• hLI062636 (Community Member)

      Thanks. I have another question. Is there way to exclude third party library in pipeline scan? For example, my java application has aws-sdk. but I don't want to scan the aws-sdk. @Boy, Security Consultant (Veracode)​ 

      • Hi @hLI062636 (Community Member)​ ,

         

        Veracode Static Analysis for Java applications requires that the third party components are provided. Excluding these libraries from what is uploaded to Veracode will likely negatively impact the results we are able to provide do you.

         

        You can find more information on how to handle flaws in third party software on this Community Article: https://community.veracode.com/s/article/How-to-fix-a-Veracode-Static-Analysis-flaw-in-third-party-software .

         

        Thank you,

        Boy Baukema

        Expand Post
      • hLI062636 (Community Member)

        If exclude the third party library is not recommended. How we suppose deal with the application size over 100mb, using sandbox scan ? @Boy, Security Consultant (Veracode)​ 

      • Hi @hLI062636 (Community Member)​ ,

         

        If your application does not meet the requirements of Pipeline Scan I would suggest the following:

        1. Review your dependencies, do you require the entire SDK or only a small portion? Can you remove the unused portion and get the size below 100M?
        2. If this is not possible, you can consider removing the SDK from the upload you send to the Pipeline scan and comparing the results against a full Policy Scan. It may be of acceptable quality. However, if you do this, you will likely want to ensure you also require a full Policy scan and you will likely want to inform the team members who do the triage of this custom step.
        3. Relying on a scheduled (nightly) Sandbox scan.

         

        Thank you,

        Boy Baukema

        Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.