Try our new research platform with insights from 80,000+ expert users

Veracode Visibility into Application Status

Does the solution provide visibility into application status at every phase of development - Veracode Static Analysis, Dynamic Analysis, Software Composition Analysis, and Manual Penetration Test throughout your SDLC? If yes, how does this affect your DevSecOps processes? Please explain.

reviewer2587689 - PeerSpot reviewer
reviewer2587689
Cloud/Devops Engineer at a computer software company with 1,001-5,000 employees
Veracode provides visibility into application status at every phase of development.
View full review »
Deepak Naik - PeerSpot reviewer
Deepak Naik
Chief Security Officer at a computer software company with 201-500 employees
The solution provides visibility at every stage of development. We have automated almost everything through integration with Jenkins. As soon as the developer commits, it triggers the static scan for the main branches. We don't need to trigger the scan manually or do a follow-up to see if it's done scanning.
View full review »
Evan Gertis - PeerSpot reviewer
Evan Gertis
Penetration Tester at a tech vendor with 51-200 employees
To my knowledge, Veracode is the only real devSecOps pipeline that captures every component of the software delivery cycle, from sandbox and staging to development and production. You need to go through those four phases and ensure the code is secure by the time it hits production. Veracode handles all those phases seamlessly and can be automated with Jenkins.
View full review »
reviewer2381340 - PeerSpot reviewer
reviewer2381340
Lead Consultant DevOps and Infrastructure at a tech vendor with 5,001-10,000 employees
Veracode can provide visibility into application status at every phase of development.
View full review »
MS
MukeshSaha
Associate Principal, Software Engineering at a tech vendor with 10,001+ employees
The visibility that Veracode provides is good. They provide a proper dashboard for everything. We have visibility into the application status at every phase of development - Static Analysis, Dynamic Analysis, Software Composition Analysis, and Manual Penetration Test. I am satisfied with it. We have not integrated it with our DevOps pipeline, but it has all the features for easy integration.
View full review »
reviewer2703864 - PeerSpot reviewer
reviewer2703864
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
The way we are using Veracode now means that since we haven't finished the rollout yet, we are not putting any restrictions on our pipelines so that they can only go to production if Veracode didn't find any critical vulnerability. Now, we are not using it as a blocker, so it depends on the team. Some teams don't want to appear in red in the reports from the last pipeline scan, so they are delivering much more secure code to production. Other teams don't care and still deliver with the same vulnerabilities, but that's something that varies from team to team. Generally, most teams have improved a lot, for example, by updating all the libraries and reducing all the critical and high vulnerabilities, delivering to production only with low or medium vulnerabilities.
View full review »
SR
SrikanthRaghavan
Principal Architect at a consultancy with 11-50 employees
Veracode provides visibility into application status at every phase of development, as it's how we stitch it together, allowing us to introduce it at various phases to gain fast feedback. This capability increases the velocity in DevSecOps processes as developers receive feedback on vulnerabilities before committing, reducing the overall rework.
Veracode provides visibility into application status at every phase of development, as it's how we stitch it together, allowing us to introduce it at various phases to gain fast feedback. This capability increases the velocity in DevSecOps processes as developers receive feedback on vulnerabilities before committing, reducing the overall rework.
View full review »
DK
Dristi Kurre
Lead Information Security Analyst at a financial services firm with 10,001+ employees
Veracode provides visibility into application status at every phase of development.
View full review »