Mend.io configuration
Mend.io specializes in Software Composition Analysis (SCA), Static Application Security Testing (SAST), and container security, helping developers to securely manage open-source risks, license compliance, and AI-generated code. DevOps Intelligence supports Mend.io as an integral part of your security SDLC regimen.
Prerequisites
The following items are prerequisite to Mend.io integration with DevOps Intelligence:
- Mend.io account
- Access Policy as Platform Administrator role: Users must be assigned the Platform Administrator role to create and manage connections.
- DevOps IntelligenceAdministrator role: Users must be assigned the DevOps Intelligence Administrator role to create and manage configurations.
Integration procedure
The following procedure describes how to configure and integrate a supported tool with Developer Experience:
- Create a UserKey.
- Creat a Connection.
- Tool Configuration – Secure Phase
- Onboard the technical service
Details are available in subsequent sections:
Create a UserKey
Use the following procedure to create a UserKey:
- Click on Manage & Administer → Connections Management.
- Click Tool Connections from the left-side menu. You will be redirected to the Tool Connections page.
- Click Add Connection.
- Choose Connection type as Mend.io.
- Name Local account name for reference.
- Enter the Mend.io Host URL. Example: https://test.mend.io
- Enter the created e-mail and Userkey.
Create a connection
Use the following procedure to create a connection:
- Navigate to DevOps Intelligence→ Settings & Utilities → Application Configurations.
- Click the overflow menu for the chosen application and click on Edit Tools Configuration. You will be redirected to the Add Tools step.
- Select Secure for Phase.
- Click Add Tool Configuration. The service navigates to the Edit Tool Configuration step.
- Select category as License Scan. Select Tool Engine as Mend.io.
- Complete the configurations, categorized into two tabs (Release and License status).
- Click Add Configuration.
Tool configuration
Use the following procedure to add Mend.io to DevOps Intelligence.
- Navigate to DevOps Intelligence → Settings & Utilities → Application Configurations.
- Click the overflow menu for the chosen application
- Click on Edit Tools Configuration. The service navigates to the Add Tools step.
- Select the phase as Secure.
- Click on Add Tool Configuration. The service navigates to the Edit Tool Configuration step.
- Select category as License Scan.
- Select Tool engine as Mend.io.
- Complete the form, categorized into two tabs (Release and License status).
- Click Add Configuration.
Release Identification takes the following format:
- Prefix signifies the starting sequence of characters for releases, with the default value being empty.
- Variable signifies the starting sequence of characters for releases, with the default value being empty.
- The release format is applicable to identify the release names in issues and the release branches.
The tool configuration inherits the release prefix and variable from the application. To override these values only for this configuration, click on the Edit button and make the necessary changes. Changing the values here will not impact the release prefix and variable set in the application.
Example prefix and variable designators
Prefix | Variable | Matched Example |
|---|---|---|
release- | YYYY.MM.DD | release-2023.03.10,release-2023.04.12,release-2023.02.17 |
release- | **** .*** .** | release-2023 .03 .10,release-2023 .04 .12,release-2023 .02 .17 |
rel- | **** | rel-2023,rel-2022 |
release- | **** .*** .** | release-2023 .Mar .10,release-2023 .Apr .12,release-2023 .Feb .17 |
release- | **** .*+ .** | release-2023 .Mar .10,release-2023 .04 .12,release-2023 .February .17 |
release- | *+ .*+ .** | release-23 .Mar .10,release-2023 .04 .12,release-2023 .February .17 |
release- | **** .** .** .** | release-2023 .03 .10 .03,release-2023 .04 .12 .10 |
| **** | 2023,2022,2021 |
version | | version1,version2023,version2.3 |
Supported License Status includes the following:
- Allowed
- Denied
- Need Approval
The Mend.io tool classifies license risks into Low, Medium, and High categories. These risk levels should be mapped to the Allowed, Need Approval and Denied in DI.
Onboard the Technical Service
Use the following procedure to onboard the technical service:
- Navigate to DevOps Intelligence→ Settings & Utilities → Application Configurations.
- Click the overflow menu for the chosen application
- Select Onboard Technical Service.
- Select the phase as Secure.
- Select the category as License Scan.
- Select the tool engine as Mend.io.
- For Connection, select connection name from the drop down.
- For Repository, select repository name from the drop down.
- Click Onboard to onboard the technical service.
Delete the Technical Service
You have the option of deleting the technical service at any time. Use the following procedure:
- Navigate to DevOps Intelligence → Settings & Utilities → Application Configurations.
- Expand the application to see all the associated phases.
- Click the overflow menu for the phase (Secure).
- Click Delete Technical Service.
- Select the category as License Scan.
- Select tool engine as Mend.io.
- Select the Organization and Repository.
- Click Delete.