• MPeitz503616 (Community Member)

      Yes I am using Visual Studio 2017. It's interesting I am looking at the same code that came back with issues from a veracode static scan. When I run greenlight on the code it does not show that it has issues. So there is a disconnect. If I run a green light scan on a code file that is in C# the results match between the Veracode Scan and the Green light scan.

      • Hi @MPeitz503616 (Community Member)​ , the "discrepancy" in scan results between Greenlight Scan and Static Scan is expected. Check the feedback from @Veracode Support (Veracode, Inc.)​ from our support team:

         

        "Greenlight scans just that page of code, while static scans the entire app and will scan all the data paths. This will always yield more flaws than when you see in Greenlight since Static Scan is taking the entire scope into the Scanner, instead of just that one file.

         

        Think of it like this, a room in a house is the file. The room looks secure when greenlight scans it since the room's door IS locked. However, once the Static scanner scans the entire house, they find an unlocked door to the house itself outside of that one room. Now that one room is no longer secure since outsiders can get into the house and essentially kick down this petty locked door. so the flaw is marked on the file (room) since the entire scope (house) has now been scanned for flaws."

         

        Does that make sense?

        Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.