When using the Jenkins Veracode plugin, it would be great if the plugin would mark the build failed if the Veracode scan result is less than "Passed". Also, the build should fail if the PCI compliance scan failed. Both is not happening at the moment.

We are using Veracode Jenkins Plugin version 19.7.5.9. I know that there is a new version available already, but from looking in the release notes, the question I am opening here is not covered by the new version(s).

 

We are using the Jenkins Veracode plugin as it is described in this section of the Veracode documentation:

https://help.veracode.com/r/c_jenkins_config_plugin

 

The console output in Jenkins for our project is the following:

 

"[20.02.10 10:24:10] The status of the new build is "Results Ready".

[20.02.10 10:24:13]

[20.02.10 10:24:13] The scan finished with policy status 'Conditional Pass'.

 

Notifying upstream projects of job completion

No emails were triggered.

Finished: SUCCESS

"

 

Actually, I would like the scan to be marked as failed so that Jenkins would automatically trigger an email to the project owners. The reason for this is that in the latest Veracode scan new flaws arose, which aren't noticed because no email is triggered.

 

Even worse, the PCI scan failed completely in Veracode. But as far as I can see, those scan results are not taken into account by the Veracode Jenkins plugin at all. 😒 See the following screenshot from the associated Veracode scan, which was triggered by Jenkins:

2020-02-13-VeracodePCIComplianceReportScanFailed 

This is really an issue as I would assume that the Jenkins build should be marked as failed in this case.

 

I hope that this could be implemented in the not so far future. 🙂


  • Thanks @DeCaPa (Community Member)​ for the input!

    Hello @UScholz (Community Member)​ I hope you have a chance to give the workaround a try while the Veracode team working to enhance the product to address your needs. If you do, we'd love to hear how the workaround works for you, and if you have suggestion for other users facing similar challenges. Oh btw, I've submitted an Idea on your behalf (https://community.veracode.com/s/idea/0872T000000brgMQAQ/view). I appreciate your taking the time to submit. Sorry again for the glitch that you ran into during the submission process!

    Expand Post
    Selected as Best
  • Hi @UScholz (Community Member)​ , thank you for your feedback -- which we're always seeking to continually improve the product and give you the best experience! As Veracode customer, you have exclusive access to the Ideas forum in the Community where you can provide this input directly to the Veracode product team. You also have the opportunities to weight in the enhancement requests from other users. I'd encourage you to check out the forum and add your feedback! Let me know if you have any questions. 🙂

    Expand Post
  • DeCaPa (Community Member)

    A conditional pass isn't a "fail" ... just yet. It means things are ok as long as the identified issues are fixed/mitigated within the time-to-fix, as defined in the policy you are measuring the scan against. When the time to mitigate exceeds the time defined in the policy, the scan will fail.

     

    In absence of a conditional pass notification feature in the Jenkins plugin. It could be possible to set the time to mitigate to 0 days in the policy, making every policy scan a binary outcome - Pass / Fail. This may meet your desired outcome.

    Expand Post
    • UScholz (Community Member)

      Thanks for your thoughts, DeCaPa. Though, your idea would only be a workaround. The reason is that there are different roles for employees everywhere (also in our company), some have only read access to Jenkins, others only have read access to Veracode, and even less people which have access to Veracode are able to edit the policies there. But a big number of devs can contribute to a single product and they might not always be informed about the outcome of a Veracode scan automatically, for example because they are just not assigned to the Veracode application in question.

       

      From a dev perspective it therefore would be good to be informed about new security flaws on an earlier stage, e.g. by having a setting in the Veracode Jenkins plugin to turn a conditional pass into a failed build, irrespective of how the policy in Veracode is configured.

       

      And even more important, the PCI scan results should be taken into account in the Jenkins results.

       

      @Shuning, Veracode Community Manager (Veracode)​ I will create a record in the ideas forum.

      Expand Post
  • DeCaPa (Community Member)

    Veracode has a 12 month roadmap they work from, so it might be a while.😥 So, I posted the work around to help address your immediate need.

     

    👍 for notification of new flaws. In your case, it sounds like it is less about policy compliance & reporting, and more about feedback to the developer. Even if your org doesn't have Greenlight, a developer can still import flaws into her IDE workspace, but it doesn't highlight *new* flaws afaik (maybe that is another entry into the ideas forum). It is a way to provide visibility to a developer who may not regularly access Veracode or using a language that Greenlight doesn't support.

    Expand Post
    • Thanks @DeCaPa (Community Member)​ for the input!

      Hello @UScholz (Community Member)​ I hope you have a chance to give the workaround a try while the Veracode team working to enhance the product to address your needs. If you do, we'd love to hear how the workaround works for you, and if you have suggestion for other users facing similar challenges. Oh btw, I've submitted an Idea on your behalf (https://community.veracode.com/s/idea/0872T000000brgMQAQ/view). I appreciate your taking the time to submit. Sorry again for the glitch that you ran into during the submission process!

      Expand Post
      Selected as Best
      • UScholz (Community Member)

        Hi Shuning. I fear that the workaround is not an option for us. It is a company policy that only products with passed Veracode scans go live. So we cannot just turn the existing policy into another one which immediately fails, just for the purpose to inform the developer that there is a new flaw found. It really would be better if the plugin would change the build status accordingly as requested originally.

         

        Thanks for your understanding.

         

        PS: I also found this idea which is similar to the current one.

        Expand Post
    • UScholz (Community Member)

      Exactly. And today I found an idea of another Veracode user asking also for the new flaw notification. Please vote for it! 😊

       

      By the way: We tried to use Greenlight in our project, but it was slowing down response time in Visual Studio extremely. Reason certainly is that our project is quite big, i.e. several hundreds of MB of source code. Veracode scans take 4 to 5 hours, so a feedback via the Jenkins plugin would be highly appreciated.

       

      Thanks, @Shuning, Veracode Community Manager (Veracode)​ for setting up the idea for me!

      Expand Post
  • DeCaPa (Community Member)

    @UScholz (Community Member)​  - 👍 , not sure how many are needed before Veracode gets the hint, but it is a very good idea, from many perspectives.

Topics (7)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.