
Product Announcements — Tim J (Veracode PM) (Veracode) asked a question.
Hi all, @Tim J (Veracode PM) (Veracode) here with a new best practices guide about the use of the baseline file feature of Pipeline Scan.
The baseline file is a powerful feature that allows you to control which findings can cause the CI pipeline to fail. This document gives a deep dive into the purpose and structure of the baseline file and describes three use cases for it: coping with security debt, dealing with second party findings, and managing mitigations.
Like Pipeline Scan itself, the baseline file feature will continue to evolve based on feedback, so please let us know your thoughts here!
.png)
that was really useful ... thanks tim
Any guidance on auto-updating the baseline file with releases? Right now it requires manual action and PR to update the Baseline but I would like that if we accept a merge and are moving forward with the release the baseline file would be updated accordingly. What is the guidance on using baseline file vs policy file?
Hi @ig596 (Community Member) , I've seen some YAML examples that automate updating the baseline file with a merge to main, but I'd say use that with caution, for obvious reasons:
I'd love to hear from other community members regarding how you're managing the baseline file. This is an area where we're actively thinking about how to improve the product, especially around the relationship between the baseline file and the mitigation workflow for sandbox and policy scans.