Start your First (Static) Scan in Five Basic Steps
Step 1: Get Access to Veracode
First, search your inbox for an email with the subject line, “Welcome to Veracode!” If found, simply follow the steps to log into the platform for the first time. If you’re unable to locate the email, contact your internal Veracode Admin, Veracode Security Manager, or contact our support team to submit a ticket for help getting set up.
Step 2: Get the Right User Roles Assigned to Your Account
If you are an Administrator for the Veracode Platform and would like to onboard an additional Administrator, make sure you add that individual to the platform as a user, then contact support to request that user become an Administrator to your account (only existing Administrators can make that request). From there, reference our managing users' video guide alongside our roles and permissions guide to apply the right roles to the appropriate user. If you’re not an Administrator but need Administrator access, please reach out to your pre-existing Administrators for assistance. (In most cases, the appropriate roles for developers will be Submitter, Reviewer, and Sandbox)
Step 3: Create or Find the Correct Application Profile to Scan In
An application profile is primarily used to separate flaw reports by application for ease of remediation. Think of an application profile as a container in which repeated scans of the same code base will be run. If you have the Creator user role, you can create an application profile, where you will be required to set the visibility and policy for that application. We suggest starting with Veracode Recommended Low or Medium Policy while completing your baseline scans and creating a custom policy once the program has matured to fit your company use case.
The policy can be changed at any time, and the rigor of the scan is always the same regardless of the policy set. Once you are further along in your AppSec journey and gain some insights based on your experiences, come back to this step and use this guide to help set the appropriate policy for your organization’s goals. Reach out to your security program manager to review your current policy and to get recommendations on where you can improve.
Step 4: Upload Your Application
Once you have found the correct application profile, find the “Start a Scan” button to begin uploading your app for scanning. Ensure “Auto-Scan after Pre-scan” is set to “Off.”
Make sure the app has been properly packaged per our Compilation Guide for the platform/languages you used to develop your application before initiating the pre-scan. Failing to follow the instructions from the Compilation Guide could result in undetected vulnerabilities due to improperly packaged modules not being read by our scanner, giving your team an inaccurate view of the security posture of the application.
Step 5: Review, Correct, & Select the Appropriate Modules
The first time a new code base is scanned, it’s necessary to conduct a manual review to help our scanner know when to start and stop scanning. The manual review of the code base ensures that all parts of the application are being scanned correctly – here at Veracode, we call this “Module Selection.”
The final step is to review the codebase that was uploaded to ensure that the proper components are selected for scanning (you will receive an auto-generated email once the pre-scan process has completed). During the pre-scan process, the team will need to select all modules that represent your first-party code and deselect any modules that represent third-party components that you do not want scanned via Static Analysis. Furthermore, you will need to review each module to ensure it has been packaged/compiled properly during Step 4. Using this guide, correct any errors found during the pre-scan process, re-upload the fixed files, and conduct the pre-scan again until you’ve cleared all the relevant warnings. Once this has been completed, you’re ready to start your first (static) scan!
Also Recommended
Forums where you can post questions, ask for advice, and get answers from other Veracode customers, static users or security managers:
← Go back to How to Use Veracode, an onboarding guide for new Veracode users
.png)