Vigilance vs Mend
Mend. Checks your open-source parts against a list of known bugs and flags packages it knows are bad.
Vigilance. Runs on your own machine and names the one file that gained a new power.
Vigilance as a Mend alternative
Vigilance is a Mend alternative that runs on your own machine. It names the one file that gained a new power, before you trust an update. Below, a plain table sets the two side by side.
Side by side
| Question | Mend | Vigilance |
|---|---|---|
| Finds known bugs in your dependencies | Yes | No |
| Flags a brand-new bad package by what it can do | Some | Yes |
| Spots a file that can do more than the version before | No | Yes |
| Covers software that did not come from a public registry | No | Yes |
| Runs with no cloud account | No | Yes |
| Looks inside an installer, a zip or your build output | Some | Yes |
Which one do you need?
Mend guards public packages against known bugs. Vigilance guards everything on the machine against new behaviour. Run both.
Known risk versus new risk
A bug or a bad package someone already reported, with a name and a number. Most tools work here.
A file that gained a power it never had, that no report covers yet. Vigilance works here.
Common questions
Is Vigilance a Mend alternative?
Yes, for one job. Vigilance names the file that gained a new power, on your own machine. Many teams run it next to Mend.
What does Vigilance do that Mend does not?
Vigilance can spot a file that can do more than the version before, and on Pro run with no internet at all.
What does Mend do that Vigilance does not?
Mend finds known bugs that already have a name and a number. Vigilance does not.
Does Vigilance need the internet or a cloud account?
The Free plan runs online. Pro runs fully offline, with no cloud account.
Try it on your own software.
Show it the version you run today and the one you are about to install.
Talk to us
A question, a pilot, or a bigger fleet? Send a note. It reaches a person.