
JPalmer768162 (Community Member) asked a question.
Good Morning - I'm trying to use the Greenlight plugin for Visual Studio 2019 and my findings are generally not lining up with the results posted on the website with a full scan? I'm seeing either inconsistent results, or a subset of the findings displayed on Greenlight? Same code, different results?
.png)
Hello @JPalmer768162 (Community Member) ,
Thank you for reaching out to the Community.
Veracode Greenlight provides findings in seconds, by analyzing a small portion of the application. As a result, Veracode Greenlight is an excellent complement to an AppSec program based on Veracode Static Analysis but is NOT a replacement for it.
When you scan an application as a whole using Veracode Static scan, our scan engine generates a data model using the top-level modules and scans through those data paths.
It might be the case that the flaw occurs only when the data flows through certain class files/modules, but when you scan a small portion of code using Veracode Greenlight, you might not find the same flaw, as that portion of code, on its own, is not vulnerable. So we recommend a full application scan using Veracode Static scan at a later stage of the SDLC.
Veracode Greenlight is used on a newly written class or one that was recently modified, providing a preview of some security findings when they are the cheapest to fix.
If the information we’ve provided you has helped resolve your challenge (or answered your question), we would appreciate it if you could mark the response that was helpful with “Select as Best”. This will help other Community members who come across your question as a similar challenge they might be facing and your best answer will help them find the right solution as well.