
RHeimerman135265 (Community Member) asked a question.
I recently set up on one of our pipeline to fail pr's if there are vulnerabilities. However, the pipeline scan is not finding the flaw that is found within scan that takes place on the "veracode website." I updated the jar to the latest version-- same behavior. I scanned the same artifact that the "veracode website" scans with the jar and that did not find the flaw either.
Not sure if it helps, but I'm scanning a jar file and it's a Cross-Site Request Forgery (CSRF) CWE ID 352 vulnerability.
I didn't know which forum to post this to. So if this is the incorrect place, I apologize.
Thanks
.png)
Veracode Static Analysis Pipeline Scan and Veracode Static Analysis Policy scan use the same underlying engine, any difference in results can usually be attributed to a difference in what is provided or selected for scanning.
I would recommend you schedule a consultation call to discuss.
You can check out this knowledge article (https://community.veracode.com/s/article/How-to-schedule-a-consultation-call) on how to schedule a consultation call with us.
Thank you,
Boy Baukema