
JPALMA DEL VALLE110789 (Community Member) asked a question.
We have performed an analysis of our application with Upload and scan feature but the component path is not showed correctly in javascript/typescript applications:
We have followed the documentation: https://docs.veracode.com/r/compilation_jscript
All the javascript code is uploaded in a ZIP file that includes package-lock.json.
.png)
Hello @JPALMA DEL VALLE110789 (Community Member) ,
Thank you for reaching out to the Community.
The component is coming from the package-lock.json file, or if you uploaded the node_modules folder, it would be in there.
Best regards,
Steven
Veracode Support Engineer
Hello @Steven D., Veracode Support (Veracode) ,
In our case we upload two zip files with two differents repositrory, in every ZIP we upload the file package-lock.json and the problem is that we cannot identify from Veracode in wich ZIP is the SCA vulnerability found because we dont get the name of the ZIP file instead we receive this string file8437656265_1642894732948_html.
With this behaviour it is complicated for us indentify directly from Veracode in wich ZIP we have the issue.
I dont know if this is the normal working of the platflorm o i am doing something wrong.
Thank you for your help Steven.
Best regards,
Javier
Hello @JPALMA DEL VALLE110789 (Community Member) ,
There could be a few factors that could be causing this issue and it would be best to open a support ticket for assistance. To log a case:
Once you have a ticket number, please let me know and I can follow up afterward.
Kind regards,
Steven
Veracode Support Engineer
Hello @Steven D., Veracode Support (Veracode)
I have contacted support and the case is 00559001.
Thank you for your help.
Kind regards,
Javier