Veracode for Developers
Getting Started with Veracode
Veracode provides several security testing tools to help you find issues at different stages of the development process, including Static Analysis to help find issues in the code you write, and Software Composition Analysis to find known vulnerabilities in open source libraries in your application. You can use different tools in different parts of the process.
Packaging an Application for a Veracode Scan
Veracode provides compilation and packaging recommendations for popular languages and frameworks to ensure you get the best possible results from your static or SCA scans. Refer to our Compilation Guide for how to archive and upload your binaries.
Integrating Veracode Into Your Development Process
Integrate Veracode into your existing development tools, from CI/CD tools to IDE. Refer to the Integration Guide to see the tools and versions that Veracode currently supports.
When writing code, use IDE Scan to catch errors as they’re introduced, or an IDE plugin to review findings from a prior scan.
When committing, building, and deploying code, use Pipeline Scans to evaluate the security of your first-party code directly within a CI/CD pipeline. The median scan time for Pipeline Scan is just 90 seconds. At this stage, you can also use Veracode SCA Agent to identify known vulnerabilities or license issues in your open source libraries.
Additional resources on Pipeline Scan:
- Documentation: Examples of Using Pipeline Scan - examples of incorporating Pipeline Scan into Gitlab, Github Actions, Azure DevOps, and Jenkins
- Videos:
- Run a Pipeline Scan in Your CI/CD Environment (2:06).
- Deep-dive on Veracode Static Analysis Pipeline Scan – why you might want to use the Pipeline Scan rather than a Sandbox or Policy scan.
- Whitepaper: The Right Scan, At The Right Time, In the Right Place - how Veracode fits seamlessly into development processes.
Performing a Policy Scan
In later stages of your pipeline or prior to release, you can perform a Policy Scan to evaluate your application against policy and generate a report that can be shared with auditors, customers, or other business stakeholders.
How Using Sandboxes Can Help You
Development Sandboxes provide the ability to scan applications and measure the results against the policy rules without affecting the policy compliance of the entire application. Sandboxes are a good place to perform pre-release security testing that references policy and includes mitigations as a “dry run” for the release (Policy) scan. Refer to Using the Development Sandbox.
Mitigating Security Findings
In some cases, Veracode may be missing some context that lowers the risk of a finding, such as an external security control; or your organization may have decided to accept the risk of a finding. In these cases, you can document a mitigation proposal that explains how the finding is mitigated. If your security lead agrees, he or she can approve the mitigation proposal to close the finding. See the additional resources here.
Fixing Security Findings
You can learn how to code more securely and fix findings already in your code via several resources:
Developer Training
- Veracode Security Labs: Interactive labs that give developers hands-on-keyboard practice they need to learn how to write secure code. Available as a free Community Edition or Enterprise Edition.
- Veracode eLearning: Video-based overviews of security concepts and language-specific topics suitable for non-technical team members.
Remediation Guidance
- Common Web Application Vulnerabilities
- Open Source Vulnerability Database
- Veracode Community - How to Fix Flaws discussions
Video Tutorials
Also Recommended
Resources that help you get started with Veracode, integrate, and remediate flaws.
Forums: New to Veracode, How to Fix Flaws, Integrations
Guide: Integrations Hub
← Go back to How to Use Veracode, an onboarding guide for new Veracode users
.png)