• Hi @APrieto034095 (Community Member)​ ,

     

    From our Packaging Instructions for JavaScript or TypeScript:

     

    > Veracode requires that you submit JavaScript as source code in a format readable by developers. Build steps that minify, obfuscate, bundle, or otherwise compress JavaScript significantly affect the quality of analysis results.

     

    * https://help.veracode.com/reader/4EKhlLSMHm5jC8P8j3XccQ/AM8PAkQKwsHbNYXy2VeX5Q

     

    I would recommend making sure that common.min.js is not present in the upload for Veracode Static Analysis.

     

    Please let me know if you have any remaining questions or concerns.

     

    Thank you,

    Boy Baukema

    Expand Post
      • Sorry @APrieto034095 (Community Member)​ , I missed that this was on Veracode Dynamic Analysis results.

         

        Veracode Dynamic Analysis will report any mention it finds of possible error or exception messages by looking through the page for values like "Exception".

         

        We recommend reviewing the flaw within the Veracode Platform and using the flaw details there (particularly the "Original Value") to determining if this is indeed an Exception message or not.

         

        If this is an exception or error message, we recommend that you disable Exception and/or detailed technical error messages for production environments.

         

        If not, we recommend you mitigate the flaw as a Potential False Positive and have this mitigation proposal reviewed by your security team. You can find more on how to propose mitigations here: https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/~p4MSKOS8F8X8h0KwFTKoQ .

         

        Thank you,

        Boy Baukema

        Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.