
Product Announcements — Mike M (Veracode TPM) (Community Member) asked a question.
This week's February Static Analysis Release includes the following:
Updated language and framework support
C/C++
- Improved flaw detection for exported functions
iOS
- Improved overall detection for taint based flaws
JavaScript
- Enhanced Angular 18 support
PL/SQL
- Improved flaw detection for out-of-scope code, resulting in a reduction in false positives
- Enhanced flaw detection for new variable declarations initialized with a taint source. As a result, this improvement may lead to an increase in the number of reported flaws.
- Improved SQL injection detection
Ruby on Rails
- Rails 3.4 and Rails 8 support
Other languages
- Improved CWE-259 and 798 flaw detection, resulting in a reduction in false positives for all languages
- Improved flaw description and remediation details for CWE-284 and CWE-115
- Updated CWE Top 25 to 2024 version. All policies having Auto-Update CWE Top 25 as Requirement are impacted by this change
.png)