Veracode Prevent Vulnerable Code

What is your impression of the solution’s ability to prevent vulnerable code from going into production? Please explain.

Miodrag Zarev - PeerSpot reviewer
Senior Software Engineer at a tech vendor with 11-50 employees
The quality of our software has improved significantly since we started using Veracode. We have a software development shop and also provide solutions for other companies. It's critical to have our software checked by Veracode.
View full review »
JS
Manager of Application Development and Integrations at a university with 1,001-5,000 employees
Veracode effectively prevented vulnerable code from going into production. I have a hard time validating that assumption, but I think it's good at that.
View full review »
Rishabh Khanna - PeerSpot reviewer
Security Engineer at a tech services company with 5,001-10,000 employees
Depending on the technology we are working with, the solution's ability to prevent vulnerable code from going into production whether it is Java-based code or ASP.net the efficient number of identification codes is the best in the market for legacy technologies.
View full review »
Rafael Mesquita - PeerSpot reviewer
Full Stack Software Developer at DreamDev
Veracode helped us prevent possible security breaches. The team can anticipate and correct issues earlier instead of waiting for someone to find the issue or discover it when your application is attacked.
View full review »
Zach Handzlik - PeerSpot reviewer
Release Manager/Scrum Master at Amtech Software
We feel very confident about Veracode's ability to prevent vulnerable code from going into production. Having the stamp of approval helps not only from a marketability standpoint but also from an overall good feeling within the organization that we're doing our part to help keep our code free from vulnerabilities.
View full review »
SumalyaGuha - PeerSpot reviewer
Security Engineer at a comms service provider with 10,001+ employees
It also has the ability to block a build. In pipeline scanning, there is a configuration that can be set whenever Veracode is integrated within the pipelines, with respect to the security level of the flaw. If there is a high or a critical issue, there's a way the build can be failed and blocked before going into production.
View full review »
HM
DevOps Engineer at Barclays Technology
It provides all the details to prevent vulnerable code from going into production. The Veracode scanning report shows where we need to create security and how to encrypt usernames, passwords, or other details. It's very helpful from an application security perspective.
View full review »
JA
Technical Architect at Orange España
It has the ability to statically scan your source code before it goes to production. It can be scanned within your testing environment or development environment, and that is very useful. And good explanations of all the vulnerabilities in your source code help take care of that in future code implementation as well.
View full review »
MC
Vice President of Engineering at Avant Assessment
Veracode is a valuable tool to have in the toolbox to prevent vulnerable code from going into production.
View full review »
Shiva Prasad Reddy - PeerSpot reviewer
Program Analyst at a tech services company with 10,001+ employees
It helps fix a lot of flaws and bugs. As a developer, you look at things with a different perspective with the Veracode results. You can see that certain things can be implemented in another way, how they can be more secure. As a result, it helps improve your level of understanding and decrease the number of production issues.
View full review »
‌B
Senior software engineer at a tech services company with 1,001-5,000 employees
Veracode assists in the prevention of vulnerable code from reaching production by providing a comprehensive review of security risks and comprehensive reports with thorough descriptions of the vulnerabilities. This allows us to address any security gaps in the release. Based on the severity, we should determine the standards for release. We should not have any security issues with a severity of medium or higher before releasing.
View full review »
DB
Security Engineer at a tech vendor with 10,001+ employees
The solution's ability to prevent vulnerable code from going into production is incredible. I have done several consultations and remediation calls with the app team, and Veracode catches almost everything. It picks up the same issues in everything we scan, and we've done a lot of retests that way; the tool is very proficient in this area.
View full review »
Reyansh Kumar - PeerSpot reviewer
Technical Specialist at Accenture
Veracode is excellent at preventing vulnerable code from going into production; the scans are speedy and give us a detailed analysis of our code.
View full review »
FN
Application Security Engineer at a financial services firm with 1,001-5,000 employees
The solution actually helps us to access the code. If there are vulnerable areas, it pinpoints them and those areas are blocked, fixed, or remediated. It's good if you want to scan your line of code.
View full review »
BahatiAsher Faith - PeerSpot reviewer
Software Developer at Appnomu Business Services
I like the fact that it can be used at any stage of application development. I use scanning with a particular piece of code. There is an extension that helps me to create my code easily in Visual Studio and then find flaws before deploying the code. It's definitely benefiting me and the organization. It's so quick and easy to create a code and then deploy it live.
View full review »
AkashKhurana - PeerSpot reviewer
Senior Software Engineer at Publicis Sapient
Veracode's ability to prevent vulnerable code from being deployed into production is crucial. Typically, if a dependency we use has security issues or concerns, Veracode suggests upgrading to a more secure version. For example, if we're using a PayPal dependency with version 1.3 and it has a security bug, Veracode suggests upgrading to version 1.4 which fixes the issue.
View full review »
Michea Mbaziira - PeerSpot reviewer
Insurance Agent at ICEA
Veracodes' ability to prevent vulnerable code from entering production works very well and it can detect the type of script used.
View full review »
Hassan Saleh - PeerSpot reviewer
Managing Director at Century Bottling Company
Veracode is great for preventing vulnerable code from going into production because it covers various programming languages like JavaScript and PHP. You can be confident that your code is secure no matter which language you use.
View full review »
Shashank Niranjan - PeerSpot reviewer
Senior Software Engineer at Capgemini
Veracode has helped us to identify the vulnerable code in our applications before we put them into production.
View full review »
Geofrey Mutabazi - PeerSpot reviewer
Founder at a manufacturing company with 1-10 employees
Veracode's capability to prevent the deployment of vulnerable code is impressive. It allows for quick detection of defects during the development cycle, leading to faster release of improved code, and ultimately ensuring that our product is free of vulnerabilities. This feature is a great advantage for our organization.
View full review »
KW
Founder/Developer at Sarkonah
I'm very pleased because it prevents vulnerable code from going into the software. It's definitely a helpful solution.
View full review »
Avinash Mukesh - PeerSpot reviewer
IT Specialists at Soft Hostings
The solution's ability to prevent vulnerable code from going into production is a good thing because we have not upgraded to detect any variable code before deployment. Therefore, it is a good way to start our campaign.
View full review »
Ivo Dias - PeerSpot reviewer
Sales Engineer at M3Corp
Veracode's ability to prevent vulnerable code from going into production is the main selling point that we talk about with our customers. It is one of the most important features.
View full review »
AjitMatthew - PeerSpot reviewer
Principal. - Head - IT, Information Security and Admin at a consultancy with 201-500 employees
Veracode's ability to prevent vulnerable code from entering production is both effective and thorough.
View full review »
VS
Senior Manager Cyber Security at a tech services company with 201-500 employees
Veracode prevents 90 percent of vulnerable code from being introduced into production.
View full review »
VR
Solution Architect at a tech vendor with 10,001+ employees
Veracode provides both us and our customers with confidence that our applications do not have any issues by helping to prevent any vulnerable code from being deployed in production.
View full review »
JV
Manager Consultant at a tech services company with 1-10 employees
Veracode prevents 100 percent of vulnerable code from entering production.
View full review »
UmarQureshi - PeerSpot reviewer
Security Lead at a retailer with 10,001+ employees
Once Veracode is correctly tuned, its ability to prevent vulnerable code from entering production increases.
View full review »
BF
Application Security Engineer at Advantasure
For the most part, we've had good luck with the static scans as well as the software composition analysis scans. Veracode does a decent job of catching most vulnerabilities from making it into production, but it doesn't catch everything.
View full review »
Saket Pandey - PeerSpot reviewer
Product Manager at a hospitality company with 51-200 employees
Veracode's ability to prevent vulnerable code from entering production is remarkable.
View full review »
SR
Product Marketer at a media company with 1,001-5,000 employees
Veracode provides a lot of programming language support and different frameworks are available, which enables us to get things into production much more efficiently... We have been able to completely secure our enterprise software with the solution.
We have also found more security vulnerabilities in our code, which has helped us produce much better applications for our end-users. Most of the time, vulnerabilities go unnoticed by humans. Veracode helps us pinpoint the exact vulnerability, what it affects, and it helps us correct it...
View full review »
AK
LSA at a consultancy with 10,001+ employees
Veracode helps prevent vulnerable code from being deployed into production by identifying problematic code. It enables us to send a report to the application developer, allowing them to address the vulnerabilities based on their criticality level. The developers are given six months to address medium-level issues and three months for critical ones. If the criteria are not mapped with the higher critical alerts present in those applications, we can enforce the build field and proceed without deploying it into production.
View full review »
SA
Manager IT at a tech company with 201-500 employees
Veracode or any other solution like it doesn't prevent anything. The product provides insight into the vulnerabilities, but it's up to the end-user to mitigate that and move it into production. If we fail to remedy the issue and move the code into production, it isn't Veracode's failure. We can't judge the product based on whether it could do that. The product is doing what it should be doing.
View full review »
Robert Hood - PeerSpot reviewer
Information Security Architect at a tech vendor with 5,001-10,000 employees
Veracode's ability to prevent vulnerable code from being deployed into production is excellent. It is considered one of the best scanning tools available. We have conducted several comparisons between Veracode and other products in the market, and Veracode consistently ranks first among those we have tested.
View full review »
OK
Sr. Development Manager at RWS Holdings PLC
It helps us save time and effort for a portion of our production. For example, if you're scheduling to release product improvements in the spring, you don't want to fix anything after it goes into production. From that perspective, fixing things before the code is released saves us time. It also protects our reputation because fewer issues are entering production.
View full review »
Boyapati Sivannarayana - PeerSpot reviewer
Devops Engineer at Accenture
We like that it can prevent vulnerable code to go into production.
View full review »
Oluseyi Osifalujo - PeerSpot reviewer
Executive Director at Precise Financial Systems Limited
Veracode does an excellent job to prevent vulnerable code from entering production.
View full review »
Shobana Raghu - PeerSpot reviewer
Application Development Analyst at a consultancy with 10,001+ employees
It helped me fix vulnerabilities and any other errors before deployment to the applications.
View full review »
Dipjyoti Roy - PeerSpot reviewer
Senior Devops Engineer at Thosmon Reuters
Veracode assists in preventing vulnerable code from entering production. It is essential to ensure that our applications entering production are free from errors.
View full review »
Oscar Narvaez - PeerSpot reviewer
COE Head at a tech services company with 1,001-5,000 employees
I rate Veracode 10 out of 10 for its ability to prevent vulnerable code from entering production. It has a lot of useful and intuitive features. In previous settings, static analysis was one of the primary use cases, but dynamic analysis is also helpful. Veracode is highly valuable because one vulnerability could result in service downtime or worse: a leak of customer information.
View full review »
Arnab Paul - PeerSpot reviewer
Cyber Security Consultant at a consultancy with 10,001+ employees
From a SAST perspective, Veracode can prevent vulnerable code from entering production by adhering to our manual checklist.
View full review »
Sairam Bathini - PeerSpot reviewer
DevSecOps Engineer at Tata Consultancy
It is a good idea to integrate Veracode into the DevOps pipeline because it would create a great impact on the application delivery. Previously, we used to do the security testing after the entire application was built. However, now we are integrating the security in the initial stages of development. We can find vulnerabilities while building the application and report them to the developer, making it easy to deliver.
View full review »
Anant Upadhyay - PeerSpot reviewer
Game Developer at Gamezlab
Veracode helps prevent vulnerable code from entering production, and it has a low false-positive rate, so it can reliably find real vulnerabilities.
View full review »
PB
ML engineer at a consultancy with 10,001+ employees
In terms of readiness for the production release, Veracode definitely helps us be confident and quickly identify the risks. There's a huge benefit in that area.
View full review »
AR
DevOps Engineer at a consultancy with 10,001+ employees
Before Veracode, the application was deployed to the production server and there would be a lot of bugs and issues. Once we implemented the Veracode scan, the full deployment issues were drastically reduced. In a month we do 10 releases and we used to get five or six post-deployment issues. Now, we barely get one or two.
View full review »
Freddy Bang. - PeerSpot reviewer
Chief Technology Officer at ELEARNINGFORCE International ApS
Veracode does a great job of preventing vulnerable code from going into production.
View full review »
JW
Lead Product Security Engineer at a computer software company with 1,001-5,000 employees
Veracode can block vulnerable code from going into production.
View full review »
GR
System Engineer at a tech vendor with 10,001+ employees
We do not receive many threats. The threats are very minimal. Therefore, I have never been in a situation where Veracode had to save me from vulnerable code entering production. However, it is still helpful for us and our managers to access our code to see what is happening and what can be improved using Veracode.
View full review »
Alice William - PeerSpot reviewer
Senior Web Developer at a insurance company with 1,001-5,000 employees
Veracode's ability to prevent vulnerable code from entering production is comprehensive and effective.
View full review »
CM
CyberSec professional at a manufacturing company with 5,001-10,000 employees
Veracode has been effective at preventing vulnerable code from entering production. I can easily enable the support team. Additionally, the reports are free. Although we are at the beginning of our journey, I can see that Veracode is capturing vulnerabilities.
View full review »
Jan Pašek - PeerSpot reviewer
Tech Lead at a financial services firm with 10,001+ employees
Veracode's analytical capabilities are very good, but I'm not sure if they have prevented security vulnerabilities from going into production in our case because we haven't been using them optimally. We're now working on integrating them into our development pipeline so that we can test applications before they're released. This will also allow us to familiarize ourselves with the sandboxes during development. I believe that if we start using Veracode correctly, it will be very beneficial in preventing security vulnerabilities from going live.
View full review »
PavanKumar18 - PeerSpot reviewer
Senior Testing Engineer at TollPlus LLC.
Veracode's ability to detect security vulnerabilities is excellent. We can feel confident that none of the vulnerabilities will make it into production. It doesn't take long to realize the benefits from it. The
View full review »
Vikas Agrawal - PeerSpot reviewer
DevOps Lead at HealthEdge Software, Inc.
Before integrating Veracode, we were getting so many security vulnerabilities on higher branches. We integrated it to fix that. It prevents vulnerable code from going into production. We have fewer vulnerabilities and bugs.
View full review »
TR
Associate Software Engineer at a healthcare company with 201-500 employees
Veracode does a great job preventing vulnerable code from going into production. For enterprise-level companies, saving time is paramount. Previously, manual testing took days and still didn't uncover as many issues as Veracode now identifies. Despite having a skilled testing team, their workload has been reduced by 70 percent thanks to Veracode. This newfound efficiency has revealed vulnerabilities we wouldn't have found otherwise. Veracode excels at showcasing issues and their severity, extending beyond violation errors to encompass potential security risks and logic-related issues. Its user-friendly interface simplifies the process for all users, regardless of their technical expertise. As a developer, I recognize the immense effort behind Veracode's seamless operation. It automates the grunt work, freeing up our developers to focus on other tasks.
View full review »
AF
Cloud system engineer at a consultancy with 1-10 employees
Veracode effectively identifies vulnerabilities within the code. My role is to analyze these vulnerabilities and assign a severity level before forwarding them to the development team. This allows them to address the issues before deployment to production.
View full review »
Deepak Naik - PeerSpot reviewer
Chief Security Officer at Digite
The solution effectively prevents vulnerabilities from entering production. We've drastically reduced our third-party VAPT-reported issues. Before Veracode, the third-party VAPT analysis reported hundreds of issues per application. Now it's down to about 20, and Veracode can address most of them.
View full review »
KS
Lead Consultant DevOps and Infrastructure at a tech vendor with 5,001-10,000 employees
Veracode's ability to prevent vulnerable code from entering the production environment is good.
View full review »