
TPolaki120583 (Community Member) asked a question.
I have recently started using the Veracode and its been a overwhelming with so many types of scans available. I would like to have some kind of Use case or Recommendations for when to use each of scan type.
- Use case or Recommendations for when to use each of scan type namely Greenlight IDE Scan, Sandbox IDE Scan, pipeline scan
- Is it recommended for Developers to have both greenlight and Sandbox scans run in IDE
- if already we have pipeline scan is it value add to have the above two scans.
- Is SCA analysis will be part of both sandbox scan and Pipeline scans?
- What scans are to be recommended to be run by Infosec and Development teams
- How is the effective way of utilizing the SAST License like per application or per individual project or bundle a group of Java projects
Thanks in Advance
.png)
Hi Teja,
Good day to you.
You can go ahead and review the product details on the Vera docs which has all the information regarding the scan and other functionality and this will help you to get answers to all your questions.
Regards,
Pranita
Veracode Support.