
TMitchell882797 (Community Member) asked a question.

TMitchell882797 (Community Member) asked a question.

Although Greenlight provide quick results turnover for developers in their IDE it also has limited language compatibility and provides limited coverage. Having said that, automating static code analysis within the build process (for example nightly) is best for a more comprehensive coverage and obtain policy-level compliance results. Scan results may then be imported (using API or development tools integration) into developers defect management systems for remediation or mitigation.

@Glico Man (Community Member) Thank you for taking the time to answer this question. Forgive me for not mentioning it in my question, but with several application delivery teams currently employing automated static scanning, recurring dynamic analysis scans, automated Greenlight CI tool integration, and implementation of the Greenlight plugin on all developer IDEs, I completely agree with you that these proactive steps during the build process are absolutely the best defense in securing your applications before the ever reach production.
However, this was not the crux of my question. My question was specific to IDE plugins for our frontend developers that do not work in Java and JavaScript which are the coding languages supported by the Greenlight IDE plugin. Since then I was able to locate and vet through our Veracode engagement team the Veracode for VS Code plugin that our frontend developers can rely on similar to the way that our backend developers rely on the Greenlight IDE plugin.
Thank you again for taking the time to try and address this question.

Integration with development tools and automation is THE key for adoption and obtain good code posture for compliance.
Ask the Community
Get answers, share a use case, discuss your favorite features, or get input from the community.
By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.
.png)
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.
These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.
@Glico Man (Community Member) Thank you for taking the time to answer this question. Forgive me for not mentioning it in my question, but with several application delivery teams currently employing automated static scanning, recurring dynamic analysis scans, automated Greenlight CI tool integration, and implementation of the Greenlight plugin on all developer IDEs, I completely agree with you that these proactive steps during the build process are absolutely the best defense in securing your applications before the ever reach production.
However, this was not the crux of my question. My question was specific to IDE plugins for our frontend developers that do not work in Java and JavaScript which are the coding languages supported by the Greenlight IDE plugin. Since then I was able to locate and vet through our Veracode engagement team the Veracode for VS Code plugin that our frontend developers can rely on similar to the way that our backend developers rely on the Greenlight IDE plugin.
Thank you again for taking the time to try and address this question.