When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
More information
Anyone from Veracode have any idea on this? A key part of our workflow involves management of components identified in the SCA. Without annotations, our workflow is stuck.
Hi @AMarcinkowski942768 (Community Member) ,
I don't know if we expose the specific mitigations comments but we do expose whether a vulnerability has been mitigated, for example:
<vulnerability
cve_id="SRCCLR-SID-13642"
cve_summary="...."
cvss_score="10.0"
cwe_id=""
first_found_date="2019-10-07 09:56:34 UTC"
mitigated_date="2019-10-17 13:39:57 UTC"
mitigation="true"
mitigation_type="Mitigate by Design"
severity="5"
severity_desc="Very High"
vulnerability_affects_policy_compliance="false"/>
Would this be sufficient for your workflow?
Thank you,
Boy Baukema
Ah okay, so you'd like to retrieve the comments attached to a vulnerability and the contents of that comment would be a Jira issue?
I'm afraid I just checked with our Integrations team and we don't currently support this.
Please create a Veracode Community Idea here: https://community.veracode.com/s/ideas .
Thank you,
Boy Baukema
Thanks.
The use-case makes sense, exposing the mitigations and comments also makes sense, unfortunately it's just not implemented at the moment.
I would recommend creating a new idea. Exposing the mitigations seems outside of the scope of the "Analytics on SCA" request and is not likely to be considered as part of it's implementation.
Thank you,
Boy Baukema
Thanks,
Alan
I'm sorry to hear that, @Shuning, Veracode Community Manager (Veracode) could you investigate this?
As soon as Idea submission is working again I will submit something on your behalf.