
HSingh007417 (Community Member) asked a question.
As per my understanding of the veracode platform, we have to precompile all the solution files separately and then upload the binaries for scan. BUt I want something similar to as we do in Fortify where we supply the complete code branch and have that scanned.
Also, how to precompile the wcf solution file for uploading to Veracode? I cannot find anything similar in the documentation.
.png)
Hi @HSingh007417 (Community Member),
Thanks for your question.
Unlike other products out there, Veracode Static Analaysis offers superior results by analysing software at a binary level rather than exclusively source code. You can read more about why here: https://www.veracode.com/blog/intro-appsec/appsec-buyers-insights-binary-vs-source-code-scanning. For .NET applications we require compiled exe's or DLLs but they have to be packaged correctly.
I recommend you follow the compilation and packaging instructions in the Help Centre (https://help.veracode.com/reader/4EKhlLSMHm5jC8P8j3XccQ/UWyzuOKNbFbwQACRLkZVjA) to create a zip package for each of your solutions/utilities. Then you will be able to upload all the zips to a single scan. Each of the uploaded zips should be selected as being an entry point in order to scan them. The results will then be aggregated and presented in a single scan for you to review and action.
For WCF we have no specific requirements other than as described in the above Help Centre link regarding compilation and packaging. We are able to identify the services and endpoints and we treat them as sources for tainted data when analysing.
I hope that helps answer your question.
Thanks,
Anthony Fielding