Tim J (Veracode PM) (Veracode) asked a question.

Product Update: New Mitigation Type for 2nd Party Risk

👉Veracode PM Tim Jarrett here with another product update!

We are pleased to announce the availability of a new mitigation status that allows developers to indicate that a finding is outside the scope of their team's responsibility, but that it has been referred to the maintaining team. You might use this mitigation for the following types of findings:

  • An issue in a common library maintained by your company's architecture team
  • An issue in a commercial library licensed from an independent software vendor

Veracode recommends that this mitigation type should be used only as a last resort, when it is impractical to rewrite your code to avoid calling the security issue. This is because it does not eliminate the risk as much as identify that the risk exists and has been escalated.

The new mitigation status, "Referred to Library Maintainer," can be used in all the same ways that other mitigations are used, including:

  • Veracode integrations and APIs
  • PDF reporting
  • Analytics
  • TSRV format

As with other mitigation types, a finding with a proposal of type "Referred to Library Maintainer" no longer counts as a policy compliance issue once the mitigation proposal is approved. 

This feature will be active for Veracode customers by the end of the week. Please let us know if you have questions!


Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.