• SamHouston (Veracode)

    Hi @SMadipelli752689 (Community Member)​ 

     

    Veracode scans are designed to be performed on code during development and testing phases, not on live production environments or production branches. This is achieved through the use of development sandboxes.

     

    These sandboxes allow your teams to scan application code during testing, outside of production environments, using tools like Veracode Upload and Scan for Static Analysis and SCA scans. This approach ensures that policy scans do not affect the compliance of the entire production application.

     

    Furthermore, sandbox scans provide feedback on in-development applications without degrading the policy compliance or flaw metrics of the production versions. This strategy supports branching and trunk-based development, enabling analysis of multiple versions concurrently.

     

    For more detailed information, refer to the documentation on Scan code in a sandbox.

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.