Veracode
You can ingest SAST findings directly from Veracode into Cortex Cloud Application Security. This allows you to use Cortex Cloud Application Security's analysis and visualization tools to identify critical vulnerabilities, prioritize remediation efforts, and improve your application code security.
Veracode supports Cyclonedx, json and table output formats.
Limitations
Currently, Veracode SAST ingestion supports Veracode periodic and CLI scans. Pull Request scans and other types are not supported
History, deduplication and DevEx features such as PR comments, IDE, CLI and enforcement are not supported
Prerequisites
Cortex Cloud
Permissions: View/Edit permissions for Data Sources & Integrations Instance Admin, AppSec Admin, or GRBAC permissions
Connected VCS: Ensure that you have a connected version control system (VCS) and repositories.
Egress path: Create an egress path to establish the designated route for outbound data transmission from Cortex Cloud to third party services. For more information about configuring egress paths, refer to Egress configurations
Veracode
Permissions: At minimum, Reviewer permissions are required.
Access key: Generate and copy a Veracode access key. The access key includes a key ID and secret.
Onboarding steps
Navigate to Settings → Data Sources & Integrations → + Add New.
Search for and hover over Veracode and click Add, or Add Another Instance if an instance is already onboarded.
On the Configure Integration step of the integration wizard:
Fill in the provided fields:
Enter the Veracode key ID and secret from step 1b into their respective fields
Select your Veracode region from the Region dropdown
Click Authorize.
The integrationSelect Applications step of the integration wizard is displayed, including a list of Veracode applications automatically mapped to Cortex Cloud Application Security repositories.
Select an option, and click Save.
Select Automatically map future Veracode applications to automatically map all future applications to Cortex Cloud Application Security repositories
Click Next.
On the Map to Repositories step of the wizard:
Select an option:
Accept the displayed mapping as detected by Cortex Cloud Application Security . This does not require any action on your part
Manually configure mapping if Cortex Cloud Application Security could not match a project to a repository: Select Set in the Cortex Cloud Application Security Repository column, and select a repository from the list that is displayed
Reject mapping: Check the Don’t map any applications box
Manually modify mapping: Click Replace next to the existing mapped Cortex Cloud repository. This will open an option to select a different repository from the displayed list, allowing you to update the mapping
Click Next.
Verify integration
Verify the integration in Cortex Cloud:
On Data Sources & Integrations, filter for Veracode. Select the data source and confirm your instance and mapped projects show Connected.
Manage integration instances
Manage administration channels, credential rotation, and integration deletion in Third-party integrations lifecycle administration and automation.
Manage ingested findings
Investigate findings, prioritize issues, remediate risks, and enforce policies in Manage the third-party data lifecycle.
Last updated
Was this helpful?
