Use Veracode in your IDE

Why use Veracode in your IDE?


  • Prevent the net new introduction of flaws
  • Burn down existing technical debt
  • Manage 3rd party risk introduced during coding
  • Prevent Net New Introduction of 3rd party Vulns

 

What does this unlock for me & my team?


  • Developers can detect and fix security flaws as they write code
  • Developers can detect and fix security flaws as they review code as part of their flaw burndown process
  • Developers can review flaws existing on the Veracode platform and propose a flaw mitigation category as a temporary measure.
  • Note: Flaws mitigated will no longer fail Veracode policy
  • Developers can review vulnerabilities open-source libraries and dependencies, ensuring they are up to date and secure.

 

How: Paths to Success

Use Veracode in your IDE - documentation


Prevent the net new introduction of flaws

  • After changes are made to your code in the project, run Veracode Static (SAST) and SCA scan 
  • Review and apply patch supplied by Veracode Fix
  • From IDE source control changes, review fixes provided by Veracode Fix and choose fix to apply
  • Rerun scan and confirm that the flaw has been fixed
  • Review SCA vuln libraries and any licenses found
  • Decide on corrective action based on company process


Burn down existing technical debt

  • Run Veracode static and sca scan
  • Review and apply patch supplied by Veracode Fix for targeted flaws
  • Dependent on burn down strategy From IDE source control changes, review fixes provided by Veracode Fix and choose fix to apply
  • Rerun scan and confirm that flaw/s has been fixed
  • Review SCA vuln libraries and licenses found
  • Decide on corrective action based on company process
  • Download existing results and perform flaw mitigation proposal


Stop 3rd party risk from being introduced on workstations

  • After Veracode Package Firewall has been installed - when packages are installed, only packages allowed by firewall policy will be installed


Manage 3rd party risk introduced during coding

  • Run Veracode Static and SCA scan 
  • Review SCA vuln libraries and licenses found
  • Decide on corrective action based on your company process


Scan & Fix in your IDE (Veracode Greenlight & IDE Plugins):


Veracode Fix (AI code flaw remediation):







ο»ΏGuide Links: