• Hi @MPatel187276 (Community Member)​ ,

     

    I'm sorry we missed this question at the time you asked it and I hope you got this resolved. If you have any questions of this nature, I would recommend you contact our technical support team. Here's how you can log a case:

    1. Navigate to the upper right corner of any page in the Community, click on your user avatar.

    2. Select Contact Support from the drop-down menu.

     

    For those arriving at this post through search, Veracode Dynamic Analysis does Production-Safe Testing:

     

    "The Veracode Dynamic Analysis scan engine is designed to test production web applications with minimal impact, and uses testing approaches that do not harm the site or accidentally delete data. For example, the Veracode SQL injection test patterns use timing-based methods that append to the existing query without altering its logic. In addition, the XSS test strings inject JavaScript that is benign and does not execute outside the embedded browser used by the Dynamic Analysis scan engine."

    * https://help.veracode.com/reader/OZJ0LCrqCUqbxFvNFcJnWQ/5hmEhAjLHVaVnOKFBiRm6A

     

    How this fits into your SDLC depends very much on your SDLC. A typical use-case would be to run against production or staging on a regular schedule. Alternatively, you can manually trigger a scan when a new build is ready for QA testing.

    If you would like to learn more about strategies for fitting Veracode Dynamic Analysis into your SDLC we recommend contacting your Veracode Program Manager.

     

    Thank you,

    Boy Baukema

    Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.