
JPhor537964 (Community Member) asked a question.
Referring to https://help.veracode.com/r/r_pipeline_scan_commands
- Download a custom policy to your working directory using the --request_policy <custom policy name> parameter. The only result is that you download the requested policy. No scanning occurs.
- Veracode recommends that you only download a policy that has changed and do not download a policy every time you run a pipeline build.
.png)
Hello @JPhor537964 (Community Member) ,
One of the reasons that we recommend that you only download a policy that has changed and do not download a policy every time you run a pipeline build, is because it's not often that policy changes (or needs to change), so there is no need to download it every time. It might also be helpful to read this Knowledgebase article Development Sandbox Best Practices.
Jason
Veracode Support Engineer