Veracode Base Camp — Boy, Security Consultant (Veracode) asked a question.
Hi community!
@Boy, Security Consultant (Veracode) here at the Veracode Application Consultant team. We are software developers, security consultants, and expert Veracode users available to meet within the Veracode Platform to help you configure scans and work with the results.
Application Profiles are important to your AppSec program. They describe your application, identify policies for evaluation, and provide vital metadata for deeper analysis of security performance. Here are some of the things I recommend customers keep in mind when determining what to upload to the Application Profiles.
- Policy results: policy results can only be obtained for a single Application Profile.
- Flaws and mitigations: these are stored in an Application Profile.
- Entry points: an Application Profile should have at least 1 user-facing component.
- No more than one library version: libraries should be unique per scan, and you should not have a library with multiple versions.
- Licensing: you may be constrained by the number of your license with Veracode in the number of Application Profiles.
Is there anything else you would recommend users to pay attention to when setting up their Application Profiles?
.png)
📖 In case you’re not familiar with what "Application" means in the context of Veracode scans:
Check out this article Boy wrote to help bring more clarity. In the article, ge also delved into each of the five concerns above regarding setting up Application Profiles. Take a look and let me know if you have questions!