Can Mend Detect Vulnerabilities in Source Code and Binaries?
Mend identifies libraries/binaries/source files coming from publicly-available open source software repositories.
Mend can extract common archive files (e.g. *.zip, *.tar.gz, *.war, etc.) and scan their content; whether if it comprises open source files or binary libraries, they can all be identified as long as they are in the same form in which they were originally published.
Mend cannot, however, decompile executables or packaged/deployed applications to scan their content.