• Public

Veracode Base Camp

Skip Feed
  1. Pinned Post

    Welcome to your Veracode Base Camp🏕️ 🙂 ! We’re here to help as you get started with Veracode. A few things to begin with:  

     

    👋 And don't forget to say hello and introduce yourself to the community! 

    Expand Post

  1. Application Security Testing - Business Outcomes, Goals and Objectives

     

    We've created a PDF document that walks customers through the process of planning their AppSec program with Veracode. This doc will guide you through planning your program around your business's goals, objectives, and the outcomes you want to drive towards.


  2. DQuince102705 (Community Member) asked a question.

    Is it possible to pass in a parameter to the API spec an API dynamic scan?

    Right now, the file_id parameter gets a dynamic value and causes the validation to fail. If we hardcode to a known value, it works. Is it possible to pass in a parameter to the API spec an API dynamic scan to replace the file_id parameter?

    Ty

      "/{file_id}/actions": {

       "get": {

        "summary": "GetActionsByFile",

        "description": "Gets actions on a file.",

        "operationId": "21825749",

        "parameters": [

         {

          "name": "file_id",

          "in": "path",

          "required": true,

          "schema": { "type": "string" }

         }

    Expand Post

    • SamHouston (Veracode)

      Hi @DQuince102705 (Community Member)​ - Updating the API spec before each scan with the required hard coded value OR using a postman collection that contains a flow that fetches the value for file_id and reuses the value in subsequent calls. Not a postman expert myself, but there should be plenty of generic postman documentation out there to check if that's a possibility.

  3. GSengodan192690 (Community Member) shared a post.

    Shared Post

    GSengodan192690 (Community Member) asked a question.

    System.IO.TextWrite.WriteLine() - Usage error (CWE Code : 209 Generation of error message containing sensitive information)

    Hello Community,

     

    We have a .NET application in which The application is not using System.IO.TextWrite.WriteLine() anywhere But while doing Veracode static scan the report says "The application calls the mscorlib_dll.System.IO.TextWrite.WriteLine() function, Which may expose information about the application logic or Other details such as names and versions of the application container and associated components. "

     

    This is the assembly name Antlr3.runtime.dll where Veracode reported the flaw.

     

    Below is the Flaw details:

    CWE Code : 209 Generation of error message containing sensitive information

     

    Please advise on the above issue.

     

    Thank you,

    Gunasekaran

    View Original Post
    • 1 answer
    • 2.5K views

  4. DEllis (Community Member) asked a question.

    SAML Set Up

    I am trying to set up SAML integration and saw that the documentation says that Relaystate URL, Audience URL, and Target URL can be found in the SAML tab of the Admin interface. I do not see those three fields in my interface and am wondering if I am doing something wrong or if I am missing something. Any help?


    • LZandman904529 (Community Member)

      Did you already upload a certificate? Because that triggers the display of additional settings.

End of Feed
8 Chatter Feed Items

Group Details

Details

Description
New to Veracode? Ask questions and get help from expert users as you begin your Veracode journey.
Show More
Information

Find resources, get help, and most importantly, meet peers who are getting started or have been where you are and are ready to help. Check out: 

✅  VeraTips – new tip added frequently.  

📺  Webinars – product walk-through and live Q&A, sign up here. 

🙆  Quick Start Guide - check out Veracode for Developers.

Show More