How to use Veracode in your Repo CI/CD
Why use Veracode in your Repo CI/CD?
- Avoid introducing new vulnerabilities into the codebase during the devlopment process
- More Efficient and Cost Effective to catch issues early
- Provides clear insights into security vulnerabilities
- Ensures compliance with organizational standards
- Allows developers to focus on coding while security scans run seamlessly in the background
What does this unlock for me & my team?
- The Developer gets immediate feedback on security issues as part of their normal workflow.
- Automated Scans: Analyze code in pull requests or branches.
- Actionable Insights: Provides in-line comments for detected vulnerabilities.
- Integration-Friendly: Works with supported repo Actions to embed security in CI/CD pipelines, or wrappers
- Finding Prioritization: Configurable to fail the builds that do not pass the security policy
How: Paths to Success
- 🚀 CI/CD Integrations (Est. 15-30 min)
- includes AWS, GIthub, Gitlab, Jenkins, Azure DevOps, & many others
- By integrating Veracode into your build and release pipelines, using tools such as Jenkins or Azure DevOps, you can test in the pipeline or in parallel. You can also stop the pipeline if Veracode finds security issues that violate your policy.
- 🔷 Azure DevOps App Documentation (Est. 5-15 min)
- Veracode REST APIs enable you to programmatically interact with the Veracode Platform to seamlessly incorporate application flaw, summary, and policy information into your compliance and risk management programs.
- Veracode XML APIs enable you to programmatically interact with the Veracode Platform to seamlessly incorporate application flaw, summary, and policy information into your compliance and risk management programs.
- The Veracode API wrappers are Veracode-developed CLI programs that can communicate with the Veracode XML APIs. You can use the API wrappers to accelerate the integration of the Veracode XML APIs in your software development lifecycle.
- Veracode provides Docker images for the Java API wrapper, Pipeline Scan, and for HMAC signing.
Guide Links:
- 🏁 Getting Started Guide (Start here)
- 🧭 Secure the SDLC with Veracode (where we fit, end-to-end)
- 🧑💻 Application Security Testing Developer Workflow (scan → fix → verify)
- 🧩 IDE Scanning (find flaws while you code)
- 🔁 Repo / CI Scanning (automate scans in your pipelines)
- 🛡️ Package Firewall (block risky open-source dependencies)
- 📊 Veracode Risk Management (VRM) (prioritize, track, report)
.png)