SCM integrations
Veracode Repository Scanning and other Veracode-authored integrations add security to your source control management (SCM) tools. These integrations embed scanning, review, and remediation tasks into your build and deployment workflows. Use SCM integrations in addition to CI/CD integrations.
Veracode source control management (SCM) integrations allow you to:
- Scan all target repositories.
- Trigger scans on push or pull requests.
- Detect flaws in source code.
- Identify vulnerabilities in open-source components.
- Review results and remediate findings using the provided guidance.
- Import findings as issues or work items for tracking.
You can ingest data and findings from the Repository Scanning integrations for GitHub and GitLab into Veracode Risk Manager (VRM). You can also integrate Veracode with your SCM tools using the Veracode CLI.
To learn more about these integrations and interact with other users, visit the Community forum. If you don't see the integration you need, check the Open Source Projects.
Veracode APIs and integrations require access to specific region domains based on your Veracode account region. Contact your IT team to confirm that the required domains for your region are on your organization’s allowlist. Ensure one-way communication on port 443 to the REST API domain. For a full list, see domains and IP addresses to add to your allowlist.
Azure DevOps
Select from the following integrations.
- Azure DevOps Workflow Integration: add Repository Scanning with Static Analysis, SCA, and Container Security scans, and review findings.
- Azure DevOps Extension: add Static Analysis scanning to your pipelines and import findings as work items.
- Pipeline Scan: add Static Analysis scanning to your workflows.
- SCA agent: add SCA agent-based scanning.
Integration type: Veracode-authored
Bitbucket
SCA agent: add SCA agent-based scanning.
Integration type: Veracode-authored
GitHub
Select from the following integrations.
- GitHub Workflow Integration: add Repository Scanning with Static Analysis, SCA, and Container Security scans, and review findings.
- Veracode Risk Manager: ingest data and findings from the GitHub Workflow Integration into VRM.
- Pipeline Scan: add Static Analysis scanning to your workflows.
- Veracode Fix GitHub Action: automatically resolve flaws found in Pipeline Scans with Veracode Fix.
Integration type: Veracode-authored
GitLab
Select from the following integrations.
- GitLab Workflow Integration: add Repository Scanning, including Static Analysis, SCA, and Container Security scanning, and review findings.
- Veracode Risk Manager: ingest data and findings from the GitLab Workflow Integration into VRM.
- Pipeline Scan: add Static Analysis scanning to your workflows.
- SCA agent: add SCA agent-based scanning.
Integration type: Veracode-authored