
Jon J (Veracode Product Manager) (Veracode) asked a question.
Veracode has added new static analysis support for these technologies:
- The Gorilla Framework for Go applications
- AWS SDK for Node.JS
Veracode has improved static analysis of these technologies:
- Improved static analysis of iOS applications by improving the results of scans, to better focus the results on custom first-party components, instead of third-party libraries.
- Improved Go application results quality
- Veracode now reads the contents of the go.mod file included in an application submission to more accurately identify which Go components to analyze.
Analysis Size Changes
In the 2020.5 release on June 9, 2020, Veracode made some changes to the way that we calculate the analysis size for Java and .NET applications. These changes will only affect customers using the static analysis “Per Megabyte” licensing model.
There are some circumstances in which the size of the components analyzed reported in the Veracode platform UI was not consistent with the way these were being recorded in analytics and license reporting systems. This occurs in a minority of cases and primarily affects when dependent DLL or JAR files were included in scan submissions.
We have resolved this inconsistency and users may see differences in the reported analysis sizes for static analysis scans that occurred after the 2020.5 release.
Please work with your program manager if you have any questions about analysis sizes or licensing reporting.
.png)
Good stuff- I know my GO developers will be happy about this