
Product Announcements — Shuning, Veracode Community Manager (Veracode) asked a question.
Hi Community, Happy October! It's time for the weekly product news. We’re excited to share an extensive list of features we shipped at the end of September.
◾️Static Analysis
- New Language Support
- Angular 9 and 10
- Visual Studio 2019 for Visual C++
- Pipeline Scan now supports Android applications
- Improved Support
- AWS SDK for JavaScript
- .NET and JVM-based Applications
- Packaging Improvements for .NET Applications
️◾️Veracode Integrations
- Veracode Static for Eclipse (version 3.4.1) now allows you to store your Veracode API credentials securely in an external file.
- Introducing Veracode for GitHub
- You can use GitHub Actions for performing static analysis of your application source code from within GitHub.
- Veracode provides preconfigured GitHub Actions for uploading your code to Veracode for static analysis or running a pipeline scan from within your GitHub development workflow.
◾️Veracode Platform
- Rolling Sandbox Histories
- You can limit sandbox data by restricting the number of retained scans for each sandbox to 15.
- After more than 15 scans, the Veracode Platform deletes the oldest scan, though the data remains available through Veracode Analytics.
- If enabled, this feature replaces the previous data limitation method of expiring old sandboxes.
- To request access to rolling sandbox histories, contact Veracode Technical Support.
- Updates to Some XML API Deletion Calls: To improve performance, the deleteuser.do, deleteteam.do, deleteapp.do, and removefiles.do XML API calls now return an HTTP 200 response and a change summary, instead of a list of the items remaining after the deletion.
- Shareable Links to Your Analytics Dashboards
- You can now share links to Veracode Analytics dashboards, including Veracode dashboards and dashboards that your organization creates.
- To access a dashboard link, you must log in to the Veracode Platform and have permission to view the data in the dashboard.
- Activity Log Updates
- You can now download a report of the full history of application profile activity, scan activity, and sandbox activity.
- The activity log in the Veracode Platform now displays activity data for the past 90 days.
- Technique Removed from TSRV Format for Accepting Risk
- Technique from the TSRV standard has been removed.
- Remaining Risk, and Verification are still required fields.
- Updates to CWE Top 25 Policy Rules
- The Latest CWE Top 25 policy rule in the Veracode Platform now reflects the 2020 CWE Top 25 standard.
- The 2019 CWE Top 25 policy rule has also been updated to disallow the children of CWE-94: CWE-91, 95, 98, 185, and 830.
- Two URLs Added to Required Veracode Domains: If you restrict access to public internet sites for your organization, please add app.pendo.io and analytics2.veracode.com to your allow list.
â—ľSoftware Composition Analysis
Grace Periods for SCA Policy Rules, allowing you to:
- include grace periods for SCA upload scans in your application security policies.
- define a grace period for all scan types, including SCA, or define a grace period that applies specifically to SCA scans.
📣 Did you know?
To keep up with product updates, you can subscribe for weekly digest emails every Sunday – a summary of new posts made in the Product Announcements group from the last week. Here’s how:
- Join Product Announcement Group
- Make sure your notification is set to “Weekly Digest”
.png)