Customer Stories
Microsoft uses Mend for open source security
HIGHLIGHTS:
- Relies on Mend to give high quality recommendations with very low false positive rates.
- The detailed remediation advice enables Microsoft engineers to quickly upgrade their packages.
- Able to scale to the ecosystems that we want to cover. Overall…a great decision.
The Challenge
Microsoft developers use a lot of open source software โ over 80,000 distinct open source packages are used over 11 million times in Microsoftโs entire code base.
To help Microsoftโs 85,000 developers be confident in their use of open source software, the Microsoft 1ES team โ which selects and manages all the tools that Microsoft developers use โ was tasked with finding the best open source software security tool. They wanted a tool that was extremely accurate, easy to use, and provided actionable recommendations for how to fix vulnerable open source packages.
The Solution
Microsoft chose Mend for several reasons:
1) High accuracy. According to Magnus Hedlund, the Director of Engineering for the 1ES team at Microsoft: โThe easiest way to lose a developerโs trust is to give them a false positive. If you give false positive results, developers will tune out that tool and not look at it again. Microsoft relies on Mend to give high quality recommendations with very low false positive rates.โ
2) Ease of use. Magnus Hedlund again: โWe integrate Mend vulnerability detection directly into the developerโs workflow. Without developers doing anything, we automatically scan for vulnerabilities and notify them of their vulnerable code.โ
3) Great remediation advice. โIdentifying the vulnerabilities and telling developers they have a problem is useful, but if you donโt tell them how to fix it, they canโt make it better. Without the remediation recommendation there is no point raising a number of alerts that nobody can do anything about. The detailed remediation advice provided by Mend enables Microsoft engineers to quickly upgrade their packages to less vulnerable versions.โ
“Microsoft relies on Mend to give high quality recommendations with very low false positive rates.โ
Magnus Hedlund, Director of Engineering – 1ES team
The Results
Bryan Sullivan, manager of Microsoftโs 1ES security tooling group said: โMend plays an integral part in helping us identify where weโre using potentially risky or insecure open source and getting that addressed as early as possible. We rely on Mend for great remediation guidance. Remediation guidance is extremely critical to helping developers fix the problem correctly the first time, every time.โ
Poonam Gupta, the Director of Microsoftโs 1ES team said: โWorking with Mend has been the right decision. When we have the right set of recommendations, we feel more secure. Mend has been able to scale to our needs. Itโs been able to scale to the ecosystems that we want to cover. Overall itโs been a great decision.โ
“Mend has been able to scale to our needs. Itโs been able to scale to the ecosystems that we want to cover. Overall itโs been a great decision.”
Poonam Gupta, Director of Microsoftโs 1ES team
About Microsoft
Microsoft is one of the worldโs best known corporations. They produce computer software, consumer electronics, personal computers, and related services such as cloud services. Microsoft employs 181,000 people worldwide, including about 85,000 software developers.