
Prem (Community Member) asked a question.
Hi
We have a java web application (war file) which has some third-vparty java script files present in it. For example
my-web.war/assets/js/third-party/json.js
Here the content of the "third-party" folder has thirdparty java script.
Veracode Static scan reported vulnerabilities on the files present within this folder. Is there a way I can exclude this folder and make it a part of SCA (thirdparty issue) report rather than as a first party code flaw?
Regards
Prem
.png)
Hello @Prem (Community Member) ,
Veracode's scanner will try to detect and avoid scanning unnecessary third party libraries, but you can also check the Review Modules screen and de-select 3rd party components.
Help Center article Selecting Modules to Scan: https://help.veracode.com/r/c_request_modules_scan
If the information we’ve provided you has helped resolve your challenge (or answered your question), we would appreciate it if you could mark the response that was helpful with “Select as Best”. This will help other Community members who come across your question as a similar challenge they might be facing and your best answer will help them find the right solution as well.
Jason
Veracode Support Engineer