📘 Static Analysis Reference Architecture: Best Practices for Pipeline Scan, Sandboxes, Application Profiles and Microservices

✍️ 01/21/2021 - Updated the doc to include new pipeline scan supported languages.

✍️ 01/06/2021 - Uploaded a new doc to this post with updated hyperlinks.

 

Hi all, @Tim J (Veracode PM)​ here. I want to share a new document that provides best practice recommendations about using Veracode Static Analysis for your applications, including specific recommendations about using Pipeline Scan, sandboxes, and application profiles, and recommendations about scanning microservices and other architectures.

 

Please let us know if you have questions about this guide!

 

(Apologies for the repost -- the previous post was not searchable.)


Blomgren, ig596, and 4 others like this.
  • ScottyGoSW (Community Member)

    Good to see this published

     

  • ScottyGoSW (Community Member)

    @Tim J (Veracode PM) (Veracode)​ Was re-visiting this document over break. Noticed that the blue links in the document are not 'active' hyperlinks to material that is referenced. Will there be an update that included those? (I have them on early "working" copy, but don't feel it's my place to publish that in the community)

  • Thanks @ScottyGoSW (Community Member)​ -- it looks like the conversion to PDF stripped out the hyperlinks. I'll look to see if we can get that corrected.

  • Mark_M (Community Member)

    This is a terrific reference document to have around! Thank you!!! I just shared it with our Security Champion Network 😀

  • Blomgren (Community Member)

    This needs to get updated for 2022. Very useful info here.

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.