AMarcinkowski942768 (Community Member) asked a question.

I see that the XML flaws have the comments in the annotation element. How do I get the annotations (comments) applied to SCA components in the detailed report XML? I don't see it in the schema.

Is this a missing feature? I tried all the other XML APIs but can't find the comments I applied to a component's vulnerabilities in the Veracode portal being passed down stream into our integration.


  • AMarcinkowski942768 (Community Member)

    Anyone from Veracode have any idea on this? A key part of our workflow involves management of components identified in the SCA. Without annotations, our workflow is stuck.

  • Hi @AMarcinkowski942768 (Community Member)​ ,

     

    I don't know if we expose the specific mitigations comments but we do expose whether a vulnerability has been mitigated, for example:

     

        <vulnerability

    cve_id="SRCCLR-SID-13642"

    cve_summary="...."

    cvss_score="10.0"

    cwe_id=""

    first_found_date="2019-10-07 09:56:34 UTC"

    mitigated_date="2019-10-17 13:39:57 UTC"

    mitigation="true"

    mitigation_type="Mitigate by Design"

    severity="5"

    severity_desc="Very High"

    vulnerability_affects_policy_compliance="false"/>

     

    Would this be sufficient for your workflow?

     

    Thank you,

    Boy Baukema

    Expand Post
    • AMarcinkowski942768 (Community Member)

      …I saw that but the issue I have is that what I want to annotate on the issue isn’t a mitigation at all but rather an internal tracking ID (JIRA) that is tied to actually resolving the vulnerability.
      • Ah okay, so you'd like to retrieve the comments attached to a vulnerability and the contents of that comment would be a Jira issue?

        I'm afraid I just checked with our Integrations team and we don't currently support this.

        Please create a Veracode Community Idea here: https://community.veracode.com/s/ideas .

         

        Thank you,

        Boy Baukema

        Expand Post
      • The use-case makes sense, exposing the mitigations and comments also makes sense, unfortunately it's just not implemented at the moment.

        I would recommend creating a new idea. Exposing the mitigations seems outside of the scope of the "Analytics on SCA" request and is not likely to be considered as part of it's implementation.

         

        Thank you,

        Boy Baukema

        Expand Post
      • AMarcinkowski942768 (Community Member)

        ….could you suggest a description for the idea that might actually make the road map? I was trying to piggy back on something that might cover what I needed, but I see your point.

        Thanks,

        Alan
        Expand Post
      • AMarcinkowski942768 (Community Member)

        …I tried to create a new idea on that page, and after two “submit” attempts that lost all the data I entered I gave up. Pressing submit on that page results in a “not found” ☹
10 of 13

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.