JPhor537964 (Community Member) asked a question.

Why veracode not recommend to download the policy everytime a new build trigger?

 

Referring to https://help.veracode.com/r/r_pipeline_scan_commands

 

  • Download a custom policy to your working directory using the --request_policy <custom policy name> parameter. The only result is that you download the requested policy. No scanning occurs.
  • Veracode recommends that you only download a policy that has changed and do not download a policy every time you run a pipeline build.

 


  • Hello @JPhor537964 (Community Member)​ ,

     

    One of the reasons that we recommend that you only download a policy that has changed and do not download a policy every time you run a pipeline build, is because it's not often that policy changes (or needs to change), so there is no need to download it every time. It might also be helpful to read this Knowledgebase article Development Sandbox Best Practices.

     

    Jason

    Veracode Support Engineer

    Expand Post
    Selected as Best
  • Hello @JPhor537964 (Community Member)​ ,

     

    One of the reasons that we recommend that you only download a policy that has changed and do not download a policy every time you run a pipeline build, is because it's not often that policy changes (or needs to change), so there is no need to download it every time. It might also be helpful to read this Knowledgebase article Development Sandbox Best Practices.

     

    Jason

    Veracode Support Engineer

    Expand Post
    Selected as Best
  • JPhor537964 (Community Member)

    hi Jason,

     

    Thanks for your explanation. Initially i thought there are some impacts / drawbacks on doing so

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.