What is a scannable module?
Every scan with Veracode Static Analysis is comprised of two parts:
- Pre-scan (typically takes 5 to 10 minutes), which results in a module selection
- Analysis, which results in the actual flaws
In the pre-scan, it analyzes your upload for what we call Scannable Modules.
A loose definition:
"A collection of inter-dependent files, scannable as one independent unit, optionally identified by a potentially user-facing entry point."
When we analyze the upload of static languages, we will typically create several modules of either of the following categories:
- A top-level module, our heuristics have determined that this may be user-facing. Typically means this group of files with this entry point does not have anything call into it.
- A dependency module, hidden by default in our UI, this file or groups of files are called by other files in the upload.
Topics (1)
Related Articles
What is prescan verification? 695Number of Views Web.War Module 545Number of Views FAQ: How long does Veracode store customer binaries? 691Number of Views Forced Validation Paradigm 3.83KNumber of Views Is it possible to know what percentage of an application is scanned? 1.32KNumber of Views
This topic isn't available in this community.
Related Topics
Ask the Community
Get answers, share a use case, discuss your favorite features, or get input from the Community.
.png)