When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
More information
Select only the binaries you want scanned for static analysis. Selecting 3rd party components may show flaws, in them, but if you don't have access to source code for them, you won't be able to determine if the findings are false positives.
Thanks for your answer. What would happen if a 3rd party component is referenced but not used by the project, and I don't select that 3rd party component as an entry point? Would Veracode skip it?
I should not be scanned for static analysis, but should reflect vulnerabilities in SCA findings.