  

|--------------|---------------------------------------------------------------------------------------|
| **Field**    | **Description**                                                                       |
| Category     | The Secret Category, for example: Cloud Provider, SaaS Provider, etc.                 |
| Severity     | The Secret Severity Level. The supported values are: * Critical * High * Medium * Low |
| Description  | A description and the type of secret                                                  |
| Layer Number | The layer in which this secret was found                                              |
| File Path    | The full path and name of the file in which the secret was found.                     |
| Start Line   | The line in the file in which the secret is located                                   |
| End Line     | The line in the file in which the secret ends                                         |

### Secrets in the Mend Platform User Interface

Within the Mend Platform, you can review each Mend CLI scan's summary, details, and more. For more information on how to navigate through your Container Image scan results in the Mend Platform, visit the [Review Top Risky Container Image Scan Results](https://docs.mend.io/platform/latest/review-container-scan-findings-organization.md) page.  
![image-20240312-120315.png](https://docs.mend.io/__attachments/a_6d68ad90c3eefac8008e420487d7e89153dcef8f79366332ad408d855ee5c537/image-20240312-120315.png?cb=4b9c044e0a404282d56efd92a5e01f1c)

## Reference

### Mend CLI-supported file types for secret detection

* The Mend CLI scans all **text-based files**, including .json, .pem, .private, .txt (including Linux text files without a suffix), .yaml and more.

* The Mend CLI scans **native code files** like .go, .js, .py etc.

### Mend CLI-supported formats for secret detection

|        **Format**         |                                                                              **Details**                                                                               |
|---------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Alibaba keys              | * Access * Secret                                                                                                                                                      |
| AWS Access Key ID         | N/A                                                                                                                                                                    |
| AWS Secret Access Key     | N/A                                                                                                                                                                    |
| Azure Storage Account Key | N/A                                                                                                                                                                    |
| GitHub tokens             | * Refresh * Access * App * OAuth                                                                                                                                       |
| Package manager tokens    | * RubyGem API token * NPM access token * PyPI upload token                                                                                                             |
| Private key               | * EC * RSA                                                                                                                                                             |
| SaaS Keys \& tokens       | lack, Shopify, Stripe, Twilio, Facebook, Twitter, Adobe, Asana, Atlassian, Databricks, Discord, Dropbox, Doppler, Dynatrace, Grafana, HashiCorp, HubSpot, and Intercom |
| SSH Key                   | * EC * RSA                                                                                                                                                             |

---
version: "Latest"
language: "en"
---
# Copyright and Legal Information

The software described in this document is a product owned or licensed by WhiteSource Ltd. doing business as Mend. Such information is supplied solely for assisting authorized personnel to evaluate or use Mend's products in compliance with the Mend.io's Terms of Service available here:

[Mend.io's Terms of Service](https://www.mend.io/terms-of-service/)

No part of this document may be used for any other purpose, disclosed to any person or entity or reproduced by any means without the prior written permission of Mend.

The text, graphics and examples included in this document are for illustration and reference only. Corporate, individual names, and data used in examples are fictitious unless otherwise noted. If you find any problems in the documentation, please report them to Mend in writing. Mend does not warrant that the documentation is error-free.

Information in this document is subject to change without notice. Mend reserves the right to revise or withdraw the documentation or any part thereof, including, without limitation, the elimination or modification of any product functionality, at any time.

The software may be used or copied only in accordance with the terms of its license, and it is protected by one or more patents granted in the United States. Reverse engineering of the software is prohibited.

**For customers downloading a beta version, please note the following important disclaimer:**

By downloading a beta version, you acknowledge that it is being provided on an "as-is" basis and may not be at the level of performance of a final, generally available product offering. Mend will have no liability for damages arising out of or in connection with the beta version. Mend shall have no obligation to perform any fixes to the beta version and may immediately and without notice change or remove the beta version or any part thereof for any reason.

For questions or concerns, please contact your Mend representative.

**© Copyright 2025** [**Mend.io**](http://mend.io/)**(White Source Ltd). All rights reserved.**

**Contact us:** [support@mend.io](mailto:support@mend.io)

---
version: "Latest"
language: "en"
---
# Copyright Management in the Mend Platform

## Overview

OS Inventory shows the copyright status for each library, including whether copyright notices were detected, not detected, or not specified. It helps you quickly understand the copyright information detected for each open source library in your project, without opening each library individually.

### Copyright Statuses

Use copyright status to understand how complete the detected copyright information is for each library.  

|         **Status**         |                                    **Meaning**                                    |                                  **Recommended action**                                   |
|----------------------------|-----------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------|
| **Has Copyrights**         | Copyright notices were detected for the library.                                  | Review the notices as part of your standard legal review process.                         |
| **No Copyrights**          | No copyright notices were detected for the library.                               | Confirm whether this matches your organization's open source review policy.               |
| **Unspecified Copyrights** | Copyright information is not available or has not been specified for the library. | Prioritize the library for review if your policy requires complete copyright information. |

## Copyright Actions

### Filter by Copyright Status

You can filter OS Inventory to focus on libraries with a specific copyright status.  
![image-20260627-052520.png](https://docs.mend.io/__attachments/a_134d469b929be22883a29d6b02fe0c18a246d592df35b09216d2883ccf3e7d6f/image-20260627-052520.png?cb=c3c093e488c89571d53b9115efa23c95)

1. Open **OS Inventory**.

2. Open the **Copyrights** filter.

3. Select one or more statuses:

   * **Has copyrights**

   * **No copyrights**

   * **Unspecified copyrights**

4. Review the filtered list of libraries.

5. Clear or change the filter to adjust the results.

Filtering by **Unspecified Copyrights** is useful when you want to find libraries that may require additional legal review because copyright information is missing or unavailable.  
![image-20260627-052238.png](https://docs.mend.io/__attachments/a_06b9bb9089a61e886f28d454fb033b1d24eeb23abd8d2356ef4ab8625d7956d6/image-20260627-052238.png?cb=df9903c2bf397b763833c9d28f254922)

**Note:** It is recommended to review libraries with missing or unavailable copyright information according to your organization's legal review process.

### Copyright Assignment

Follow the steps in the parent [Legal and Compliance Workflows article](https://docs.mend.io/platform/latest/legal-and-compliance-workflows.md#Library-Actions) to assign or override a copyright.

---
version: "Latest"
language: "en"
---
# Create a Project in the Mend AppSec Platform

## Overview

As an **Admin** of the **account** , you can create new **Projects** . This can be done in the **Mend Platform's** **Administration** menu. This article will provide the details for creating new **Projects**.

## Getting it done

### Create Projects in the Mend Platform

1. Log into the **Mend Platform**

2. Click the settings gear in the top right corner of the page.

3. Click **Administration** to navigate to the **Administration** page.

![new_set_admin.png](https://docs.mend.io/__attachments/a_f56b50d81c6d2ee232177549ab1febb9ee8ccb12dd0ec8e90362821d869ce6f6/new_set_admin.png?cb=d8890d29f618a7d126cd97c94ce77350)

4. Click **Projects** in the left Administration list to navigate to the **Projects** management page.

5. Click the **+ Add Project** button in the top right corner of the **Projects** table.

![add_proj.png](https://docs.mend.io/__attachments/a_65a25890e705aa3a416900de9296c94facc8a1412b83cdd95b1d63e8feb17772/add_proj.png?cb=2fae93078e1efe548a896bd334dbfc6e)

6. Enter a name for your **Project** in the **Add Project** pop-up window (valid characters in project names are documented in the [Limitations](https://docs.mend.io/platform/latest/known-issues.md#Limitations) page).

   Note that at this stage, you also have the option to **upload a previously generated Dependencies SBOM** report file and create a new project out of it. Read more about this feature [here](https://docs.mend.io/platform/latest/create-a-project-using-a-dependencies-sbom-import.md).

7. Select an **Application** to assign the **Project** to.

![new_add_proj.png](https://docs.mend.io/__attachments/a_3f660da268da41084d0c6e31149f21d20eaf5eba7e4fffe104239b712c093693/new_add_proj.png?cb=e5cc4761954f0d944646d46884ca72db)

8. Click **OK**.

![proj_ok.png](https://docs.mend.io/__attachments/a_c9fab54f74c893131d84a143231cf6ab9ac6a2d8d776570c67899afe6cc02422/proj_ok.png?cb=ce5d2b2f739fb1c10cea6aa80de2f1d3)  
**Note:** If you enter a **Project** name and assign it to an **Application** to which a **Project** with the same name is already assigned to that **Application**, you will see a notification in the bottom right corner of the window.  
![proj_exists.png](https://docs.mend.io/__attachments/a_d0ae5dc84701cd244397ecb16918418b221999f42a895e5bde85bb28774f8994/proj_exists.png?cb=694c716c88093f21b8ba61f29f2d9d5c)

The new **Project** will be added to the **Projects** table, and a notification will appear in the bottom right corner of the window.  
![proj added.png](https://docs.mend.io/__attachments/a_f441dcb82a5bb1ecf80ff25ee9088a97f87467456c6bc26a2ee103b91ae0c9a2/proj%20added.png?cb=146cacb9bc81572558a2c39e20207001)

[Next Page](https://docs.mend.io/llms-full.txt/1)
