Code Scanning over Veracode
What do you like best about the product?
It's a tool to make a static code scan and detect the exposed secrets or passwords before the application is released. We can create multiple sandboxes and run various parts of the code individually. Veracode can be easily integrated with CI/CD pipelines, making it easy to trigger the scan.
What do you dislike about the product?
Any meditation of false positive flaws is not straightforward or internal to the team. There is always dependency on the Veracode admin team to mitigate the flows, interrupting the overall workflow.
What problems is the product solving and how is that benefiting you?
We use Veracode for static code scanning to identify the vulnerabilities.
It helps us identify the same and fix the code as per the action plan.
We even conduct secure code review end to end for better code processing.
It helps us identify the same and fix the code as per the action plan.
We even conduct secure code review end to end for better code processing.
There are no comments to display