BSingh303227 (Community Member) asked a question.

Why does the Sandbox scan report no flaws?

Hi,

I've been scanning my application recently and noticed that the Sandbox scan doesn't report any flaws in the source code. However, when I run the full policy scan then the reports shows more than 200 flaws. Can you someone help me to understand the behavior?


  • Hello @BSingh303227 (Community Member)​ ,

     

    After reviewing your inquiry, if your Sandbox is getting zero flaws and the policy scan is 200, it can't be the same code being run.

     

    Jason

    Community Support Engineer

    Expand Post
  • BSingh303227 (Community Member)

    Hi Jason,

    Thank you for the response. I confirm that the source code is the same in both types of scans which makes me wondering how it finds flaws in one place but not in the other.

    • Hello Bhupinder,

       

      Thank you for sending me the links to the Sandbox scan and the full scan. After looking them over, I see that the Sandbox scan file size was 36.6KB (with 90 modules) and the full scan was 28.5MB (with 82 modules), which means that there is a different amount of code in each scan and that is why you are seeing the different results.

       

      Jason

      Community Support Engineer

       

      Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.