• TMitchell882797 (Community Member)

     

    @Glico Man (Community Member)​ Thank you for taking the time to answer this question. Forgive me for not mentioning it in my question, but with several application delivery teams currently employing automated static scanning, recurring dynamic analysis scans, automated Greenlight CI tool integration, and implementation of the Greenlight plugin on all developer IDEs, I completely agree with you that these proactive steps during the build process are absolutely the best defense in securing your applications before the ever reach production.

     

    However, this was not the crux of my question. My question was specific to IDE plugins for our frontend developers that do not work in Java and JavaScript which are the coding languages supported by the Greenlight IDE plugin. Since then I was able to locate and vet through our Veracode engagement team the Veracode for VS Code plugin that our frontend developers can rely on similar to the way that our backend developers rely on the Greenlight IDE plugin.

     

    Thank you again for taking the time to try and address this question.

    Expand Post
    Selected as Best
  • Glico Man (Community Member)

    Although Greenlight provide quick results turnover for developers in their IDE it also has limited language compatibility and provides limited coverage. Having said that, automating static code analysis within the build process (for example nightly) is best for a more comprehensive coverage and obtain policy-level compliance results. Scan results may then be imported (using API or development tools integration) into developers defect management systems for remediation or mitigation.

    Expand Post
    • TMitchell882797 (Community Member)

       

      @Glico Man (Community Member)​ Thank you for taking the time to answer this question. Forgive me for not mentioning it in my question, but with several application delivery teams currently employing automated static scanning, recurring dynamic analysis scans, automated Greenlight CI tool integration, and implementation of the Greenlight plugin on all developer IDEs, I completely agree with you that these proactive steps during the build process are absolutely the best defense in securing your applications before the ever reach production.

       

      However, this was not the crux of my question. My question was specific to IDE plugins for our frontend developers that do not work in Java and JavaScript which are the coding languages supported by the Greenlight IDE plugin. Since then I was able to locate and vet through our Veracode engagement team the Veracode for VS Code plugin that our frontend developers can rely on similar to the way that our backend developers rely on the Greenlight IDE plugin.

       

      Thank you again for taking the time to try and address this question.

      Expand Post
      Selected as Best
  • Glico Man (Community Member)

    Integration with development tools and automation is THE key for adoption and obtain good code posture for compliance.

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.