Mend (formerly Whitesource) step configuration
Scan code repositories and container images with Mend.
The Mend step in Harness STO enables you to scan both code repositories and container images. You can perform SAST, SCA and Container scans using the available scan modes: Orchestration, Extraction, and Ingestion.
Mend step settings
The recommended workflow is to add a Mend step to a Security or Build stage and then configure it as described below.
Scan
Scan Mode
Scan Configuration
Default: Uses the legacy Mend Unified Agent CLI with the V2 API. This configuration performs only SCA (Software Composition Analysis) for repositories and uses the legacy method for container image scanning.
SAST, SCA, Container: Uses the newer Mend CLI with the V3 API. This configuration supports SAST, SCA for repositories, and Container for container image scanning.
Target
Type
Target and variant detection
Name
Variant
Workspace (repository)
Ingestion File
Authentication
Domain
The fully-qualified URL to the scanner. The default is https://saas.whitesourcesoftware.com/.
Enforce SSL
Access Id
The user key for your Mend personal account: in the Mend UI, click the Account Settings button in the top right.
You should create a Harness text secret with your encrypted token and reference the secret using the format <+secrets.getValue("my-mend-user-key")>. For more information, go to Add and Reference Text Secrets.
Access Token
The API key for your Mend organization.
This field is required. If you want to run a scan in an organization other than the default organization for your account, generate an Access Token in that specific organization. In the Mend UI, go to Integration > Organization > API Key.
You should create a Harness text secret with your encrypted token and reference the secret using the format <+secrets.getValue("my-mend-org-api-key")>. For more information, go to Add and Reference Text Secrets.
Scan Tool
Lookup Type
You can specify the Mend product or project By Token or By Name.
Product Name / Token
The name or token of the Mend product that you want to scan.
This field is required for Orchestration and Extraction scans.
Project Name / Token
The name or token of the Mend project that you want to scan.
This field is required for Extraction scans.
Include
If you're running an orchestration scan on a code repository, you can use this setting to specify the files to include in the scan. By default, a Mend scan includes all files in the code repository.
This setting corresponds to the Includes configuration parameter for the Mend United Agent.
Exclude
If you're running an orchestration scan on a code repository, you can use this setting to specify the specific files to exclude from the scan. By default, a Mend scan includes all files in the code repository.
This setting corresponds to the excludes configuration parameter for the Mend United Agent.
Log Level
Additional CLI flags
Use this field to run the Mend Unified Agent with additional flags.
Fail on Severity
Settings
Additional Configuration
Advanced settings
Proxy settings
Mend orchestration pipeline example
The following pipeline shows an end-to-end orchestration workflow. The Mend step includes the settings needed to run this specific scan: access_token, domain, access_id, and product_name.
Last updated
Was this helpful?