Grace Period in New Policy
Example Scenario :
Completed initial scan 1st January - containing high and very high flaws (failed policy as it does not allow ANY high or very highs) - policy has grace period as zero days.
Applied a newer policy to the same scan on the 17th May WITH grace periods of 150 days (end of May) for high and very high flaws (policy still does not allow ANY high or very highs)
In the above use case following will happen:
When the new policy is applied on the 17th of May it shows as a conditional pass with an orange shield (not failed with a red shield as it did previously).
At the end of May, (if none of the flaws have been fixed,) the scan then moves back to a failed state with a red shield as the 150 day grace period has elapsed.
Further, if there was also a scan that happened in March, that found a few new flaws that would fail policy, those flaws would not cause policy failure until the end of July.
Topics (1)
Related Articles
.NET Remediation Guidance for CWE-915 6.41KNumber of Views SCA issues found on workspace view not matching project view 573Number of Views SCA - Unrecognized License 700Number of Views Is it possible to know what percentage of an application is scanned? 1.35KNumber of Views What is the max name length characters we can have when we define one of the following in the Veracode platform? - Applica… 394Number of Views
This topic isn't available in this community.
Related Topics
Ask the Community
Get answers, share a use case, discuss your favorite features, or get input from the Community.
.png)