• Public
  • Broadcast OnlyThis group is for broadcast messages. Only group managers can post content.

Product Announcements

Skip Feed
  1. Welcome to the Veracode Product Announcements Group! This is where you’ll get weekly product news, a summary of recently released features and enhancements, and learn about upcoming changes with high impact on your Veracode experience.  

     

    Here are some tips to help you stay on top of the latest Veracode features and engage with the product team to impact our roadmap: 

     

    👉 How can I keep up with the latest Veracode release? 

    You can subscribe for weekly digest emails – a summary of new posts made in the Product Announcements group from the last week. Here’s how:   

    1. Join this group 
    2. Make sure your notification is set to “Weekly Digest”  

     

    👉 Where can I provide feedback about Veracode’s products and services? 

    As a Veracode customer, there are three ways you can engage with our product team and shape the future of our products: 

    • Submit your feature request to the Ideas portal. 
    • Apply for the Early Adopter Program to influence our upcoming features and products. 
    • Attend the product showcase series, including monthly product deep-dive and quarterly roadmap review webinars to share your ideas with the product team directly and learn how other Veracode users are using the products.  
    Expand Post
  1. Mike M (Veracode TPM) (Community Member) asked a question.

    📣 Static Analysis Product Updates - Upcoming changes for the August Release

    Next week's August Static Analysis Release includes the following:

     

    Updated language and framework support

     

    Android

    • Enhanced support for Android 16.
    • Improved third-party detection.

    Dart and Flutter

    • Adds support for hardcoded value detection in get assignments modeled as getter functions.

    Java

    • Improves Java scan performance when analyzing common template patterns.
    • Improved detection of CWE-78 flaws.

    JavaScript

    • Adds support for Next.js 16.x

    PHP

    • Enhanced detection of third-party code.

    PL/SQL

    • Improved scan performance.

    Python

    • Improves detection of hardcoded passwords and credentials (CWE-259 and CWE-798).
    • Adds support for the Python google-cloud-bigquery library.

    RPG

    • Improves remediation guidance for flaws associated with CWE-78, CWE-114, CWE-200, CWE-338, CWE-359, CWE-628, CWE-787, and CWE-823.
    • Improved detection of CWE-787 flaws to reduce false positives.
    • Improved RPG parsing.

    Other languages

    • Improves detection of CWE-259 and CWE-798 flaws across all languages to reduce false positives.

     

    Expand Post

    SamHouston likes this.

  2. SamHouston (Veracode) asked a question.

    Veracode Platform Updates - Aug 12, 2026

    A fresh batch of platform updates just landed across the Veracode portfolio. Here's what's shipped since August 5th — from smarter scan notifications to sharper DAST targeting and a more capable packaging runner for GitHub and GitLab integrations.

     

    EASM: Real-Time Scan Event Notifications

    Released August 5, 2026

    External Attack Surface Management (EASM) now sends real-time, in-app notifications the moment a scan completes, fails, or gets cancelled. No more manually refreshing scan status — security teams get an immediate signal, keeping threat surface monitoring responsive and shrinking the gap between detection and action.

    Notifications show up directly in the EASM interface, so teams can track scan outcomes without ever leaving the workflow.

     

    DAST: Business Unit Targeting and Scan Engine Enhancements

    Released August 6, 2026

    Dynamic Analysis (DAST) now lets teams assign a business unit when creating a web application or API specification target — or straight from the DAST configuration page. That makes it simple to organize and filter scan targets by business unit, a real win for organizations that need to align application security reporting with internal team and ownership structures.

    The DAST scan engine also got sharper, with improved detection for CAA record checks on SSL certificates for CWE-862 — applied across both Dynamic Analysis and DAST. Better detection means more accurate identification of certificate-related misconfigurations, so teams can close gaps before they're exploited.

     

    GitHub Workflow Integration: Check Runs Bug Fix (v2.1.2)

    Released August 6, 2026

    A minor release of the GitHub Workflow Integration (v2.1.2) fixes a bug where GitHub APIs weren't updating and reflecting the correct check runs status. With the fix in place, check run results now display accurately in GitHub — so developers and security teams can trust the status shown right in pull requests and commit views.

     

     

    Runner Image scm-packaging-5.0.0: Expanded Packaging for GitHub and GitLab

     

    A new default runner image — scm-packaging-5.0.0 — is now available for GitHub and GitLab repository integrations, replacing scm-packaging-3.0.0

    . The updated image brings a broad refresh of underlying components, expanding support for a wider range of project types and increasing overall project coverage across repo workflows.

    Updated components include:

    • Alpine v3.24.0
    • Ubuntu v26.04
    • .NET v10
    • PipEnv v2026.6.2
    • libicu v78
    • Node.js v22.22.1
    • Python v3.14.4

     

    GitHub Workflow Integration (v2.1.1) also introduces a new uninstallation workflow. Administrators can now uninstall the Veracode app from GitHub organizations directly through the Veracode Platform — streamlining lifecycle management without toggling settings in GitHub itself.

     

    GitLab gets the same scm-packaging-5.0.0 support, enhancing packaging capabilities in repo workflows and broadening the range of project types covered.

     

    That's the full set of updates since August 5th. For a complete history of platform changes, visit the Veracode release notes.

    Expand Post

  3. SamHouston (Veracode) asked a question.

    Pipeline Scan supports artifacts larger than 200 MB

    This update adds support for scanning packaged artifacts larger than 200 MB. No changes to existing integrations are required.

     

     

    https://docs.veracode.com/updates/r/c_all_static#pipeline-scan-supports-artifacts-larger-than-200-mb


  4. SamHouston (Veracode) asked a question.

    💻 NEW Security Labs Focus on OWASP Top 10 for LLM and Web Applications  

    We've released two new lessons: one covers the eighth OWASP LLM Top 10 category, helping developers identify and mitigate AI security vulnerabilities. The other challenges developers with broken access control in web applications. 

    • OWASP LLM 08: Vectors Without Borders (Flask) 
    • OWASP 1: Bad Cookie (Java) 

     

    Check out the release notes and course catalog to learn more.  


  5. SamHouston (Veracode) asked a question.

    Upcoming End of Support for Jira 9.x in the Veracode Integration for Jira (November 30, 2026)

    What does this mean?

    Beginning December 1, 2026, Jira Server and Jira Data Center 9.x versions will no longer be supported by the Veracode Integration for Jira. Customers running Jira 9.x should plan their upgrade path now to avoid disruption to support and compatibility.

     

    Required action

    To continue using a supported version of the Veracode Integration for Jira, upgrade to Jira 10 or later before November 30, 2026.

     

    Additional information

    After the support end date:

    1. Veracode will no longer test or validate the integration against Jira 9.x.

    2. Issues encountered on Jira 9.x may not be investigated or fixed.

    3. New integration enhancements and compatibility updates will be targeted toward supported Jira versions.

     

    For the latest supported version information, see the Veracode documentation: https://docs.veracode.com/r/c_jira_about#supported-versions

     

    If you have any questions about this change or need assistance planning your upgrade, please contact Veracode Support.

     

    Expand Post

  6. SamHouston (Veracode) asked a question.

    Introducing Veracode Marketplace & DryRun Security

    Today Veracode launched the Veracode Marketplace — a curated ecosystem of security integrations built for the AI-powered software development era. Every partner is vetted for technical depth and workflow fit, every integration is anchored to Veracode findings for a unified audit trail, and every purchase runs through a single contract.

     

    DryRun Security joins as the inaugural partner, bringing AI-native code analysis that reasons across intent, behavior, and application context. The marketplace is available to all customers today, with additional partners joining throughout 2026.

     

    Learn more here: https://www.veracode.com/partners/marketplace/

    Expand Post

  7. SamHouston (Veracode) asked a question.

    2026 GenAI Code Security Report

    Today Veracode releases the second annual benchmark of AI model security performance — and the findings tell a story that every developer, security team, and engineering leader should sit with for a moment.

     

    The full report is available now at the link below. Dig into the model-by-model breakdowns, the vulnerability category data, and what the trend lines say about where this is all heading.

     

    👉 2026 GenAI Code Security Report

     

    Nearly 1 in 2 AI-generated code tasks still introduces a known vulnerability.

     

    That's not a headline designed to alarm. It's the result of testing 100+ models across four programming languages and four vulnerability categories — with a methodology consistent enough to make the trend data genuinely reliable. The number hasn't moved much since 2023.

    Here's where it gets interesting: bigger doesn't mean safer. Large, medium, and small models all cluster within the same narrow band — 51–53% security pass rates. Coding-specialized models? They average 51%. General-purpose models? 52%. The gap is essentially noise.

    What has changed is scale. Organizations adopting AI tools are shipping dramatically more code — which means the failure rate stays flat while total vulnerability volume climbs. Teams aren't seeing fewer bugs. They're seeing more of them, faster.

     

    The takeaway for any team evaluating AI tooling: swapping models won't solve the security problem. The fix lives in the workflow — in scanning the code that AI produces, at the speed AI produces it.

     

    Expand Post

  8. SamHouston (Veracode) asked a question.

    DAST Custom Host Release – July 22, 2026

    Customers can now configure custom host-to-IP address mappings for DAST scans. This is useful when DNS lookup is unavailable or when a customer wants to bypass DNS resolution during scanning.

     

    Release Notes: https://docs.veracode.com/updates/r/c_all_was#dast-custom-host-to-ip-address-mappings

     

    Documentation: https://docs.veracode.com/r/Configure_URLs_for_web_application_scans#configure-host-to-ip-address-mappings

    Expand Post

End of Feed
8 Chatter Feed Items

Group Details

Details

Description
This group is for announcements and discussions of recent and upcoming Veracode release.
Show More
Information
  • Join the group and customize your notifications to receive daily or weekly digest emails.  
  • For all technical functionality and how-to questions please post to product Q&A forums.   
  • For product feedback, new feature requests, please post to Ideas
Show More