AUB-1 (Community Member) asked a question.

Policy for SCA Agent-Based Scan

We would like to set up a policy that flags scans as failed if and only if Vulnerable Methods are found by the SCA Agent-Based Scan. The policy should not flag the scan as failed if the SCA Agent-Based Scan uncovers vulnerable libraries but no vulnerable methods are found.

 

Perhaps I am missing something, but I could find a way to set up such policy. Thanks.


VCode likes this.
  • Hello @AUB-1 (Community Member)​ ,

     

    In your request, you are inquiring about a policy if vulnerable methods are found by an agent based scan but those are two different types of scans. Policy is used in the Upload and Scan method while vulnerable methods are used in an Agent-based scan.

     

    Here is a Help Center article that is helpful in understanding scan methods. https://help.veracode.com/reader/9nOkCbEfhLEzMgzr2zCv5Q/8ogXM1j_wRm_AYmyKdrdoQ

     

    If the information we’ve provided you has helped resolve your challenge (or answered your question), we would appreciate it if you could mark the response that was helpful with “Select as Best”. This will help other Community members who come across your question as a similar challenge they might be facing and your best answer will help them find the right solution as well.

     

    Jason

    Community Support Engineer

    Expand Post
  • AUB-1 (Community Member)

    Jason, as I have already mentioned in the ticket I opened with Veracode's support, the answer provided does not address my question. The question I asked has nothing to do with the fact that there are two types of scans for SCA. We understand that already. Policy setting has the provision to include certain criteria for SCA scan. It appears, however, that among those criteria, there is nothing that allows to flag an SCA scan as failed if and only if vulnerable methods are greater than zero. In lay man terms, I am not overly interested to know that I have 127 vulnerable libraries when my code does not use any vulnerable methods from those libraries. Therefore, I don't want the scan to be flagged as failed just because of the 127 vulnerable libraries. On the other hand, I don't want to completely forego the SCA CVSS rule. This seems again one of those issues related to Veracode SAST and SourceClear not being very well integrated.

    Expand Post
    • Hello @AUB-1 (Community Member)​,

       

      | The question I asked has nothing to do with the fact that there are two types of scans for SCA.

       

      Actually, it has everything to do with it. Scan pass/fail is a concept associated with policy, and policy configuration is scoped only to application profiles. Upload and Scan SCA functions within application profiles, whereas Agent-based scanning occurs within workspaces.

       

      Additionally, vulnerable libraries detection functionality only exists within Agent-based scanning. Since Agent-based scanning is not within the scope of policy configuration, there would be no way to set any kind of failure around that criteria.

       

      In short: Jason was correct in stating that they are two different types of scans, as the functionality is not identical across them both. If this is functionality that you'd like to see in the product in the future, you can submit it as product feedback in the Ideas section of the Community, which can be found in the Help menu in the top navigation bar.

      Expand Post
  • AUB-1 (Community Member)

    Hi Matthew, you should have read my question and answered accordingly. The question has nothing to do with the type of scan. The question has to do about setting a policy that fails a scan, if and only if, vulnerable methods are found. The semantic of the question is clear. Your answer fails to address my question and it simply describes a glaring shortcoming of Veracode/SourceClear integration. I am not interested in the "why"; I did not ask for it; I only wanted to know if it is possible or not.

     

    Therefore, the correct answer should have been: a policy that detects when vulnerable methods are used cannot be defined. And perhaps you could have added: because policies do not apply to agent-based scans. As simple as that.

     

    This shows, once again, that Veracode SAST and SourceClear are poorly integrated. They work and behave for what they are: two separate products. Perhaps instead of spending time submitting product feedback that typically goes nowhere, we should look into another SCA product instead.

    Expand Post
  • Bernie (Veracode Inc.)

    Hello @AUB-1 (Community Member)​ ,

     

    This capability that you are asking about for Agent-based scan exists. In the Rules section under "Manage Workspace" page in Agent-based SCA, when you create or edit a rule, one of the conditions available is 'Vulnerable Method' as a dropdown box with 'Yes/No' options.

    Please note that this will be effective only for languages for which we support vulnerable methods.

    We encourage security practitioners to use vulnerable methods to prioritize their remediation list but to also have a plan to address all vulnerabilities eventually and not just the ones with vulnerable methods.

    Expand Post
  • AUB-1 (Community Member)

    Hi @Bernie (Veracode Inc.)​ Thanks for the note. That looks promising. I am testing it as we speak. We do have plans to have dev teams address all vulnerable libraries. We just don't want to overwhelm developers to the point where they shut down completely. Dev teams have to learn how to walk first before they can run, and they are barely crawling.

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.