
Static Analysis Group (Archived) — Tim J (Veracode PM) (Veracode) asked a question.
✍️ 01/21/2021 - Updated the doc to include new pipeline scan supported languages.
✍️ 01/06/2021 - Uploaded a new doc to this post with updated hyperlinks.
Hi all, @Tim J (Veracode PM) here. I want to share a new document that provides best practice recommendations about using Veracode Static Analysis for your applications, including specific recommendations about using Pipeline Scan, sandboxes, and application profiles, and recommendations about scanning microservices and other architectures.
Please let us know if you have questions about this guide!
(Apologies for the repost -- the previous post was not searchable.)
.png)
Good to see this published
@Tim J (Veracode PM) (Veracode) Was re-visiting this document over break. Noticed that the blue links in the document are not 'active' hyperlinks to material that is referenced. Will there be an update that included those? (I have them on early "working" copy, but don't feel it's my place to publish that in the community)
An example of this would be if you search for Mitigation Copier. It's blue text, no hyperlink. In the draft it would point to https://github.com/brian1917/veracode-mitigation-copier
Thanks @ScottyGoSW (Community Member) -- it looks like the conversion to PDF stripped out the hyperlinks. I'll look to see if we can get that corrected.
Hi @ScottyGoSW (Community Member) - following up on Tim's comment, we've uploaded a new doc to this post with updated links that should be working! Let us know if you have any feedback.
This is a terrific reference document to have around! Thank you!!! I just shared it with our Security Champion Network 😀
This needs to get updated for 2022. Very useful info here.