SChaurasia183107 (Community Member) asked a question.

I am seeking assistance with the installation and setup of SAST in our environment. We need to ensure that the Fortify Static Code Analyzer is correctly configured and ready to run security scans on our source code.

Could you please provide guida

  • Bill T (Veracode)

    Hi @SChaurasia183107 (Community Member)​ , Thanks for your question. The Veracode Community (this site) is best placed to answer questions related to Veracode's products (including Veracode Static analysis) or general questions on how to remediate various types of software security issues in code regardless of the tools or methods used to find those issues.

     

    While I can't comment on specifics of how to setup and run Fortify's SAST tools, I can suggest that you take a look at the Microfocus documentation website(https://www.microfocus.com/en-us/support/documentation) and search for whichever product of theirs your organization is using.

     

    If you are still having trouble with Fortify, you might consider seeing if your organization or development team would be interested in switching over to Veracode. We have a number of developer friendly features such as integration of SAST into the developer's IDE, Integrations with Veracode SAST and GitHub actions so that scanning can be done from the repository swiftly and easily, quick and easy access to a team of software security experts who can guide you and your developers through fixing security issues in their code through a live online meeting. We even offer an AI-based auto-remediation product (Veracode Fix) which can help developers rapidly remediate security issues in their code.

    Being Cloud-based, Veracode SAST is very easy to get up and running, very little configuration is required and of course, we continually update our analysis capabilities so that all of our customers can benefit from improvements to our platform and technology without having to redeploy. Finally, we offer an analytics capability within the Veracode platform that can make it really easy to track and manage how well your organization is addressing software security risk, including a number of premade reports for management as well as the ability to create custom reports if you need to.

     

    If you are interested in learning more about how Veracode might be a good fit for your organization let me know which company you're working with and we can arrange for a follow-up discussion.

     

    Cheers,

     

    -Bill

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.