GFlores177100 (Community Member) asked a question.

filepath contains both JARs and WARs, but only JARs are scanned using UploadAndScan API wrapper

I'm using veracode/api-wrapper-java:latest, and I've indicated at least the following parameters:

 

-action UploadAndScan \ 

-autoscan true \

-filepath $SCAN_DIR

 

where SCAN_DIR is a folder that contains a number of .jar and .war files. Note: the JAR files aren't dependencies of the WAR files.

 

However, when the scan completes, Veracode report says all .jar modules are included in the scan, whereas all .war modules are excluded. Why? How can I run a full scan of the application that contains both JAR and WAR modules?

 

Thanks in advance


  • GFlores177100 (Community Member)

    Was able to resolve it by separating .jar and .war files into 2 different archives

    Selected as Best
  • GFlores177100 (Community Member)

    Was able to resolve it by separating .jar and .war files into 2 different archives

    Selected as Best
  • Hello @GFlores177100 (Community Member)​ ,

     

    A good starting point to ensure that both JAR and WAR modules are being scanned is the Veracode Packaging Guide, Selecting Modules to Scan for what is being uploaded and intended for full scanning or what should be selected for entry points. Without the URL to the application, it would be difficult to see what is going on with the scan.

     

    There is also a good Communities article by the Application Security Consultants (ASCs) which is a great resource as well titled What are Modules and how do my results change based on what I select? Also, another option is to review the results of your specific application with a Consultant if your Veracode Services includes that.

     

    Jason

    Veracode Support Engineer

    Expand Post

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.