ScottyGoSW (Community Member) asked a question.

Adobe Experience Manager (above 6.4)

Does veracode have coverage for Adobe Experience Manager 6.5 or above?

 

In working with teams that have this platform that contain both Java code and Javascript/Html/CSS, the packaging guidance provided in Veracode ::

 

Packaging Adobe Experience Manager Applications

As part of the build process for typical Adobe Experience Manager projects, you can use mvn install. After the build completes, upload all ZIP files containing OSGi components or other compiled Java code. The Java code includes any code in the ui.apps ZIP archive, which is usually found in ui.apps/target/.

Upload each package individually. Do not upload multiple packages in a ZIP file. Veracode does not support ZIP archives containing ZIP files.

https://help.veracode.com/r/compilation_java

 

:: seems off in terms of where the java code is located on this version of the platform (underlined passage).

 

Am currently running scans on the java and javascript, but not really seeing much value provided back to the team using this platform


    • Another suggestion to is that you can also give the feedback as an Idea in our Community. Take a look to see if the idea already exists, for if it does, you can Upvote it and if the idea doesn't then create one!

       

      Jason

      Veracode Support Engineer

      Expand Post
  • ScottyGoSW (Community Member)

    Thanks @Jason M., Veracode Support (Veracode)​  in regards to the two items. However, appreciate re-inforcement of those areas to look at before posting. Not very helpful in my case, as had already reviewed the compilation guide (included the passage from current guide in the post) and ideas (zero topics in regards).

     

    Release note monitoring has not been great in 2 years timeframe to updates. Seldom are frameworks/platforms covered in that or roadmap updates. Also to note, have not seen alignment of releases to support cases that we've opened where fixes are created.

     

    Post as intentional in community to drawn insight/thoughts from other customers. We have seen that 6.4->6.5 results in a new compilation practice where the "zips within zips" issues comes into play. This makes it "difficult" for customer that would like a something generated from a DevOps 1st practice to upload the build artifact (for deployment) vs. a "special" build artifact (for Veracode). Will put that topic out here as well.

    Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.