Azure DevOps
Use the following integrations to add security scanning to your Azure DevOps pipelines.
- Azure DevOps Workflow Integration: embed Veracode Repository Scanning into your pipelines. Run Static Analysis, SCA, and Container Security scans, and review the results in Azure DevOps.
- Azure DevOps Extension: install the extension to add two tasks to Azure DevOps: Veracode Upload and Scan and Veracode Flaw Importer. Use the Upload and Scan task to upload application code for Static Analysis. Use the Flaw Importer task to import findings from Static Analysis, SCA, and Dynamic Analysis scans as Azure DevOps work items.
note
Veracode APIs and integrations require access to specific region domains, depending on your Veracode account region. Contact your IT team to ensure that the correct domains for your region are on the allowlist. Also ensure one-way communication on port 443 to the REST API domain. For details, see the complete list of domains and IP addresses to add to your allowlist.