OYou496345 (Community Member) asked a question.

What is the best option for js lib project?

My company is preparing a release for js lib type solution which targets B2B customers. So, I'm checking all measures for security requirements and compliance. What can be the best option among veracode solutions and products for my project? 

A basic static scan like ESLint has been already applied to my project. 

 

I'm currently using veracode static scan service for Android and iOS apps which work with Blackberry dynamics . It is required for every app update. It is blackberry's guideline. Like this, I want to add a process to prove code security for every release and to provide the result for my future customers. 

 

Please give me an advice.  


  • Hi @OYou496345 (Community Member)​ ,

     

    Which analysis types are appropriate depend very much on the composition of the application / library.

    For example Veracode Software Composition Analysis can be used to verify none of the dependencies of your application / library have known vulnerabilities.

    Veracode Dynamic Analysis can be used to dynamically scan any websites built with your application / library.

    Veracode Static Analysis can be used to perform deep analysis of your application / library code for flaws (please note that this is *much* more in-depth than a linting tool like ESLint and only focussed on security flaws).

     

    I would recommend contacting our Sales department, they can match Veracode products to your needs, you can contact us through the following URL: https://info.veracode.com/web-contact-us.html

     

    Thank you,

    Boy Baukema

    Expand Post
    Selected as Best
  • Hi @OYou496345 (Community Member)​ ,

     

    Which analysis types are appropriate depend very much on the composition of the application / library.

    For example Veracode Software Composition Analysis can be used to verify none of the dependencies of your application / library have known vulnerabilities.

    Veracode Dynamic Analysis can be used to dynamically scan any websites built with your application / library.

    Veracode Static Analysis can be used to perform deep analysis of your application / library code for flaws (please note that this is *much* more in-depth than a linting tool like ESLint and only focussed on security flaws).

     

    I would recommend contacting our Sales department, they can match Veracode products to your needs, you can contact us through the following URL: https://info.veracode.com/web-contact-us.html

     

    Thank you,

    Boy Baukema

    Expand Post
    Selected as Best

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.