
Tim J (Veracode PM) (Veracode) asked a question.
👉Veracode PM Tim Jarrett here with another product update!
We are pleased to announce the availability of a new mitigation status that allows developers to indicate that a finding is outside the scope of their team's responsibility, but that it has been referred to the maintaining team. You might use this mitigation for the following types of findings:
- An issue in a common library maintained by your company's architecture team
- An issue in a commercial library licensed from an independent software vendor
Veracode recommends that this mitigation type should be used only as a last resort, when it is impractical to rewrite your code to avoid calling the security issue. This is because it does not eliminate the risk as much as identify that the risk exists and has been escalated.
The new mitigation status, "Referred to Library Maintainer," can be used in all the same ways that other mitigations are used, including:
- Veracode integrations and APIs
- PDF reporting
- Analytics
- TSRV format
As with other mitigation types, a finding with a proposal of type "Referred to Library Maintainer" no longer counts as a policy compliance issue once the mitigation proposal is approved.
This feature will be active for Veracode customers by the end of the week. Please let us know if you have questions!
.png)