Veracode Visibility into Application Status

Does the solution provide visibility into application status at every phase of development - Veracode Static Analysis, Dynamic Analysis, Software Composition Analysis, and Manual Penetration Test throughout your SDLC? If yes, how does this affect your DevSecOps processes? Please explain.

Rishabh Khanna - PeerSpot reviewer
Security Engineer at a tech services company with 5,001-10,000 employees
The solution provides visibility into application status at every phase of development. We can see and make adjustments accordingly at each level.
View full review »
Zach Handzlik - PeerSpot reviewer
Release Manager/Scrum Master at Amtech Software
This solution provides visibility into application status at every phase of development. It goes from compiling the code all the way to running it in production. It covers all major aspects of the SDLC. We run static scans and SCA scans early on in the process to make sure that we catch any code that is insecure by design. If we are able to catch it earlier on, before it's actually out in the production environment, it reduces costs. The dynamic scans are run further along in our QA process. That is, once we've deployed the code and have it in a runtime environment, we run weekly scans in a dynamic environment against the code runtime to make sure that there aren't any new vulnerabilities that got introduced. We are looking at doing manual penetration testing in 2023, where we would be using a spinoff of the code that was released to the customers to make sure that there aren't any holes through which a nefarious actor could get in and exploit what was built.
View full review »
SumalyaGuha - PeerSpot reviewer
Security Engineer at a comms service provider with 10,001+ employees
It scans at three different integration points or stages, so it helps developers to remediate their vulnerabilities before they have moved far in pipeline. Shift-left is definitely possible through Veracode.
View full review »
HM
DevOps Engineer at Barclays Technology
With this solution, we have visibility into application status at every phase of development including static analysis, dynamic analysis, software composition analysis, and manual penetration test throughout our SDLC. It is helpful for our DevSecOps processes because we get all the details before going into production. We can then talk with the design team and developers to fix any issues before going live.
View full review »
DB
Security Engineer at a tech vendor with 10,001+ employees
The platform provides visibility into application status at every phase of the development- Veracode Static Analysis, Dynamic Analysis, Software Composition Analysis, and Manual Penetration Testing throughout our SDLC. In terms of DevSecOps processes, the solution makes them quicker and smoother, with less confusion.
View full review »
Reyansh Kumar - PeerSpot reviewer
Technical Specialist at Accenture
The solution provides visibility into application status at every development phase throughout the SDLC; we can use Veracode during the development, design, testing, and implementation phases. We can easily analyze our code before commencing large production deployments and fix any issues.
View full review »
AkashKhurana - PeerSpot reviewer
Senior Software Engineer at Publicis Sapient
Veracode provides visibility into the status of our application during every phase of development, including continuous integration and continuous development CI/CD pipeline stages. This includes builds, package creation for deployment, and various enrollment stages such as develop, queue, stage, above, and production enrollment. Prior to each stage, a Veracode scan is run. This can be accessed through Jenkins or the CI/CD pipeline by clicking on the Veracode scan option, which provides a detailed report highlighting any security issues and concerns.
View full review »
Michea Mbaziira - PeerSpot reviewer
Insurance Agent at ICEA
Veracode provides visibility into all phases of development.
View full review »
Hassan Saleh - PeerSpot reviewer
Managing Director at Century Bottling Company
Veracode provides insight into vulnerabilities at every stage, so your team can progress through the development cycle more efficiently. It improves developer confidence by showing us our capabilities and the potential of our code.
View full review »
Shashank Niranjan - PeerSpot reviewer
Senior Software Engineer at Capgemini
Veracode provides visibility into application status at every phase of development which makes it easier for our DevSecOps to do their jobs.
View full review »
Geofrey Mutabazi - PeerSpot reviewer
Founder at a manufacturing company with 1-10 employees
Having visibility into the status of our applications at every phase of development throughout the software development cycle enhances our DevOps productivity and ensures a stable solution.
View full review »
NS
Delivery Manager at a tech vendor with 10,001+ employees
Veracode provides visibility into application status, but we do not use it during every development phase. We only use Veracode before the code goes into production.
View full review »
Avinash Mukesh - PeerSpot reviewer
IT Specialists at Soft Hostings
Veracode provides visibility into application status throughout the development process. It is easy to understand the severity of a threat, thanks to their clear and concise documentation. This documentation can be used to understand code, security, vulnerabilities, and project management. Veracode also helps ensure compliance with all industry standards.
View full review »
VS
Sr. Web Application Security at a tech vendor with 10,001+ employees
It provides visibility to application status at every development stage.
View full review »
AjitMatthew - PeerSpot reviewer
Principal. - Head - IT, Information Security and Admin at a consultancy with 201-500 employees
Veracode helps to provide visibility into the application's status at every phase of development. This helps us ensure that our code is secure from the start, saving us time that would otherwise be spent sorting through bugs at the end.
View full review »
VS
Senior Manager Cyber Security at a tech services company with 201-500 employees
Veracode provides visibility into application status at every phase of development.
View full review »
VR
Solution Architect at a tech vendor with 10,001+ employees
We utilize Veracode for static and dynamic code scanning in our software configuration and lifecycle management. It is integrated as part of our pipeline, allowing the code to be automatically scanned in the background. This enables us to review the reports promptly.
View full review »
JV
Manager Consultant at a tech services company with 1-10 employees
Veracode provides visibility into the status of applications at every phase of development. It is one comprehensive integrated system, but we can also utilize specific features like SAST if we require it.
View full review »
Saket Pandey - PeerSpot reviewer
Product Manager at a hospitality company with 51-200 employees
Veracode provides visibility into the application's status at every phase of development. Primarily, we were only conducting two types of tests. One was continuous integration, which keeps track of the entire application's deployment process. It detects any defects and ensures a smooth deployment. The other test we used to perform at certain times was manual integration. We would delve deeper and test additional aspects because we wanted to ensure with utmost precision that there were no vulnerabilities when deploying the application. Hence, we also had to manually utilize this program before deploying or pushing it to the code.
View full review »
SR
Product Marketer at a media company with 1,001-5,000 employees
We get good, actionable insights at each stage, including static, dynamic, and penetration analysis, and it reduces overhead for us.
View full review »
AK
LSA at a consultancy with 10,001+ employees
Veracode offers visibility into the application's status at every phase of development, including static analysis, dynamic analysis, composition analysis, and manual penetration testing throughout the Software Development Life Cycle.
View full review »
Mahammad Azeem - PeerSpot reviewer
Application Architect at a tech services company with 10,001+ employees
Veracode provides visibility into the status of applications at every phase of development to a certain extent. Veracode scan reports present a comprehensive view of planned releases that are scheduled to go live in the coming days. To keep the team informed, we run a scheduled deployment, sending email notifications twice a week for each application. This alerts the team to any issues that may need fixing. However, it's worth noting that the system is not fully integrated into the pipeline and notifications. Nevertheless, Veracode offers an API. This interface allows us to obtain the XML result file, and subsequently, I can extract and analyze the values from the XML. Once the scan is complete, Veracode API will fetch the XML report and store it in my workspace within the pipeline. From there, I can execute an XML parser function to obtain the application status results.
View full review »
CS
Executive Assistant at a tech company with 51-200 employees
Veracode provides visibility into the application's status at every phase of development.
View full review »
Robert Hood - PeerSpot reviewer
Information Security Architect at a tech vendor with 5,001-10,000 employees
Although Veracode can offer visibility into the application's status at every phase of development, we do not rely on manual penetration testing because we have our own testing team. Instead, we use SAST from the moment our developers start typing the code until the deployment phase.
View full review »
Boyapati Sivannarayana - PeerSpot reviewer
Devops Engineer at Accenture
I'm not sure how much visibility we are getting using the solution.
View full review »
Dipjyoti Roy - PeerSpot reviewer
Senior Devops Engineer at Thosmon Reuters
Veracode has assisted our organization by providing a report that we can share with our developers, identifying vulnerabilities in their code. This enables them to address the issues before the code is put into production.
View full review »
Oscar Narvaez - PeerSpot reviewer
COE Head at a tech services company with 1,001-5,000 employees
Veracode offers visibility throughout the entire development lifecycle. SecOps is an essential framework inside the organization currently because we need to deliver applications to market faster while improving code quality. It's crucial to be careful when using code generated by community sources. We need to test the final applications and also the components and packages in any code repository we use.
View full review »
LF
Sales Engineer at a computer software company with 51-200 employees
Veracode provides visibility into application status at every phase of development. We can have many analytics dashboards and reports, and we can build a custom dashboard to have this visibility. This visibility is essential for DevSecOps processes. We need this visibility and information to have a strategic approach and mature our security.
View full review »
Arnab Paul - PeerSpot reviewer
Cyber Security Consultant at a consultancy with 10,001+ employees
We do have a dashboard in Veracode that offers visibility into the status of applications. There is a section where we can view the application names, and next to each name, there is a status report such as "The SAST has been completed" or "in progress," and the same goes for DAST.
View full review »
Sairam Bathini - PeerSpot reviewer
DevSecOps Engineer at Tata Consultancy
Veracode provides visibility into application status at every phase of development - Veracode Static Analysis, Dynamic Analysis, Software Composition Analysis, and Manual Penetration Test. We can get the entire application with all compliances.
View full review »
SM
Security Analyst at a tech services company with 11-50 employees
The solution provides absolute visibility into application status at every phase of development. The users can get visibility through the CI/CD pipeline.
View full review »
Freddy Bang. - PeerSpot reviewer
Chief Technology Officer at ELEARNINGFORCE International ApS
If you use it correctly and bring early feedback into the developers' environment, it provides visibility into application status at every phase of development... For us, it gives full insights. It changes the DevSecOps process process because we find flaws much earlier in the in the development life cycle, and we also spot third-party software that we don't allow, already, at the developer's machine.
View full review »
JW
Lead Product Security Engineer at a computer software company with 1,001-5,000 employees
Veracode provides visibility into application status in every phase of development.
View full review »
GR
System Engineer at a tech vendor with 10,001+ employees
Veracode provides visibility into application status at every phase of development, but we must manually scan applications to check the assessment for a specific application or after deploying it to a particular environment. I think they can change this so it automatically scans for us.
View full review »
CM
CyberSec professional at a manufacturing company with 5,001-10,000 employees
I am satisfied with Veracode's visibility into application status at every phase of development.
View full review »
Vikas Agrawal - PeerSpot reviewer
DevOps Lead at HealthEdge Software, Inc.
It provides visibility into application status at every phase of development. We have our initial feature branch, or low-level branch, and then we commit. The pipeline is running, so we will know about things immediately. This is quite valuable for us.
View full review »
TR
Associate Software Engineer at a healthcare company with 201-500 employees
Veracode provides comprehensive visibility into application security throughout the entire Software Development Lifecycle. During the coding stage, Veracode scans the entire codebase for vulnerabilities. Additionally, we utilize Veracode's static analysis capabilities for further security assessment. Once the product is published and deployed to the production environment, Veracode analyzes the entire software stack to identify any potential security risks. In short, Veracode plays a vital role in various stages of our software development and production process.
View full review »
KA
Cyber Security Consultant at a computer software company with 51-200 employees
It helped us a lot in mitigating the vulnerabilities. We were able to proactively react to anything malicious.
View full review »
AF
Cloud system engineer at a consultancy with 1-10 employees
Veracode provides visibility into application status at every phase of development.
View full review »
Deepak Naik - PeerSpot reviewer
Chief Security Officer at Digite
The solution provides visibility at every stage of development. We have automated almost everything through integration with Jenkins. As soon as the developer commits, it triggers the static scan for the main branches. We don't need to trigger the scan manually or do a follow-up to see if it's done scanning.
View full review »
Evan Gertis - PeerSpot reviewer
Penetration Tester at a tech vendor with 51-200 employees
To my knowledge, Veracode is the only real devSecOps pipeline that captures every component of the software delivery cycle, from sandbox and staging to development and production. You need to go through those four phases and ensure the code is secure by the time it hits production. Veracode handles all those phases seamlessly and can be automated with Jenkins.
View full review »
KS
Lead Consultant DevOps and Infrastructure at a tech vendor with 5,001-10,000 employees
Veracode can provide visibility into application status at every phase of development.
View full review »