Thomas

Thomas

The author works at and owns Mint Security, a mean and lean security company founded in 2015. No fuzz (literally - we do not fuzz, there are companies better equipped to do that).

While docs.veracode.com (formerly known as help.veracode.com) is an excellent resource, it is not the most obviously intuitive tool out there. There’s got to be a better way, you say?

There is a better way

Well, now there is a better way. Let me present to you three world-class solution playbooks for integrating Veracode into your favourite CI/CD pipelines. Now, this is not just about getting a single scan done every now and then, these manuals (as they are called) go quite deep into different aspects of integration.

We’ve got the following gold-level topics with hands-on working examples

  • Using pipeline environment variables
  • Static scanning (SAST) using scripts, pre-built docker images as well as Github actions
  • Pipeline scans
  • SCA (that is Gartner-speek for 3rd party component and library analysis)
  • DAST – dynamic analysis (scanning your deployed live application)
  • Scanning different branches
  • Importing findings into security issues or pull request comments – and overall reporting
  • Using pipeline environment variables

In addition to these technical topics and templates, there is also discussion (and practical examples) on strategical decisions around scanning and most importantly discussion on how to build this into your organization.

The manuals

Veracode State of Software Security 12
Veracode
Thomas

Veracode State of Software Security 12

Similar to last year, we looked at the entire history of active applications, not just the activity associated with the application over one year. By doing so, we can view the full life cycle of applications, which results in more accurate metrics and observations.

Read More »
Thomas

Thomas

The author works at and owns Mint Security, a mean and lean security company founded in 2015. No fuzz (literally - we do not fuzz, there are companies better equipped to do that).

contact us

Please do contact us. We most likely respond faster than you thought,