Gary (Community Member) asked a question.

How to implement Veracode scanning in CD/CI pipeline for Docker containers

Our company uses Azure DevOps for CD/CI and we're looking to add Veracode scanning for Docker container images.

 

I've seen this introductory article (https://www.veracode.com/blog/security-news/how-veracode-scans-docker-containers-open-source-vulnerabilities) but I can't seem to find any actual working examples/documentation on how Docker image scanning actually works.

 

Can anyone please point me in the right direction?


  • Hello @Gary (Community Member)​ ,

     

    The article that you linked to is a good resource for an example of our tools in a docker image for use. We don’t have any documented examples to share but you can do --image $(imageName) added to the end or --container. If you contact your Solution Architect, they would be able to advise you on how to set it up or demo it for you.  

     

    Jason

    Veracode Support Engineer

    Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.