SBlair040934 (Community Member) asked a question.

Ruby on Rails static scan requires individual loading of every single source file

I use veracode gem to package my Rails app into a zip. I upload that to veracode platform for a static scan. It completes successfully.

When I go into Triage Flaws and click on a finding, it prompts me "Load the source file from your local system. Veracode is not uploading the source code to the Veracode Platform. You are only viewing your code in the browser"

 

It requires individual loading of every single file. This makes the platform extremely difficult to use to navigate the findings. Is there some way to load my entire source code structure so I can click each finding and view the source code immediately without having to individually upload a file every time?

 

Thanks!


  • SamHouston (Veracode)

    Hi @SBlair040934 (Community Member)​ - Yes - Veracode does currently require that you upload the source code file each time. Here are the steps:

     

    To view the source code in the context of the flaws detected during the static scan, follow these steps:

    1. Open the Triage Flaws page in the Veracode Platform.
    2. Select the Source Code Viewer option, usually found at the top-right of the page.
    3. Choose a flaw from the list to examine.
    4. When prompted, locate the source code file on your local system that corresponds to the application you scanned.
    5. Load the source file into the viewer. The Veracode Platform will display the code and highlight the line containing the flaw.
    6. You can navigate through the code to view other flaws or use the Go to Line feature to jump to a specific line.

     

    This process allows you to analyze the flaws effectively while ensuring your source code remains secure and is not uploaded to the Veracode Platform.

    Expand Post
    Selected as Best
  • SamHouston (Veracode)

    Hi @SBlair040934 (Community Member)​ - Yes - Veracode does currently require that you upload the source code file each time. Here are the steps:

     

    To view the source code in the context of the flaws detected during the static scan, follow these steps:

    1. Open the Triage Flaws page in the Veracode Platform.
    2. Select the Source Code Viewer option, usually found at the top-right of the page.
    3. Choose a flaw from the list to examine.
    4. When prompted, locate the source code file on your local system that corresponds to the application you scanned.
    5. Load the source file into the viewer. The Veracode Platform will display the code and highlight the line containing the flaw.
    6. You can navigate through the code to view other flaws or use the Go to Line feature to jump to a specific line.

     

    This process allows you to analyze the flaws effectively while ensuring your source code remains secure and is not uploaded to the Veracode Platform.

    Expand Post
    Selected as Best
  • SBlair040934 (Community Member)

    Thanks for the answer Sam. That's very unfortunate, what a terrible UX ! If Veracode doesn't want to store any of the code, there really should be a way to drop in all my code in a .zip or something? Or Veracode could at least store like 3 lines of the surrounding snippet... that would be a lot better than simply the name of the containing file.

    • SamHouston (Veracode)

      Hi @SBlair040934 (Community Member)​ - thanks for the feedback and clarification about what happened re: Zip file. This is great feedback and I'll share it with the team.

Topics (9)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.