• Public

Static Analysis Group

Skip Feed
  1. ⚠️ Announcement: this group will be archived at the end of the week.

     

    We wanted to give you a heads-up that we’re archiving this user group at the end of this week, to help centralize discussions in the Static Analysis topical forum where you can continue to ask questions, exchange ideas, learn and share best practices, and get updates from the Veracode team.

     

    🔔To share feedback and stay on top of new discussions about Static Analysis, follow #Veracode Static Analysis​ and enable email notifications.

    Expand Post

  2. 📣 Static Analysis Product Updates - February 2021 Release

    Hi everyone-

     

    Last week we had another of our monthly static engine updates. This includes support for a new language and several other valuable updates!

     

    • Transact-SQL Support
    • Initial support for .NET 5
    • Kotlin 1.4 support
    • Initial support for Groovy 3
    • EmberJS version 3 support
    • Improved results for iOS 14 apps
    • Updated rules for acceptable cryptographic settings in Java apps

     

    Our next release will be at the end of March. Have a great month!

     

    @Static Analysis Group (Archived)​ 

    Expand Post

    1 of 4
    • mwaldis335267 (Community Member)

      Hi jon,

      What is being scanned in .net 5, I thought this was all open source , maybe I am missing something?

      thanks

  3. 📣 Static Analysis Product Updates - January 2021 Release

    Hi Everyone -

     

    Last week we released our first static engine update for 2021. This included support for several new versions of platforms and numerous accuracy updates. Some specifics...

    • Support for GCC 9 on RedHat 8
    • Support for the Autofac inversion of control library for .NET
    • Support of Koa.js version 2.13
    • Support for Hibernate Framework version 5

     

    Accuracy Improvements for:

    • Android
    • Java apps packaged as WAR and EAR files
    • JSP apps
    • Python
    • PHP

     

    Improved pre-scan warning messages for several common packaging mistakes.

     

    Our next static release is scheduled for early March. Have a great week everyone.

     

    @Static Analysis Group (Archived)​ 

    Expand Post

    UScholz and VCode like this.
    1 of 7
    • VCode (Community Member)

       

      "Improved pre-scan warning messages for several common packaging mistakes."

       

      this is great, it really helped me thanks

       

  4. ⚠️ Announcement: Deprecation of legacy Pipeline Scan API - Action Needed

    On April 1 2021, Veracode will cease to support versions of pipeline-scan.jar that were distributed earlier than September 2020. These are versions 20.9.1 and earlier. You can identify the version of pipeline-scan.jar that you are using by running it with the "--version" option at the command line.

     

    The process of transitioning to a supported version is straightforward – just replace the version of pipeline scan that you are using with the latest one, which can be downloaded here: https://downloads.veracode.com/securityscan/pipeline-scan-LATEST.zip

     

    Veracode also provides a docker image that includes pipeline scan, which can be found on Docker Hub

     

    Updating to the latest version of pipeline-scan.jar will also ensure that you are working with the latest version of our software, which includes many new features and bug fixes, including the helpful policy integration feature which we just released in December.

     

    Please perform this upgrade in the next 60 days in order to continue to access the pipeline scan service.

     

    Thank you and please let me know if you've got any questions!

     

    @Static Analysis Group (Archived)​ @Product Announcements​ 

    Expand Post

    EGertis462759 and VCode like this.

  5. 🚩Weekly Product Update: Pipeline and Policies

    Hi everyone!

     

    There are a few updates we made to our Static Analysis solution this week that we'd like to share with you. Let us know if you have any questions/feedback.

     

    ◾️Pipeline Scan Now Integrated with Security Policies 

    #Pipeline Scan​ now supports the use of policy rules defined in the Veracode Platform. This enhancement allows you to assess applications against consistent rules for pass or fail. 

     

    ◾️Compilation Guide Renamed 

    To more accurately describe its contents, the Compilation Guide is now called Veracode Packaging Requirements

     

    @Static Analysis Group (Archived)​ 

    Expand Post

    rlloyd, lucas.ferreira, and VCode like this.

  6. 👋 Say hello and share with us: what do you like to learn in the community?

    Welcome to the Veracode Community 👋 😊

     

    First of all, we’re so glad you’re here! We hope you find the community a safe, helpful, and fun place to learn all things Veracode and improve your AppSec skills. We’ve all been beginners at some point and we’re here to learn. Don’t be afraid to ask any questions – no question will ever be considered too basic here. 

     

    What makes your community experience special is knowing who you’re talking to and learning from. Help your peers get to know you by sharing: 

    • Where are you from? 
    • What's your role in your company?
    • How long have you been using Veracode?
    • What topics do you like to learn more about in the community?

     

    @Veracode Base Camp​ 

    Expand Post

    tri45m, dlawson, and 6 others like this.
    1 of 80
    • DThibodeaux303597 (Community Member)

      Hi everyone, my name is Doug T and I'm new to this community. I'm excited to be here and connect with other people who share my interests in Veracode. I'm looking forward to learning from each other and helping support others on this journey. How long does it normally take to get up to speed using Veracode?

  7. Seeking developer feedback!

    Hi all -- Jon from the product management team here.

     

    I'm looking to talk to some developers and devops engineers about their experience setting up analysis of their applications for the first time. We’d also like to discuss your source control and application build process, and experience of automating scans & scan reporting.

     

    This is to help plan future product capabilities - so your feedback would be appreciated! Either comment in here or send me a note privately at jjanego@veracode.com

     

    Thank you!

    Expand Post

    VCode likes this.

  8. JGallagherNuance (Community Member) asked a question.

    More annotations (custom cleansers) for other flaw types?

    The Veracode Annotations library is a super convenient way to automatically propose mitigations for flaws that I know to be false-positives, but it only covers a small number of flaws, such as CWE-73 (External control of file path). Can we get more annotations? For example we have CWE-506 (embedded malicious code) which is being flagged for something we coded that solves a business use case, and I'd like to put an annotation on it so that it is automatically mitigated in subsequent scans.


    VCode likes this.
    • Hi @JGallagherNuance (Community Member)​ ,

       

      We're glad you're finding the Custom Cleanser feature useful. More custom cleanser support is not currently planned as there are many other things we're working on but I would strongly recommend proposing this as an idea in the Veracode Community as this is used as input by Veracode Product Management. Please consider registering your idea with Veracode Community Ideas at https://community.veracode.com/s/ideas .

       

      Thank you,

      Boy Baukema

      Expand Post

End of Feed
8 Chatter Feed Items