• DeCaPa (Community Member)

    I've asked this question before, as it relates to UI's and Microservices. Where each is in a separate profile. The Verified form only asks for the URL (UI) and no supporting application profiles. It might lead one to believe that only one profile needs to meet the Verified requirement. However after my inquiry, I found that it is necessary for all profiles to meet requirements. It is just that the online form can only support one. So, until that gets corrected, you should reach out to a "Veracode human" that knows Verified to submit your list of application profiles that roll up into a single app.

     

    You mentioned MQTT, cloud, mobile, etc, remember that you can only use Veracode to scan supported languages and URL's (DAST). It supports Android/iOS, many web languages, but not MQTT (afaik). So, anything that doesn't have an associated app profile would not be included.

     

     

    Expand Post
  • Asha, Customer Engagement (Veracode, Inc.)

    Hello @PBannister179056 (Community Member)​ - The process for requesting an application be considered for the Veracode Verified program is by submitting the Verified Request form located under the "Verified" option in the top navigation, first option "Application form". As @DeCaPa (Community Member)​ mentioned, the form assumes that the full application is scanned under a single application profile. We will be making updates to this format to accommodate when a single "commercial-version" of an application is scanned across multiple application profiles. Until that update is available, my recommendation is to use the free text field at the bottom of the form to include all the application profiles which the components of this single application is currently scanned. Does this help answer your question?

    Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.