
Static Analysis Group (Archived) — Tim J (Veracode PM) (Veracode) asked a question.
@Tim J (Veracode PM) here (again!) with one more best practices recommendation. This addresses handling second-party findings -- findings in a shared component that is maintained elsewhere in your organization and not by the team whose application is being scanned. The document summarizes the different options that are available, and talks about some special considerations when the second-party code communicates via IP based APIs (microservices).
Please post any feedback or comments here!
.png)
Hi @Tim J (Veracode PM) (Veracode) this document refers to annotations as a practice to travel along with the library. Is this a reference to the Veracode custom cleanser annotations? If so I think this is the right move, however the list is very limited.
@mfawcett (Community Member) -- yes, thanks for the clarification. We do mean custom cleanser annotations in this paper, but you're right to point out that there are limitations for the number of CWEs and languages that we cover with this approach.
@Tim J (Veracode PM) (Veracode) Thanks for that Tim. I am looking at the veracode annotations API at the moment. Would this work for helping to automate the mitigations for us? If so do you have a reference implementation of this in use this way?