• marcboggs (Community Member)

    Select only the binaries you want scanned for static analysis. Selecting 3rd party components may show flaws, in them, but if you don't have access to source code for them, you won't be able to determine if the findings are false positives.

  • FRuvalcaba115755 (Community Member)

    Thanks for your answer. What would happen if a 3rd party component is referenced but not used by the project, and I don't select that 3rd party component as an entry point? Would Veracode skip it?

    • marcboggs (Community Member)

      I should not be scanned for static analysis, but should reflect vulnerabilities in SCA findings.

Topics (5)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.