Vigilance vs Mend

Mend. Checks your open-source parts against a list of known bugs and flags bad packages. Vigilance finds the update that gained a hidden power, before you install it.

Updated 5 Oct 2026

Start Free See Pricing

The Catch Mend Cannot Make

Mend checks your parts for known bugs and uses threat intelligence to flag malicious packages. Vigilance keeps no list of either. Vigilance keeps no list. It compares the version you trust with the version you install. It reports any file that can suddenly do more.

A real one: axios, March 2026

axios is one of the most-installed packages on the internet. In release 1.14.1, its package.json gained a hidden install step. That step pulls down a remote-control program. No CVE existed for it, so a list of known bugs had nothing to match. One command sees it:

vigi diff --old ./axios-1.14.0 --new ./axios-1.14.1

HEADS UP. 1 file changed. package.json can now run a hidden helper on install and reach the network.

Run both. Mend checks two lists for a known match. Vigilance checks the file itself, match or not. See them side by side below.

What Mend Does Well

Mend is an application security platform. Its site lists software composition analysis (SCA) for open-source dependencies and container images, static analysis (SAST), container security, DAST and API security. It also lists compliance automation for SBOMs and an AI security product. Source: the Mend site.

Mend SCA includes malicious package protection. Mend says it identifies typosquats, dependency confusion attacks and packages that carry data-exfiltration or backdoor code, using continuously updated threat intelligence. It lists integration in IDEs, repositories, registries and CI/CD pipelines, and it says it supports more than 200 languages and frameworks. Source: Mend supply chain protection.

Mend also maintains Renovate, the open-source bot that opens dependency update pull requests. The Renovate project says Mend supports and maintains it. That gives Mend customers a link between finding a risky dependency and updating it.

Pricing is public, which is rare in this category. A buyer can work out a budget before a sales call.

Where It Falls Short

Mend works from known bugs and threat intelligence. Both depend on someone reporting the problem first. An update that is malicious but not yet reported has nothing to match on its first day. Mend does not describe a comparison of a new version with the version you trust to find a file that gained a capability.

Mend focuses on packages from public ecosystems and your own code. The pages Vigilance read do not list a vendor installer, a zip or a program already running on a machine.

Mend prices per contributing developer. That is fair for a team that builds software. It is a poor fit for a shop that mainly installs software and has few developers but many machines.

Feature Comparison

Mend checks parts against known bugs and threat data, and Vigilance reads what changed in the files. The table shows the split.

Question Mend Vigilance
Finds known bugs in your dependencies Yes No
Flags a malicious package with threat intelligence Yes No. It keeps no list.
Scans your own code (SAST) Yes No
Opens update pull requests Yes, through Renovate No
Spots a file that can do more than the version before Not described Yes
Covers a vendor installer, a zip or a program on a machine Not described Yes
Has a free plan for the commercial platform None listed on the pricing page Yes, up to 50 machines
Works with no internet Not described Pro

When Mend Is the Better Fit

Choose Mend if you build software and want SCA, SAST and malicious package protection from one vendor, priced per developer.

Choose Mend if you want the update bot and the scanner from the same company. Renovate Enterprise is sold by Mend, and the project is maintained by Mend.

Choose Mend if you need many languages covered. It lists more than 200 languages and frameworks.

Mend Renovate and Vigilance

Renovate opens a pull request when a dependency has a new version. It does not read the files of the new version for new capabilities. The Renovate docs describe version, advisory and age checks, and an experimental check on malicious packages that uses OSV data.

Vigilance fits at the point where that pull request is read. Compare the version you trust with the version in the pull request and read the line it prints. On a normal update there is no line. The Dependabot vs Renovate page covers this in detail.

This gives a team an update bot, a scanner for known bugs and a file-level check, each doing one job.

Using Mend and Vigilance on One Update

Let Mend scan your code and dependencies for known bugs and for packages its intelligence marks as malicious. Let its policy rules act in your pipeline.

Run Vigilance on the same dependency update. Keep the old files in one folder and put the new files in another. The diff names any file that gained a capability, such as a hidden install step or a call to the network.

The results answer two different questions. Mend says what is known about the package. Vigilance says what changed in the files you hold. A package can pass the first check and fail the second when nobody has reported it yet.

Vigilance runs on your own machine. On the Pro plan it opens no network connection.

What to Ask Before You Choose

Ask how many developers you have. Mend prices per contributing developer, so a large team costs more than a small one. A shop with few developers and many machines gets less from this model.

Ask whether you need an update bot. Renovate is open source and free to run. Mend Renovate Enterprise is paid. Check which one fits.

Ask what checks the update that Renovate opens. The bot reads versions and advisories. A file-level compare covers the content of the update.

Ask which of your risks sit outside public registries. Vendor installers and your own builds are examples. Plan a separate check for them.

Pricing

Mend publishes prices per contributing developer, with no extra fee per gigabyte or per scan. The pricing page lists Mend AppSec at up to $1,000 per developer per year. It lists Mend AI at up to $300 and Mend Renovate Enterprise at up to $250, also per developer per year. Add-ons such as DAST, API security and end-of-life support cost extra. The page mentions no free tier and offers demos on request. Renovate itself is open source, and a free cloud-hosted Community app exists. Sources: Mend pricing and the Renovate project.

Vigilance has a Free plan at $0 with the full scanner for up to 50 machines. Free needs a network and sends a signed report of hashes and capabilities only. A name, an email or a file is sent only if you opt in, and each one needs its own yes. Pro works with no network at all. It is flat for the whole company, starts at $999 CAD a month, and the price steps with company size, not with the machine count.

Which One Do You Need?

Mend guards public packages and your code against known bugs and reported threats. Vigilance guards everything on the machine against new behaviour. Run both.

Read how the two sit among other options in software supply chain security tools, or see real attacks that Vigilance replays.

Known Risk versus New Risk

Known risk

A bug or a bad package someone already reported, with a name and a number. Most tools work here.

New risk

A file that gained a capability it never had, that no report covers yet. Vigilance works here.

Common Questions

Is Vigilance a Mend alternative?

Yes, for one job. Vigilance shows the file that gained a new capability, on your own machine. It does not scan code or list known bugs, so it does not replace Mend SCA or SAST.

What does Vigilance do that Mend does not?

Vigilance compares the version you trust with a new one for any package, installer or container and reports the file that can now do more, with no list needed.

What does Mend do that Vigilance does not?

Mend finds known bugs, scans your code, flags malicious packages with threat intelligence and maintains Renovate. Vigilance does none of these.

How much does Mend cost?

Mend lists prices per contributing developer per year: up to $1,000 for AppSec, up to $300 for Mend AI and up to $250 for Mend Renovate Enterprise. No free tier is listed.

Does Vigilance need the internet or a cloud account?

The Free plan runs online. Pro runs fully offline, with no cloud account.

Try It on Your Own Software.

Show it the version you run today and the one you are about to install.

Download Vigilance Talk to Us

Talk to Us

A question, a pilot, or a bigger fleet? Send a note. It reaches a person.