📣 Static Analysis Product Updates - January 2021 Release

Hi Everyone -

 

Last week we released our first static engine update for 2021. This included support for several new versions of platforms and numerous accuracy updates. Some specifics...

  • Support for GCC 9 on RedHat 8
  • Support for the Autofac inversion of control library for .NET
  • Support of Koa.js version 2.13
  • Support for Hibernate Framework version 5

 

Accuracy Improvements for:

  • Android
  • Java apps packaged as WAR and EAR files
  • JSP apps
  • Python
  • PHP

 

Improved pre-scan warning messages for several common packaging mistakes.

 

Our next static release is scheduled for early March. Have a great week everyone.

 

@Static Analysis Group (Archived)​ 


UScholz and VCode like this.
  • Egle (Community Member)

    Can you also please include links to the updated product? That would be very helpful so I don't need to look for it specifically. Please note that I am from the company that cannot update versions automatically because of proxy rules and we need to get new versions uploaded manually to our environment.

    • Hi @Egle (Community Member)​ - you do not need to download anything new to get these updates - they are made to our backend engine, which are run as part of our SaaS platform. New static scans submitted after the update on February 4th will be using these new capabilities.

      • Egle (Community Member)

        thanks for a quick response @Jon J (Veracode Product Manager) (Veracode)​ . I don't think this is the way it works on our side. Please confirm with my account team if maybe I am mistaken here but we have our custom integration mode where we use a script that includes a link to our local Nexus repository space where we pull Veracode API (Java wrapper) from which we later use to trigger a scan through that custom script

        Expand Post
      • Egle (Community Member)

        @Chris Campbell (Product Manager) (Veracode, Inc.)​ , can you please confirm the above? does engine somehow knows the updates of a newer version even if we use an old version wrapper? I just want to be sure that we don't need to update versions of wrappers on Nexus(where we pull API from)

      • Hi Egle, the wrapper version and the engine version are completely separate, you don't need to update the wrapper to be able to use the latest engine version.

  • VCode (Community Member)

     

    "Improved pre-scan warning messages for several common packaging mistakes."

     

    this is great, it really helped me thanks

     

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.