New Flaw Enhancement - Flaws appearing in duplicate files
What is it?
Veracode recently released a change to the platform where we are now showing more flaws. With this change, we are exposing duplicate flaws that appear in duplicate files. For example, if an application has two identical files “MyCode.java” in two separate areas of an application, Veracode will now show the user flaws that exist in both instances of the file, as oppose to just showing the flaws in one of the files.
Why was this change released?
The reason we released this change is to make sure that customers are aware of all flaws in their application, regardless of whether or not they have already seen a flaw in a duplicate file in their application. We want to give our customers full disclosure when it comes to the flaws in their application.
I have suddenly received a lot more flaws. How should I be handling this?
The best way to figure out how to mitigate these new flaws is to identify which files in your application are duplicates. The change in this enhancement is exposing flaws that already exist in other files in your application. Resolving flaws in files that are duplicated throughout the application, or removing unnecessary duplicate files can bring down the flaw count faster.
Topics (0)
Related Articles
License Issues is green, but licenses show high license risk 989Number of Views Developer Resources 537Number of Views App not in a state where new builds are allowed 4.97KNumber of Views Updating Veracode Level 375Number of Views What It Means to Remediate vs Mitigate a Flaw? 1.49KNumber of Views
This topic isn't available in this community.
Related Topics
Ask the Community
Get answers, share a use case, discuss your favorite features, or get input from the Community.
.png)