App1 is built with Azure Pipelines and its source code in Azure Repos includes open-source libraries. Which tool should you use to detect security vulnerabilities in those open-source dependencies?
Choose an answer
Tap an option to check your answer.
Correct answer: Mend Bolt.
Why this is the answer
Mend Bolt (formerly WhiteSource Bolt) is a free Azure DevOps extension specifically designed to detect vulnerable open-source components and provide remediation advice directly within your Azure Pipelines. It integrates with Azure Repos to scan your code for known vulnerabilities in third-party libraries. Rollbar is an error monitoring and debugging tool, not a security scanner for open-source dependencies. Code Climate focuses on code quality and static analysis, not specifically open-source vulnerability detection. DeepSource is a static analysis platform for code quality and security, but Mend Bolt is purpose-built and tightly integrated for open-source dependency scanning within Azure DevOps.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed