
cyoung144894 (Community Member) asked a question.
Veracode pipeline-scan is used. Github Marketplace https://github.com/marketplace/actions/veracode-pipeline-scan
The Veracode scan took approximately 9-10 minutes. We want to optimize the veracode scan time and get it down to roughly 3-5 minutes. The artifact jar file is approximately 100-150 MB in size.
Is there any chance of implementing:
- Is it possible to skip files that have previously been scanned in a previous scan and have had no modifications made to them?
- The article discusses how a median scanning duration of 90 seconds is attainable or close to that figure. https://www.veracode.com/blog/managing-appsec/veracodes-new-scan-type-delivers-results-devsecops-speed
.png)
hello @cyoung144894 (Community Member)
Pipeline scan tend to be faster than policy or sandbox scans, but, 90 seconds it's a reasonable time in general. Scans by pipeline scanner can take more than that depending of the size of application and complexity.