
IHayden136755 (Community Member) asked a question.
Hi, I am running an agent scan on a containerized image of our java web product that is running on an older base tomcat/ubuntu image.
We know there are flaws with the OS and the tool reports most of those, but it does not detect or report on anything else - particularly the Tomcat installation being old and full of vulnerabilities, the python installation or our own app.
I've tried scanning over the image (--image) and the container (--container) but no .jar files are appearing in the scan results (or anything else not core OS related, i.e. Python).
Is there something I am missing with this?
Many thanks,
Ian
.png)
Hi @IHayden136755 (Community Member) ,
How is your installation of Tomcat and Python managed? Is this through the OS package managers?
Currently, Veracode Software Composition Analysis Docker scanning is limited to identifying software installed with a supported OS package manager. Please consider registering your idea for detecting manually installed software with Veracode Community Ideas at https://community.veracode.com/s/ideas .
Thank you,
Boy Baukema