Veer (Community Member) asked a question.

Cannot identiify flaws for second file js file when greenlight scan used in VS code.

I have windows 10 64 bit OS and installed VS code version

Version: 1.52.1 (user setup)

Commit: ea3859d4ba2f3e577a159bc91e3074c5d85c0523

Date: 2020-12-16T16:34:46.910Z

Electron: 9.3.5

Chrome: 83.0.4103.122

Node.js: 12.14.1

V8: 8.3.110.13-electron.0

OS: Windows_NT x64 10.0.17763

 

and veracode version installed for scanning isv1.3.1996016.

 

Issue is: -

I have node js project files and did veracode scan successfully first file after install and able to see flaws but consecutive files cannot get results.. it always says 0 findings.

I did cleaning cleaning cache editor history but still cannot get results/flaws identified for the consecutive files.

 

Please suggest the solution

 

 


VCode likes this.
  • Hello @veer,

     

    I see you also opened a ticket with our support team on this issue and I want to post the answer on the Community.

     

    Please be aware, Greenlight and Policy Scans utilize the same static engine to find flaws. Since Greenlight is typically scanning just one compiled module or class file, the scanner does not have the same application scope as a full policy scan. In some cases Greenlight may not be able to detect flaws using data flow analysis as tainted data is traced between sources and sink. There can also be compiler optimizations such as removing unused variables that can mask flaws in a single module that can be detected in a full application scan. The Static Express engineering team is responsible for Veracode’s cloud service behind the Greenlight product and are not experts in this area. 

     

    If you want to understand the reason specific examples of flaws are not detected please engage with the Veracode Application Security Consultant team to get more information about your modules.

     

    Please use the following link to find additional information on scheduling a consultation call: https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/7YQTCDJKFEQzL3gL_N90hQ

     

    If the information we’ve provided you has helped resolve your challenge (or answered your question), we would appreciate it if you could mark the response that was helpful with “Select as Best”. This will help other Community members who come across your question as a similar challenge they might be facing and your best answer will help them find the right solution as well.

     

    Thank you,

    Steven

    Veracode Support Engineer

    Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.