πŸš€ Veracode Static Scanning in the veracode cli

Hello everyone, 

 

πŸŽ‰ I wanted to share an exciting update about the continued evolution of Static and the Unified Veracode CLI. This updated version of the CLI is available for download now, and allows users to perform Static scans using the same tool they use for interacting with Veracode policy, Veracode (container) scan, and Veracode fix. This is scanning using Veracode Pipeline Scan, which means it will have access to baseline files, Policy integration, guidance around integrating with Gitlab issues, as well as a number of ways to filter flaws, and apply metadata to your scan. It also produces the style of results used by Veracode Fix directly out of the box.

 

πŸ’» To Access the CLI:

  • If you already use the CLI, simply update to the latest version
  • Otherwise, follow the instructions on our help center, here!

 

πŸ—“οΈ  Looking Ahead:

 

Veracode is going to be releasing a Batch Fix functionality, using the results produced by veracode static scan. This will allow users to install the client, run a scan, and perform Veracode Fixes across large numbers of their flaws in the same, convenient place.

 

Veracode is also continuing its journey to unify our Static scanning methodologies, working towards enabling Pipeline Scans to be displayed in the web UI, as well as matching Mitigations across Policy and Pipeline Scans.

 


lucas.ferreira likes this.
  • thank you very much. Certanly, this functionality will help a lot! I'm excited to have a unified CLI which can start different scans. One of the best thing is won't be necessary to have Java installed to run it.

     

    Pipeline scan with the mitigations and have an option to see results in web UI would be great too.

Topics (7)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.