For the complete documentation index, see llms.txt. This page is also available as Markdown.

Mend (formerly Whitesource) step configuration

Scan code repositories and container images with Mend.

The Mend step in Harness STO enables you to scan both code repositories and container images. You can perform SAST, SCA and Container scans using the available scan modes: Orchestration, Extraction, and Ingestion.

Mend step settings

The recommended workflow is to add a Mend step to a Security or Build stage and then configure it as described below.

Scan

Scan Mode

Scan Configuration

  • Default: Uses the legacy Mend Unified Agent CLI with the V2 API. This configuration performs only SCA (Software Composition Analysis) for repositories and uses the legacy method for container image scanning.

  • SAST, SCA, Container: Uses the newer Mend CLI with the V3 API. This configuration supports SAST, SCA for repositories, and Container for container image scanning.

Target

Type

Target and variant detection

Name

Variant

Workspace (repository)

Ingestion File

Authentication

Domain

The fully-qualified URL to the scanner. The default is https://saas.whitesourcesoftware.com/.

Enforce SSL

Access Id

The user key for your Mend personal account: in the Mend UI, click the Account Settings button in the top right.

You should create a Harness text secret with your encrypted token and reference the secret using the format <+secrets.getValue("my-mend-user-key")>. For more information, go to Add and Reference Text Secrets.

Access Token

The API key for your Mend organization.

This field is required. If you want to run a scan in an organization other than the default organization for your account, generate an Access Token in that specific organization. In the Mend UI, go to Integration > Organization > API Key.

You should create a Harness text secret with your encrypted token and reference the secret using the format <+secrets.getValue("my-mend-org-api-key")>. For more information, go to Add and Reference Text Secrets.

Scan Tool

Lookup Type

You can specify the Mend product or project By Token or By Name.

Product Name / Token

The name or token of the Mend product that you want to scan.

This field is required for Orchestration and Extraction scans.

Project Name / Token

The name or token of the Mend project that you want to scan.

This field is required for Extraction scans.

Include

If you're running an orchestration scan on a code repository, you can use this setting to specify the files to include in the scan. By default, a Mend scan includes all files in the code repository.

This setting corresponds to the Includes configuration parameter for the Mend United Agent.

Exclude

If you're running an orchestration scan on a code repository, you can use this setting to specify the specific files to exclude from the scan. By default, a Mend scan includes all files in the code repository.

This setting corresponds to the excludes configuration parameter for the Mend United Agent.

Log Level

Additional CLI flags

Use this field to run the Mend Unified Agent with additional flags.

Fail on Severity

Settings

Additional Configuration

Mend requires higher compute resources for orchestration. Recommended minimum resource limits:

  • Memory: 16 GB

  • CPU: 2

Advanced settings

Proxy settings

Mend orchestration pipeline example

The following pipeline shows an end-to-end orchestration workflow. The Mend step includes the settings needed to run this specific scan: access_token, domain, access_id, and product_name.

Last updated

Was this helpful?