• Public

DevSecOps

Skip Feed
  1. ⚠️ Announcement: this group will be archived at the end of the week.

     

    We wanted to give you a heads-up that we’re archiving this user group at the end of this week, to help centralize discussions in the DevSecOps topical forum where you can continue to ask questions, exchange ideas, learn and share best practices, and get updates from the Veracode team.

     

    🔔To stay on top of new discussions on this topic, follow

    #DevSecOps​ and enable email notifications.

    Expand Post

  2. Hi all, Tim Jarrett, Sr. Director of Product Management for Veracode Platform here. I wanted to let you know that we're making some important changes to the way sandbox scanning works for static scans, based on your feedback and use of sandboxes.

     

    This feedback is meant to address the following:

    • Customers who create sandboxes as part of their automation can end up with an unmanageable number of sandboxes, making it difficult to work with the application or review results. 
    • It's challenging to find scans in progress across multiple sandboxes
    • Customers running several sandbox scans in an application at once may run into situations where some scans run longer because of queuing
    • There are few ways to automatically delete a sandbox
    • Sandbox scans remain and are redundant after promoting a sandbox scan to policy
    • Large numbers of sandbox scans can cause delays in publishing new scans, leading to unpredictable scan times.

     

    Over the next few releases, we'll add a number of features that will help address these issues. These include:

    • A new API call for deleting sandboxes. Released in December, the deletesandbox.do API call removes a sandbox and the scans inside.
    • Option to delete sandbox upon promotion. Released on January 28, 2020, this option allows you to cause a sandbox to be deleted when promoting a scan from the sandbox to policy. The option is available both through the UI and API.
    • Increased simultaneous sandbox scan limits. Coming soon, you will be able to conduct more sandbox scans in parallel, but the ability to queue additional scans after the maximum number is reached will be removed.
    • Better sandbox list UI. Coming soon, you will see everyone's sandboxes by default and will see the state of the latest scan in each sandbox.
    • Time to live for sandboxes. Coming soon, by default, newly created sandboxes will have a time to live, after which they will be automatically deleted. Some important notes on this feature:
      • If you have a pipeline that always scans into a sandbox with a fixed name (e.g. Release Candidate), you can set this sandbox to automatically recreate itself when it expires so your automation is not interrupted.
      • Data for deleted sandboxes and their scans will still be available in Veracode Analytics, so you can continue to track sandbox usage even after the sandboxes are deleted from the Veracode Platform.
    • Maximum number of sandboxes. Coming soon, Veracode will enforce a maximum number of sandboxes per application (25 by default).

     

    Together, these features will provide a balance of improved sandbox manageability, easier to find results, and better performance for all users of sandbox scans.

     

    If you have applications with more than the maximum number of sandboxes, your Veracode program manager will reach out to you to discuss how this functionality will be rolled out and to ensure that your Veracode scanning will not be disrupted. Please feel free to ask questions here as well!

    Expand Post

    1 of 9
    • Syazwan (Community Member)

      May I know what will happened on the excess sandbox, like we already have more than 25 sandboxes in an application, do Veracode will remove the excess ?

  3. 1 of 2

End of Feed
5 Chatter Feed Items

Group Details

Details

Description
By integrating development with IT operations and focusing everyone on making better decisions, development teams hope to deliver safer software with greater speed and efficiency. This group is meant to include discussions on how people are achieving safer software with both security and development engaged.
Show More
Information