pkg.soopen package index

cask / rank 6575

Install mend with Homebrew Cask

Application security scanning CLI. Version 26.8.2-hf1 via Homebrew Cask; verified 2026-09-09.

install

Additional install commands

macOS

Homebrew Caskverified · 100%
brew install --cask mend

local Homebrew cask metadata

overview

Package summary

Application security scanning CLI

Commands and aliases

  • mend

history

Project history and usage

Mend CLI is Mend.io's command-line application-security scanner. It runs dependency, source-code, and other supported security analyses locally or in CI and can upload findings to the Mend Platform.

Project history

Mend developed the CLI as a unified entry point for software-composition analysis, static application-security testing, and related Mend services. Its release notes document an actively maintained calendar-versioned product, while migration documentation describes consolidation of older Unified Agent workflows into the CLI.

Adoption history

Mend positions the CLI as its automation-oriented interface for application-security scans in developer workstations and CI/CD pipelines. Official migration guidance recommends it as the successor to workflows built around the older Unified Agent.

How it is used

Users authenticate interactively with `mend auth login` or supply `MEND_URL`, `MEND_EMAIL`, `MEND_USER_KEY`, and, when needed, `MEND_ORGANIZATION` in automation. Commands such as `mend dep` run supported scans, while `mend config` manages automatic-update and proxy settings.

Why package nerds care

The package is notable as a self-updating, vendor-distributed security scanner packaged as a Homebrew cask rather than a conventional source-built formula. It exposes several scanning engines through one executable and supports non-interactive environment-variable authentication for CI.

Timeline

  • 2024: Official documentation describes Mend CLI migration paths from the Unified Agent.
  • 2026-03: Authentication is unified across Mend scan engines.
  • 2026-07: The input package record reports release 26.7.1-hf1.

Related projects

  • Mend Unified Agent is the legacy scanner addressed by the official migration guide.
  • The Mend Platform receives and presents scan results uploaded by the CLI.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for mend. Package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
mendbinaryHomebrew cask binarymend

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-09-19
manager version26.8.2-hf1
manager updated2026-09-09
local dataok
upstreamnot checked
latest detectednot detected

https://www.mend.io/

  • infoRelease/tag comparison is only available for GitHub repositories.https://www.mend.io/none confidence

install metadata

Package metadata

Package keycask:mend
Version26.8.2-hf1
Package managerHomebrew Cask
Package manager pagehttps://formulae.brew.sh/cask/mend
Homepagehttps://www.mend.io/
Upstream docshttps://www.mend.io/
Source archivehttps://downloads.mend.io/cli/darwin_arm64/mend
Last updated2026-09-09T13:59:39+02:00
Pulseupdated
SHA-256ec29c49813d45bcf16ae0a579a473965b5fa0cfe9a9d3c3bfbcb4e4ed7805a37
Download URLhttps://downloads.mend.io/cli/darwin_arm64/mend
Bottlenot recorded
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew cask API
Taphomebrew/cask
Full Tokenmend
Names
  • mend
Artifacts
Deprecatedno
Disabledno

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • cross-ecosystem install command graph
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database