Software Composition Analysis Group (Archived) — Javier Perez (Veracode)
Hi, here a list of our major Veracode SCA product deliverables in Q4 (Oct-Dec 2019), more information can be found in help.veracode.com:
Go Modules Support:
In addition to package managers Glide, GoVendor, GoDep, GoGet, Dep, and Trash, SCA now supports Go Modules – the widely used package manager for Golang.
Windows Support:
The SCA Agent for Windows which is currently supported has been enhanced for complete feature parity with the list of languages and features available in the agent for other operating systems.
Gradle Support:
SCA supports the latest version of Gradle that includes support for “implementation” as the dependency configuration.
New Roles – Workspace Editor and Submitter:
Two new roles have been introduced in the new Integrated SCA product – Veracode Workspace Editor and Veracode Submitter
Veracode Workspace Editor inherits a subset of capabilities of the Workspace Administrator.
A Veracode Workspace Editor has permissions for all Workspace Administrator tasks except:
- Adding teams to workspaces
- Editing workspaces
- Deleting workspaces
Veracode Submitter - This new role enables agent management without providing permissions to view the results. The Veracode Submitter can:
- View the SCA portfolio page
- Create agents
- Rename agents
- Regenerate agent tokens
- Delete agents
Doc Link: https://help.veracode.com/reader/RXjxbTR2MDQdN3gX4l53CQ/_8oXXhMujVU63_VFWcTC9g
SCA Agent API:
Over that last 2 quarters we have been adding more features to the Agent API (formerly SourceClear API), not only making available scan results at workspace and project level, but also administration features. Take a look at the Swagger documentation.
https://app.swaggerhub.com/apis/Veracode/veracode-sca_agent_api_specification/3.0
CVSS v3 in Application Upload and Scan:
Vulnerabilities in app upload and scan will now have both CVSS v2 and CVSS v3 ratings for viewing.
Customers can choose between v2 and v3 when browsing the ‘Third-Party Components’ and ‘Vulnerabilities’ tab.
The CVSS version used in SCA Policies is, however, set at the organizational level by Veracode’s customer support. This version once set is uniformly applicable all policies. The version that is in use for Policy is listed in the ‘CVSS Version’ column in SCA’s application scan reports.
Doc link: https://help.veracode.com/reader/9nOkCbEfhLEzMgzr2zCv5Q/S8NjhjaQXsKaGfjQ~Wy4mg
.png)
Roles will greatly help to manage large teams and workspaces. Thanks!