
VMane450621 (Community Member) asked a question.
Hi Team,
I am working on upgradation of application from .Net 3.1 to 6.0, When I run the sandbox scan(triggered from local) for the application then veracode score is "95" but
when I run the scan through pipeline score is "92" and there is one high flaw(External Control of File Name or Path CWE ID 73). For this flaw we have added file name and filepath validation but still getting flaw only on pipeline triggered scan.
Kindly advise what may be the cause and how can it be fixed.
Thankyou!
.png)
Hello @VMane450621 (Community Member) ,
I see that you reached out to our technical support team in regards to your inquiry. They recommended upgrading to the newer Veracode Visual Studio Extension for Static that can be used in both Visual Studio 2022 and 2019.
Also mentions that consistent packaging and uploading of the .NET application will improve matching results between uploading using the Veracode Azure DevOps Extension and the Veracode Visual Studio Extension.
Jason
Veracode Support Engineer