📘 Pipeline Scan Baseline File Best Practices

Hi all, @Tim J (Veracode PM) (Veracode)​ here with a new best practices guide about the use of the baseline file feature of Pipeline Scan.

 

The baseline file is a powerful feature that allows you to control which findings can cause the CI pipeline to fail. This document gives a deep dive into the purpose and structure of the baseline file and describes three use cases for it: coping with security debt, dealing with second party findings, and managing mitigations.

 

Like Pipeline Scan itself, the baseline file feature will continue to evolve based on feedback, so please let us know your thoughts here!

 


  • VCode (Community Member)

    that was really useful ... thanks tim

  • ig596 (Community Member)

    Any guidance on auto-updating the baseline file with releases? Right now it requires manual action and PR to update the Baseline but I would like that if we accept a merge and are moving forward with the release the baseline file would be updated accordingly. What is the guidance on using baseline file vs policy file?

    • Hi @ig596 (Community Member)​ , I've seen some YAML examples that automate updating the baseline file with a merge to main, but I'd say use that with caution, for obvious reasons:

      • You may still have open findings that will pop up again in a policy scan unless you mitigate at the same time that you add findings to the baseline.
      • Teams that aren't actively managing their security might get in a situation where findings start to get ignored after the merge that they've never reviewed

       

      I'd love to hear from other community members regarding how you're managing the baseline file. This is an area where we're actively thinking about how to improve the product, especially around the relationship between the baseline file and the mitigation workflow for sandbox and policy scans.

      Expand Post

Topics (5)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.