Use Veracode in your IDE
Why use Veracode in your IDE?
- Prevent the net new introduction of flaws
- Burn down existing technical debt
- Manage 3rd party risk introduced during coding
- Prevent Net New Introduction of 3rd party Vulns
What does this unlock for me & my team?
- Developers can detect and fix security flaws as they write code
- Developers can detect and fix security flaws as they review code as part of their flaw burndown process
- Developers can review flaws existing on the Veracode platform and propose a flaw mitigation category as a temporary measure.
- Note: Flaws mitigated will no longer fail Veracode policy
- Developers can review vulnerabilities open-source libraries and dependencies, ensuring they are up to date and secure.
How: Paths to Success
Use Veracode in your IDE - documentation
Prevent the net new introduction of flaws
- After changes are made to your code in the project, run Veracode Static (SAST) and SCA scan
- Review and apply patch supplied by Veracode Fix
- From IDE source control changes, review fixes provided by Veracode Fix and choose fix to apply
- Rerun scan and confirm that the flaw has been fixed
- Review SCA vuln libraries and any licenses found
- Decide on corrective action based on company process
Burn down existing technical debt
- Run Veracode static and sca scan
- Review and apply patch supplied by Veracode Fix for targeted flaws
- Dependent on burn down strategy From IDE source control changes, review fixes provided by Veracode Fix and choose fix to apply
- Rerun scan and confirm that flaw/s has been fixed
- Review SCA vuln libraries and licenses found
- Decide on corrective action based on company process
- Download existing results and perform flaw mitigation proposal
Stop 3rd party risk from being introduced on workstations
- After Veracode Package Firewall has been installed - when packages are installed, only packages allowed by firewall policy will be installed
Manage 3rd party risk introduced during coding
- Run Veracode Static and SCA scan
- Review SCA vuln libraries and licenses found
- Decide on corrective action based on your company process
Scan & Fix in your IDE (Veracode Greenlight & IDE Plugins):
- π Scan and Fix in your IDE Learning Path (Est. 30+ min / Series)
- π IDE Plugins and Extensions (Also listed under Integrations) (Est. 5-15 min)
- π‘ Greenlight Best Practices (Est. 5-15 min)
Veracode Fix (AI code flaw remediation):
- β±οΈ Fix Quickstart Guide (Est. 2-5 min)
- βΉοΈ About Veracode Fix (Est. 5-15 min)
ο»ΏGuide Links:
- π Getting Started Guide (Start here)
- π§ Secure the SDLC with Veracode (where we fit, end-to-end)
- π§βπ» Application Security Testing Developer Workflow (scan β fix β verify)
- π§© IDE Scanning (find flaws while you code)
- π Repo / CI Scanning (automate scans in your pipelines)
- π‘οΈ Package Firewall (block risky open-source dependencies)
- π Veracode Risk Management (VRM) (prioritize, track, report)
.png)