Veracode for Developers

This guide includes all resources developers need to get started with Veracode.


Getting Started with Veracode

Veracode provides several security testing tools to help you find issues at different stages of the development process, including Static Analysis to help find issues in the code you write, and Software Composition Analysis to find known vulnerabilities in open source libraries in your application. You can use different tools in different parts of the process.


Packaging an Application for a Veracode Scan 

Veracode provides compilation and packaging recommendations for popular languages and frameworks to ensure you get the best possible results from your static or SCA scans. Refer to our Compilation Guide for how to archive and upload your binaries. 


Integrating Veracode Into Your Development Process 

Integrate Veracode into your existing development tools, from CI/CD tools to IDE. Refer to the Integration Guide to see the tools and versions that Veracode currently supports. 


When writing code, use IDE Scan to catch errors as they’re introduced, or an IDE plugin to review findings from a prior scan.


When committing, building, and deploying code, use Pipeline Scans to evaluate the security of your first-party code directly within a CI/CD pipeline. The median scan time for Pipeline Scan is just 90 seconds. At this stage, you can also use Veracode SCA Agent to identify known vulnerabilities or license issues in your open source libraries.


Additional resources on Pipeline Scan:


Performing a Policy Scan

In later stages of your pipeline or prior to release, you can perform a Policy Scan to evaluate your application against policy and generate a report that can be shared with auditors, customers, or other business stakeholders.


How Using Sandboxes Can Help You 

Development Sandboxes provide the ability to scan applications and measure the results against the policy rules without affecting the policy compliance of the entire application. Sandboxes are a good place to perform pre-release security testing that references policy and includes mitigations as a “dry run” for the release (Policy) scan. Refer to Using the Development Sandbox. 


Mitigating Security Findings

In some cases, Veracode may be missing some context that lowers the risk of a finding, such as an external security control; or your organization may have decided to accept the risk of a finding. In these cases, you can document a mitigation proposal that explains how the finding is mitigated. If your security lead agrees, he or she can approve the mitigation proposal to close the finding. See the additional resources here


Fixing Security Findings

You can learn how to code more securely and fix findings already in your code via several resources:


Developer Training
  • Veracode Security Labs: Interactive labs that give developers hands-on-keyboard practice they need to learn how to write secure code. Available as a free Community Edition or Enterprise Edition.
  • Veracode eLearning: Video-based overviews of security concepts and language-specific topics suitable for non-technical team members.


Remediation Guidance


Video Tutorials

Also Recommended

Resources that help you get started with Veracode, integrate, and remediate flaws.

Forums: New to Veracode, How to Fix FlawsIntegrations

Guide: Integrations Hub


← Go back to How to Use Veracode, an onboarding guide for new Veracode users