IVarga775018 (Community Member) asked a question.

Can we scan multiple unrelated apps using separate sandboxes under a single Veracode app profile, just to run static scans (non-policy) for internal visibility? We’re limited in app profiles by license but want broader scan coverage.

Hi everyone,

 

We’re trying to extend our Veracode usage to cover more of our internal apps and microservices, but we’re limited by the number of application profiles allowed under our current license.

 

Right now, only a few core apps are being scanned. We’d like to scan additional apps — even if it’s not a full policy scan, but just a way to run static analysis (SAST) and review potential findings internally.

 

I understand that sandboxes are tied to a specific application profile. My question is:

 

Can we scan multiple distinct apps under different sandboxes of a single application profile — for example, using a unique sandbox per app — even if they aren’t part of the same codebase?

 

The intent is to:

 

  • Run static scans on each app
  • Use sandboxes to isolate the results
  • Avoid triggering policy evaluations
  • Provide visibility to our security team

 

Has anyone used sandboxes this way? Are there any official guidelines or licensing constraints that prevent this approach?

 

Thanks in advance!


IVarga775018 likes this.
  • SamHouston (Veracode)

    Hi @IVarga775018 (Community Member)​ - It sounds like you may want to speak with your Veracode account manager and ask about switching to per contributing developer licensing. That may be the best way to approach this issue.

     

    Otherwise, we do not have a workaround available.

Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.