<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>DAST updates</title>
    <link>https://docs.veracode.com/updates</link>
    <description>Veracode DAST updates</description>
    <language>en</language>
    <copyright>Copyright © 2026 Facebook, Inc.</copyright>
    <lastBuildDate>Thu, 08 Oct 2026 00:00:00 GMT</lastBuildDate>
    <item>
            <title><![CDATA[DAST updates]]></title>
            <link>https://docs.veracode.com/updates/r/c_all_was</link>
            <guid>https://docs.veracode.com/updates/r/c_all_was</guid>
            <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[The updates on this page apply to the following Veracode Dynamic Application Security Testing (DAST) products and features. Subscribe to the DAST updates RSS feed Feed-icon.png.]]></description>
            <content:encoded><![CDATA[<p>The updates on this page apply to the following <a href="https://docs.veracode.com/r/Dynamic_Analysis" target="_blank" rel="noopener noreferrer" class="">Veracode Dynamic Application Security Testing</a> (DAST) products and features. Subscribe to the <a href="https://docs.veracode.com/updates/rss_dynamic.xml" target="_blank" rel="noopener noreferrer" class="">DAST updates RSS feed <img decoding="async" loading="lazy" alt="Feed-icon.png" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABAAAAAQCAYAAAAf8/9hAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAAB3RJTUUH6AUKDRQx5jYYZwAAAw5JREFUOI09kUtoXGUcxX//7/vunZvJYxIdTWyTxiQtRttog7RWaelKxdZorC5FUFAiQgk+NkKr1aUbxV3BjW1B8BF8oLu4sgUrta3BUqulJD5oEpMmmXtn7tzv4WLUsznnLA6cwxGAi4eHJ2/p7H7D+TDmCFpEQIEIIIJIS4sSjBEXHHN/Lawc23n86oxcmr7j0W2bbv2ytrJBlt5AR4JOInRbGV2KUUZQkbRYC6LBlGPIFRfP/P64fnn/wOcmzap5dYjKY68SD46hyl3QWCU0lhCjkMggCpCACATrUJGi2QjjJlYymtUzyn2DtO1+iv8QaksUP3+Fu3AS0j+RqBulFSLgCo/NciKjRvX0vr43S5FCjKCMhnwDKVeQcg968zjmzoOQLsLSHCpOcAXYhscXgXrdI/Ovj4f2RAMWcSmKHF2pEt/zBNF9U0h7FQB3+h2K7z/ASQXXDPhmYKPuUChQLiUeupfK9Cztz5wi3n4Qd/4EzROPEBZOA6AfeA1GJrBrq9jc43JP8KBEQJmAShJUdz9meC/xQ2+RPPsN6uYhis+exs9/B0DpwaP4cj82reOageADChFUuYOwOEc+8yL27HFCfRXpGSY6dBJ6d1H/5CXCxiKSdJLsfQFbq+GKAOHfBjqOEFfDX/kaO3sE+9EkYWkOdEx04D3sRko2+z4AyfgE0rUFm+WtBv9PUBDte4X4yQ+RUgfNmSlCuox09WF2PUd6+mN8bQUptRMN78bWUkIAJUoQX0dv3om5/zBq68Oo/cdo/nGZ5tlTAMQ7DmDX1mhePQdANDCGy21rglaCMgYaf0ORti67/gvOJeS//dAK9G/Hm06KpYWW7xvGO0EBMn90/NLAXZXRYm2d0DWCT26jeeUMNsvxqgNz+x58YUl//BbVM4Dp3UZz+Tr62k/Uq+ayXJgambh7z+AXaE99+QY2y3G+DVcobKPArq/jikAwnbisgc3qtLclVLf2ci1dmRSA888PHdq05aYjPjBmi6C9DwQPwbeuCj4QAhBAi7iopOZWsvW3d7z766f/ALd5WtiP5SpGAAAAAElFTkSuQmCC" width="16" height="16" class="img_ev3q"></a>.</p>
<p>Updates that apply to specific Veracode regions show a <a class="" href="https://docs.veracode.com/updates/r/c_release_notes">region icon</a>.</p>
<ul>
<li class=""><a href="https://docs.veracode.com/r/DAST-Essentials" target="_blank" rel="noopener noreferrer" class="">DAST (formerly DAST Essentials)</a></li>
<li class=""><a href="https://docs.veracode.com/r/Dynamic_Analysis" target="_blank" rel="noopener noreferrer" class="">Dynamic Analysis</a></li>
<li class=""><a href="https://docs.veracode.com/r/c_using_ism" target="_blank" rel="noopener noreferrer" class="">Internal Scanning Management (ISM)</a></li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="august-6-2026">August 6, 2026<a href="https://docs.veracode.com/updates/r/c_all_was#august-6-2026" class="hash-link" aria-label="Direct link to August 6, 2026" title="Direct link to August 6, 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="business-unit-and-scan-engine-enhancements">Business unit and scan engine enhancements<a href="https://docs.veracode.com/updates/r/c_all_was#business-unit-and-scan-engine-enhancements" class="hash-link" aria-label="Direct link to Business unit and scan engine enhancements" title="Direct link to Business unit and scan engine enhancements" translate="no">​</a></h3>
<p>You can now select a business unit when creating a web application or API specification target, or on the DAST configuration page.</p>
<p>The scan engine now provides improved detection for CAA record checks on SSL certificates for CWE-862 in both Dynamic Analysis and DAST.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="july-22-2026">July 22, 2026<a href="https://docs.veracode.com/updates/r/c_all_was#july-22-2026" class="hash-link" aria-label="Direct link to July 22, 2026" title="Direct link to July 22, 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="dast-custom-host-to-ip-address-mappings">DAST custom host-to-IP address mappings<a href="https://docs.veracode.com/updates/r/c_all_was#dast-custom-host-to-ip-address-mappings" class="hash-link" aria-label="Direct link to DAST custom host-to-IP address mappings" title="Direct link to DAST custom host-to-IP address mappings" translate="no">​</a></h3>
<p>You can now configure a <a href="https://docs.veracode.com/r/Configure_URLs_for_web_application_scans#configure-host-to-ip-address-mappings" target="_blank" rel="noopener noreferrer" class="">custom host</a> to define host-to-IP address mappings for DAST scans when DNS lookup is unavailable or not desired.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="june-26-2026">June 26, 2026<a href="https://docs.veracode.com/updates/r/c_all_was#june-26-2026" class="hash-link" aria-label="Direct link to June 26, 2026" title="Direct link to June 26, 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-2661">ISM endpoint 26.6.1<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-2661" class="hash-link" aria-label="Direct link to ISM endpoint 26.6.1" title="Direct link to ISM endpoint 26.6.1" translate="no">​</a></h3>
<p>This release includes security updates that resolve vulnerabilities identified in previous versions of the ISM endpoint.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="june-24-2026">June 24, 2026<a href="https://docs.veracode.com/updates/r/c_all_was#june-24-2026" class="hash-link" aria-label="Direct link to June 24, 2026" title="Direct link to June 24, 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-dast-directory-restrictions-and-schedule-enhancements">New DAST Directory Restrictions and Schedule enhancements<a href="https://docs.veracode.com/updates/r/c_all_was#new-dast-directory-restrictions-and-schedule-enhancements" class="hash-link" aria-label="Direct link to New DAST Directory Restrictions and Schedule enhancements" title="Direct link to New DAST Directory Restrictions and Schedule enhancements" translate="no">​</a></h3>
<p>You can now define <a href="https://docs.veracode.com/r/Configure_URLs_for_web_application_scans#control-the-scan-scope" target="_blank" rel="noopener noreferrer" class="">Directory Restrictions</a> in your target configuration to control the scan scope.</p>
<p>We have enhanced the <a href="https://docs.veracode.com/r/Schedule_a_scan" target="_blank" rel="noopener noreferrer" class="">DAST Schedule</a> feature with advanced scheduling capabilities. This update provides enhanced configuration options and greater flexibility for managing scan schedules.</p>
<p>The system automatically migrates all existing DAST schedules to enhanced schedules. After migration, scans continue to run using the enhanced scheduling feature.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="breaking-change---dast-rest-api">Breaking change - DAST REST API<a href="https://docs.veracode.com/updates/r/c_all_was#breaking-change---dast-rest-api" class="hash-link" aria-label="Direct link to Breaking change - DAST REST API" title="Direct link to Breaking change - DAST REST API" translate="no">​</a></h3>
<p>The scheduling API endpoints have changed. If you use the REST API to manage a schedule, update your integrations to use the new endpoints. Refer to the <a href="https://app.swaggerhub.com/apis/Veracode/veracode-dast-target-configuration-service-api/1.0.0" target="_blank" rel="noopener noreferrer" class="">DAST API specification</a> for details.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-2660">ISM endpoint 26.6.0<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-2660" class="hash-link" aria-label="Direct link to ISM endpoint 26.6.0" title="Direct link to ISM endpoint 26.6.0" translate="no">​</a></h3>
<p>This release includes security updates that resolve vulnerabilities identified in previous versions of the ISM endpoint.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="may-26-2026">May 26, 2026<a href="https://docs.veracode.com/updates/r/c_all_was#may-26-2026" class="hash-link" aria-label="Direct link to May 26, 2026" title="Direct link to May 26, 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-2650">ISM endpoint 26.5.0<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-2650" class="hash-link" aria-label="Direct link to ISM endpoint 26.5.0" title="Direct link to ISM endpoint 26.5.0" translate="no">​</a></h3>
<p>This update addresses security vulnerabilities identified in earlier versions. It includes patches to resolve security risks and strengthen system protection for security compliance.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="april-28-2026">April 28, 2026<a href="https://docs.veracode.com/updates/r/c_all_was#april-28-2026" class="hash-link" aria-label="Direct link to April 28, 2026" title="Direct link to April 28, 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="dast-full-scan-targets-are-migrating-to-full-scan-enterprise">DAST Full scan targets are migrating to Full scan Enterprise<a href="https://docs.veracode.com/updates/r/c_all_was#dast-full-scan-targets-are-migrating-to-full-scan-enterprise" class="hash-link" aria-label="Direct link to DAST Full scan targets are migrating to Full scan Enterprise" title="Direct link to DAST Full scan targets are migrating to Full scan Enterprise" translate="no">​</a></h3>
<p>As part of the ongoing scan engine consolidation, we are migrating all DAST targets that use the deprecated Full scan to Full scan Enterprise. After the migration, new analyses for migrated targets use Full scan Enterprise. Historical scan data remains unchanged.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-3-2026">March 3, 2026<a href="https://docs.veracode.com/updates/r/c_all_was#march-3-2026" class="hash-link" aria-label="Direct link to March 3, 2026" title="Direct link to March 3, 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="dast-essentials-rebranded-to-veracode-dast">DAST Essentials rebranded to Veracode DAST<a href="https://docs.veracode.com/updates/r/c_all_was#dast-essentials-rebranded-to-veracode-dast" class="hash-link" aria-label="Direct link to DAST Essentials rebranded to Veracode DAST" title="Direct link to DAST Essentials rebranded to Veracode DAST" translate="no">​</a></h3>
<p>DAST Essentials is officially rebranded to Veracode DAST. This is a name change only and does not impact product features, functionality, or capabilities.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="february-25-2026">February 25, 2026<a href="https://docs.veracode.com/updates/r/c_all_was#february-25-2026" class="hash-link" aria-label="Direct link to February 25, 2026" title="Direct link to February 25, 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-2620">ISM endpoint 26.2.0<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-2620" class="hash-link" aria-label="Direct link to ISM endpoint 26.2.0" title="Direct link to ISM endpoint 26.2.0" translate="no">​</a></h3>
<p>This update introduces improvements to the handling of large static files, including JavaScript assets, to prevent parsing errors during scans and reduce intermittent failures, particularly during authentication workflows.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="february-12-2026">February 12, 2026<a href="https://docs.veracode.com/updates/r/c_all_was#february-12-2026" class="hash-link" aria-label="Direct link to February 12, 2026" title="Direct link to February 12, 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="dast-target-creation-now-uses-enterprise-mode-by-default">DAST target creation now uses Enterprise mode by default<a href="https://docs.veracode.com/updates/r/c_all_was#dast-target-creation-now-uses-enterprise-mode-by-default" class="hash-link" aria-label="Direct link to DAST target creation now uses Enterprise mode by default" title="Direct link to DAST target creation now uses Enterprise mode by default" translate="no">​</a></h3>
<p>DAST target creation has been simplified and now uses Full scan Enterprise mode by default. The legacy Full scan option is deprecated and is no longer available when creating new targets or configuring Quick scan targets.
Existing targets that use legacy Full scan will continue to function. However, we recommend migrating these targets to Full scan Enterprise mode.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="january-22-2026">January 22, 2026<a href="https://docs.veracode.com/updates/r/c_all_was#january-22-2026" class="hash-link" aria-label="Direct link to January 22, 2026" title="Direct link to January 22, 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="scan-engine-updates">Scan engine updates<a href="https://docs.veracode.com/updates/r/c_all_was#scan-engine-updates" class="hash-link" aria-label="Direct link to Scan engine updates" title="Direct link to Scan engine updates" translate="no">​</a></h3>
<p>Dynamic Analysis and DAST Enterprise Mode now support scanning web applications for open ports. The scan engine also includes new detections for HTTP headers, TLS, and fingerprinting. These updates will be rolled out gradually.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="november-28-2025">November 28, 2025<a href="https://docs.veracode.com/updates/r/c_all_was#november-28-2025" class="hash-link" aria-label="Direct link to November 28, 2025" title="Direct link to November 28, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="end-of-life-for-discovery-scans">End of life for Discovery scans<a href="https://docs.veracode.com/updates/r/c_all_was#end-of-life-for-discovery-scans" class="hash-link" aria-label="Direct link to End of life for Discovery scans" title="Direct link to End of life for Discovery scans" translate="no">​</a></h3>
<p>Veracode is announcing the <a href="https://docs.veracode.com/r/Veracode_Glossary#end-of-life" target="_blank" rel="noopener noreferrer" class="">end of life</a> for Discovery scans. Discovery scans will no longer be available or supported.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="september-17-2025">September 17, 2025<a href="https://docs.veracode.com/updates/r/c_all_was#september-17-2025" class="hash-link" aria-label="Direct link to September 17, 2025" title="Direct link to September 17, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="dast-supports-application-linking">DAST supports application linking<a href="https://docs.veracode.com/updates/r/c_all_was#dast-supports-application-linking" class="hash-link" aria-label="Direct link to DAST supports application linking" title="Direct link to DAST supports application linking" translate="no">​</a></h3>
<p>DAST now supports manual application linking. This feature lets you link analysis run results to an application in the Veracode Platform to evaluate against policy and combine results from multiple scan types in a single report.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="august-28-2025">August 28, 2025<a href="https://docs.veracode.com/updates/r/c_all_was#august-28-2025" class="hash-link" aria-label="Direct link to August 28, 2025" title="Direct link to August 28, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="updated-the-ui-for-dast-analysis-run-page">Updated the UI for DAST Analysis Run page<a href="https://docs.veracode.com/updates/r/c_all_was#updated-the-ui-for-dast-analysis-run-page" class="hash-link" aria-label="Direct link to Updated the UI for DAST Analysis Run page" title="Direct link to Updated the UI for DAST Analysis Run page" translate="no">​</a></h3>
<p>DAST Analysis Run page is refreshed with a clean, modern user interface. The updated design makes the page easier to use without changing existing workflows.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="june-30-2025">June 30, 2025<a href="https://docs.veracode.com/updates/r/c_all_was#june-30-2025" class="hash-link" aria-label="Direct link to June 30, 2025" title="Direct link to June 30, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="added-easm-integration-with-dast">Added EASM integration with DAST<a href="https://docs.veracode.com/updates/r/c_all_was#added-easm-integration-with-dast" class="hash-link" aria-label="Direct link to Added EASM integration with DAST" title="Direct link to Added EASM integration with DAST" translate="no">​</a></h3>
<p>EASM now automatically <a href="https://docs.veracode.com/r/Manage_discovered_targets" target="_blank" rel="noopener noreferrer" class="">creates discovered targets</a> in DAST. You can map these targets or convert them to regular DAST targets for scanning.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="june-9-2025">June 9, 2025<a href="https://docs.veracode.com/updates/r/c_all_was#june-9-2025" class="hash-link" aria-label="Direct link to June 9, 2025" title="Direct link to June 9, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhanced-reporting-capabilities-in-dast-enterprise-mode">Enhanced reporting capabilities in DAST Enterprise mode<a href="https://docs.veracode.com/updates/r/c_all_was#enhanced-reporting-capabilities-in-dast-enterprise-mode" class="hash-link" aria-label="Direct link to Enhanced reporting capabilities in DAST Enterprise mode" title="Direct link to Enhanced reporting capabilities in DAST Enterprise mode" translate="no">​</a></h3>
<p>DAST Enterprise mode now supports <a href="https://docs.veracode.com/r/Understand_the_scan_results" target="_blank" rel="noopener noreferrer" class="">downloadable scan reports</a>. These reports provide greater visibility into scan coverage and scanner behavior.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="may-20-2025">May 20, 2025<a href="https://docs.veracode.com/updates/r/c_all_was#may-20-2025" class="hash-link" aria-label="Direct link to May 20, 2025" title="Direct link to May 20, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-2550">ISM endpoint 25.5.0<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-2550" class="hash-link" aria-label="Direct link to ISM endpoint 25.5.0" title="Direct link to ISM endpoint 25.5.0" translate="no">​</a></h3>
<p>This update introduces a fix for an issue in which virtual threads could occasionally become starved under high load.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="april-28-2025">April 28, 2025<a href="https://docs.veracode.com/updates/r/c_all_was#april-28-2025" class="hash-link" aria-label="Direct link to April 28, 2025" title="Direct link to April 28, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="dast-ai-assisted-login">DAST AI-assisted login<a href="https://docs.veracode.com/updates/r/c_all_was#dast-ai-assisted-login" class="hash-link" aria-label="Direct link to DAST AI-assisted login" title="Direct link to DAST AI-assisted login" translate="no">​</a></h3>
<p><a href="https://docs.veracode.com/r/DAST_Essentials_Enterprise_mode" target="_blank" rel="noopener noreferrer" class="">DAST Enterprise mode</a> now provides an AI-based authentication method to sign in to web applications. Even complex login flows that previously required recorded login scripts can now be covered by configuring AI-Assisted Login instead.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-27-2025">March 27, 2025<a href="https://docs.veracode.com/updates/r/c_all_was#march-27-2025" class="hash-link" aria-label="Direct link to March 27, 2025" title="Direct link to March 27, 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="dast-enterprise-mode">DAST Enterprise mode<a href="https://docs.veracode.com/updates/r/c_all_was#dast-enterprise-mode" class="hash-link" aria-label="Direct link to DAST Enterprise mode" title="Direct link to DAST Enterprise mode" translate="no">​</a></h3>
<p><a href="https://docs.veracode.com/r/DAST_Essentials_Enterprise_mode" target="_blank" rel="noopener noreferrer" class="">DAST Enterprise mode</a> is now available. It enhances the security testing of web applications and APIs by integrating with the Veracode Platform, significantly improving policy enforcement and analytics.
Analyses conducted using Enterprise mode offer the following benefits:</p>
<ul>
<li class="">Additional authentication configuration: Includes support for login scripts, scanner variables, and client certificates for web applications, as well as Scriptable Request Modifications (SRM) for APIs.</li>
<li class="">Improved API specification management: Users can now upload or dynamically reference API specifications with ease.</li>
<li class="">Internal Scanning Management (ISM): Enables scanning of web applications and APIs hosted behind a corporate firewall.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="october-22-2024">October 22, 2024<a href="https://docs.veracode.com/updates/r/c_all_was#october-22-2024" class="hash-link" aria-label="Direct link to October 22, 2024" title="Direct link to October 22, 2024" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-24100">ISM endpoint 24.10.0<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-24100" class="hash-link" aria-label="Direct link to ISM endpoint 24.10.0" title="Direct link to ISM endpoint 24.10.0" translate="no">​</a></h3>
<p>This update introduces the proxy exclusion list, which includes hosts that bypass the configured proxy settings. By default, all traffic routes through the proxy except for hosts on the exclusion list.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="september-19-2024">September 19, 2024<a href="https://docs.veracode.com/updates/r/c_all_was#september-19-2024" class="hash-link" aria-label="Direct link to September 19, 2024" title="Direct link to September 19, 2024" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="public-rest-api-for-dast">Public REST API for DAST<a href="https://docs.veracode.com/updates/r/c_all_was#public-rest-api-for-dast" class="hash-link" aria-label="Direct link to Public REST API for DAST" title="Direct link to Public REST API for DAST" translate="no">​</a></h3>
<p>The <a href="https://docs.veracode.com/r/DAST_Essentials_REST_API" target="_blank" rel="noopener noreferrer" class="">DAST Target Configuration Service REST API</a> is now available. Use this API to automate the management of DAST targets and trigger analyses.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="july-15-2024">July 15, 2024<a href="https://docs.veracode.com/updates/r/c_all_was#july-15-2024" class="hash-link" aria-label="Direct link to July 15, 2024" title="Direct link to July 15, 2024" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="improved-target-configuration-pages-in-dast">Improved target configuration pages in DAST<a href="https://docs.veracode.com/updates/r/c_all_was#improved-target-configuration-pages-in-dast" class="hash-link" aria-label="Direct link to Improved target configuration pages in DAST" title="Direct link to Improved target configuration pages in DAST" translate="no">​</a></h3>
<p>DAST has a new look and feel for target configuration. Additionally, you can now switch between non-invasive quick scans and invasive full scans.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="june-27-2024">June 27, 2024<a href="https://docs.veracode.com/updates/r/c_all_was#june-27-2024" class="hash-link" aria-label="Direct link to June 27, 2024" title="Direct link to June 27, 2024" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-scanning-now-supports-postman-collections">API Scanning now supports Postman Collections<a href="https://docs.veracode.com/updates/r/c_all_was#api-scanning-now-supports-postman-collections" class="hash-link" aria-label="Direct link to API Scanning now supports Postman Collections" title="Direct link to API Scanning now supports Postman Collections" translate="no">​</a></h3>
<p>You can now <a href="https://docs.veracode.com/r/Create_an_API_Specification_Scan" target="_blank" rel="noopener noreferrer" class="">upload and scan Postman Collections</a> in the Veracode Platform.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="may-15-2024">May 15, 2024<a href="https://docs.veracode.com/updates/r/c_all_was#may-15-2024" class="hash-link" aria-label="Direct link to May 15, 2024" title="Direct link to May 15, 2024" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-2455">ISM endpoint 24.5.5<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-2455" class="hash-link" aria-label="Direct link to ISM endpoint 24.5.5" title="Direct link to ISM endpoint 24.5.5" translate="no">​</a></h3>
<p>This update includes performance improvements to Internal Scanning Management (ISM). To install this endpoint, you must have Java 21 or greater.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-28-2024">March 28, 2024<a href="https://docs.veracode.com/updates/r/c_all_was#march-28-2024" class="hash-link" aria-label="Direct link to March 28, 2024" title="Direct link to March 28, 2024" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="improved-pause-and-resume-scheduling">Improved pause and resume scheduling<a href="https://docs.veracode.com/updates/r/c_all_was#improved-pause-and-resume-scheduling" class="hash-link" aria-label="Direct link to Improved pause and resume scheduling" title="Direct link to Improved pause and resume scheduling" translate="no">​</a></h3>
<p>You can now <a href="https://docs.veracode.com/r/Scheduling_Dynamic_Analysis_Scans" target="_blank" rel="noopener noreferrer" class="">schedule an analysis</a> to pause and resume on specific days of the week, during specific periods, or both.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="previous-updates">Previous updates<a href="https://docs.veracode.com/updates/r/c_all_was#previous-updates" class="hash-link" aria-label="Direct link to Previous updates" title="Direct link to Previous updates" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2023-updates">2023 updates<a href="https://docs.veracode.com/updates/r/c_all_was#2023-updates" class="hash-link" aria-label="Direct link to 2023 updates" title="Direct link to 2023 updates" translate="no">​</a></h3>
<details class="details_lb9f alert alert--info details_b_Ee collapse-component" data-collapsed="true"><summary>2023 updates</summary><div><div class="collapsibleContent_i85q"><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="december-19-2023">December 19, 2023<a href="https://docs.veracode.com/updates/r/c_all_was#december-19-2023" class="hash-link" aria-label="Direct link to December 19, 2023" title="Direct link to December 19, 2023" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="web-application-and-api-scans-now-support-multi-factor-authentication">Web application and API scans now support multi-factor authentication<a href="https://docs.veracode.com/updates/r/c_all_was#web-application-and-api-scans-now-support-multi-factor-authentication" class="hash-link" aria-label="Direct link to Web application and API scans now support multi-factor authentication" title="Direct link to Web application and API scans now support multi-factor authentication" translate="no">​</a></h5><p>You can now configure <a href="https://docs.veracode.com/r/c_was_conf_url3#scanner-variables" target="_blank" rel="noopener noreferrer" class="">web application scans</a> and <a href="https://docs.veracode.com/r/Configure_and_Run_an_API_Specification_Scan" target="_blank" rel="noopener noreferrer" class="">API scans</a> to use time-based one-time password (TOTP) seeds for URLs that require multi-factor authentication (MFA). You can also configure TOTP with the <a href="https://docs.veracode.com/r/Create_a_Credentials_Variable_for_Dynamic_Analysis_Login_Scripts_with_the_REST_API" target="_blank" rel="noopener noreferrer" class="">REST API</a>.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="december-12-2023">December 12, 2023<a href="https://docs.veracode.com/updates/r/c_all_was#december-12-2023" class="hash-link" aria-label="Direct link to December 12, 2023" title="Direct link to December 12, 2023" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-23121">ISM endpoint 23.12.1<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-23121" class="hash-link" aria-label="Direct link to ISM endpoint 23.12.1" title="Direct link to ISM endpoint 23.12.1" translate="no">​</a></h5><ul>
<li class="">The endpoint now supports Java 21.</li>
<li class="">Adds virtual threading functionality to improve performance and stability. Before you can use this functionality, you must upgrade to Java 21.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="november-27-2023">November 27, 2023<a href="https://docs.veracode.com/updates/r/c_all_was#november-27-2023" class="hash-link" aria-label="Direct link to November 27, 2023" title="Direct link to November 27, 2023" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="free-trial-of-dast">Free trial of DAST<a href="https://docs.veracode.com/updates/r/c_all_was#free-trial-of-dast" class="hash-link" aria-label="Direct link to Free trial of DAST" title="Direct link to Free trial of DAST" translate="no">​</a></h5><p>Veracode now offers a free 14-day trial of <a href="https://docs.veracode.com/r/crashtest-security-suite" target="_blank" rel="noopener noreferrer" class="">DAST</a> in the Veracode Platform. To sign up, on the Sign in page, select <strong>Sign Up</strong> to create your account. If you are a Veracode customer and want to try DAST, contact your sales associate.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="november-15-2023">November 15, 2023<a href="https://docs.veracode.com/updates/r/c_all_was#november-15-2023" class="hash-link" aria-label="Direct link to November 15, 2023" title="Direct link to November 15, 2023" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="introducing-dast">Introducing DAST<a href="https://docs.veracode.com/updates/r/c_all_was#introducing-dast" class="hash-link" aria-label="Direct link to Introducing DAST" title="Direct link to Introducing DAST" translate="no">​</a></h5><p><a href="https://docs.veracode.com/r/crashtest-security-suite" target="_blank" rel="noopener noreferrer" class="">DAST</a> is a new Dynamic Application Security Testing (DAST) product that provides rapid and resilient DAST scanning of web applications and REST APIs, a user-friendly interface, and seamless CI/CD pipeline integration. To get started, see the <a href="https://docs.veracode.com/r/DAST_Essentials_quickstart" target="_blank" rel="noopener noreferrer" class="">quickstart</a>.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="september-25-2023">September 25, 2023<a href="https://docs.veracode.com/updates/r/c_all_was#september-25-2023" class="hash-link" aria-label="Direct link to September 25, 2023" title="Direct link to September 25, 2023" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="web-application-and-api-scans-now-support-custom-cookies">Web application and API scans now support custom cookies<a href="https://docs.veracode.com/updates/r/c_all_was#web-application-and-api-scans-now-support-custom-cookies" class="hash-link" aria-label="Direct link to Web application and API scans now support custom cookies" title="Direct link to Web application and API scans now support custom cookies" translate="no">​</a></h5><p>You can now configure web application scans and API scans to use one or more custom cookies for authentication.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="may-9-2023">May 9, 2023<a href="https://docs.veracode.com/updates/r/c_all_was#may-9-2023" class="hash-link" aria-label="Direct link to May 9, 2023" title="Direct link to May 9, 2023" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-2350">ISM endpoint 23.5.0<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-2350" class="hash-link" aria-label="Direct link to ISM endpoint 23.5.0" title="Direct link to ISM endpoint 23.5.0" translate="no">​</a></h5><p>Added executable scripts that update the <code>JAVA_HOME</code> path for the endpoint.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="april-25-2023">April 25, 2023<a href="https://docs.veracode.com/updates/r/c_all_was#april-25-2023" class="hash-link" aria-label="Direct link to April 25, 2023" title="Direct link to April 25, 2023" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-2342">ISM endpoint 23.4.2<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-2342" class="hash-link" aria-label="Direct link to ISM endpoint 23.4.2" title="Direct link to ISM endpoint 23.4.2" translate="no">​</a></h5><ul>
<li class="">The endpoint now supports environments where the target host is on the same host as the client.</li>
<li class="">Source code files now include a copyright header.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="february-27-2023">February 27, 2023<a href="https://docs.veracode.com/updates/r/c_all_was#february-27-2023" class="hash-link" aria-label="Direct link to February 27, 2023" title="Direct link to February 27, 2023" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="set-url-scan-settings-at-the-organization-level">Set URL Scan Settings at the Organization Level<a href="https://docs.veracode.com/updates/r/c_all_was#set-url-scan-settings-at-the-organization-level" class="hash-link" aria-label="Direct link to Set URL Scan Settings at the Organization Level" title="Direct link to Set URL Scan Settings at the Organization Level" translate="no">​</a></h5><p>You can now use the <a href="https://docs.veracode.com/r/Set_Dynamic_Analysis_URL_Scan_Settings_for_an_Organization_with_the_REST_API" target="_blank" rel="noopener noreferrer" class="">Dynamic Analysis REST API</a> to set URL scan settings for all analyses and scans in an organization.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="february-17-2023">February 17, 2023<a href="https://docs.veracode.com/updates/r/c_all_was#february-17-2023" class="hash-link" aria-label="Direct link to February 17, 2023" title="Direct link to February 17, 2023" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-manual-resume-feature-for-paused-analyses">New Manual Resume Feature for Paused Analyses<a href="https://docs.veracode.com/updates/r/c_all_was#new-manual-resume-feature-for-paused-analyses" class="hash-link" aria-label="Direct link to New Manual Resume Feature for Paused Analyses" title="Direct link to New Manual Resume Feature for Paused Analyses" translate="no">​</a></h5><p>Veracode Dynamic Analysis adds a new feature that enables you to <a href="https://docs.veracode.com/r/Manually_Resume_a_Paused_Dynamic_Analysis" target="_blank" rel="noopener noreferrer" class="">manually resume a scheduled analysis</a> from a paused state. This feature is only available upon request. To add this feature to your account, contact Veracode Technical Support.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="january-20-2023">January 20, 2023<a href="https://docs.veracode.com/updates/r/c_all_was#january-20-2023" class="hash-link" aria-label="Direct link to January 20, 2023" title="Direct link to January 20, 2023" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="renamed-url-scan-status-messages">Renamed URL Scan Status Messages<a href="https://docs.veracode.com/updates/r/c_all_was#renamed-url-scan-status-messages" class="hash-link" aria-label="Direct link to Renamed URL Scan Status Messages" title="Direct link to Renamed URL Scan Status Messages" translate="no">​</a></h5><p>Veracode has renamed and changed the descriptions for the following <a href="https://docs.veracode.com/r/c_was_statuses" target="_blank" rel="noopener noreferrer" class="">URL scan status messages</a> for Dynamic Analysis. The new names more accurately describe the issues that caused these status messages to appear in the Veracode Platform.</p><ul>
<li class=""><code>Killed - Partial Results Available</code> is now <code>Lockout - Partial Results Available</code>.</li>
<li class=""><code>Killed - Verifying Partial Results</code> is now <code>Lockout - Verifying Partial Results</code>.</li>
</ul></div></div></details>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2022-updates">2022 updates<a href="https://docs.veracode.com/updates/r/c_all_was#2022-updates" class="hash-link" aria-label="Direct link to 2022 updates" title="Direct link to 2022 updates" translate="no">​</a></h3>
<details class="details_lb9f alert alert--info details_b_Ee collapse-component" data-collapsed="true"><summary>2022 updates</summary><div><div class="collapsibleContent_i85q"><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="december-19-2022">December 19, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#december-19-2022" class="hash-link" aria-label="Direct link to December 19, 2022" title="Direct link to December 19, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-22123">ISM endpoint 22.12.3<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-22123" class="hash-link" aria-label="Direct link to ISM endpoint 22.12.3" title="Direct link to ISM endpoint 22.12.3" translate="no">​</a></h5><ul>
<li class="">Fixed an endpoint issue that caused threads to lock up until the ISM tunnel closes.</li>
<li class="">Improved endpoint logging that Veracode Technical Support can use for troubleshooting.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="october-21-2022">October 21, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#october-21-2022" class="hash-link" aria-label="Direct link to October 21, 2022" title="Direct link to October 21, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-available-for-dynamic-analysis-">ISM available for Dynamic Analysis <img decoding="async" loading="lazy" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABYAAAAWCAYAAADEtGw7AAAEq0lEQVR4XrVVW09UZxRdZ0B8MY3WGvGG4FyAEZgLDDJch4sCrWklOhYx1isKCjbBtiJVg0IFFDLIbQS5ysVb25f+gT761iZt4oM+tPrgX0D45ttdZ8BorX0x7U5WcrK/fdbee+19zgf8fyYGgg9i0NpqeftkyegPtMZGY8xnMz6Kfxh9wZh/OTMtEAtnMA7RwPc0Zyvfz+tMQFGoESUDD1E8+AuKh/5AYPAZCvqfGgW9jwz/jR/g77yxIvdKLXyXiuC+aEd6/Rq8mdh5ehVSmhxIaT6AlJaf4WiuAnYOK1ROCyrnBBX3lrDrrqBsVhCgr/AOMSbwTQn8g2Lxh+Ytvu4X8HY9gafzd7g6HhPPkdG1AFdIkNYpsDZ9jijp7h/nUXl/EeX3FHbORYyymQiKZyPrdg+pNZXhxZWl4wv7GhsXVxaPR+Bj0uxpMfxMlj3KhLcFWUTmCDH6EmnXBUlfBoFdk6z2gWKVGmVzGqUzGoEZgfcn+aSuSZ/85rAgd1o3XqjRK/JHdMGh89q5py2CzImIkT2ikEV4b0XgGdJwhxWc15aJy8YF5fcVSmdJyuoL7srmz3ol2HBakHdHYgpYmX+CiSiNZ0Y+rW2QvOrzAgcl87JK7y36wwLXgIZrUCH1OxI3kLiE7ZTdVSiZ1iimnnmz8lHFgFQ3nCIhu/Ezcc6YWHJui7GDRBnUOmNcgrUnZH1RlyB9WOAeoK9PI71fIfkqietJXER9SuYUAnd0dFAFk7K6jIE+Vp9D0h2jb2g5IpYss8JbcrDusKwv7BBsD4uR0ceh9WpCwdEqSDhJ4kJmDMwoFE5p5LPlnEnp6PhY0qqY2TMl1DFKCO/w67bdQwLniMRlhsxKTVIm6NHYHlKwXybxcRLnM7hwWpFUv2o7Lpc+19QSYebfCQ2z7dRhSau4IG2XdvK5zyRlom6N1B4F20XBJpM4l9nzpxT8Yxo5bNk7IfGl3bL/VC3JhsXi5bmHcA+aA2KF/dSVSB6UD7K4AU6TlEi5rgmFbRdIfITEOxicO6mopUY2dfSMyYaSLjlQd5SVMJGTQ3P3i8XVt9y2WWGv7DtyWD7MbuN2UI5U7m5yh4ajUyGpeZnYx+w5Ewq+ER1dcrNtN7FtWvL2NknlwTq+RDkc4ShhTHo3qwtJzfEa2Zh7SWDrMUkF9msa9g6FxK8F8YdInHmTEx9V1FJz2lz0sDI8AwrbhyKp5S2RvKqzOtbVo+sb92okh/SxuqBUVJ/QiGey5K6lSk1SW7uGtU0h4RyJD+4DPJxo1vjL6NTNaZs6pvdxhZgwhbrawrLS1R2p+uLoYlzG9YW1viuLa7Naua+dEcNxLQKbiXYF69VFWNvnsaVJsL66BsigPunmANoXkHL5ORwtj2Fv/o14YjiaX1gcLfOwcYW2sF0HNbVyYFazdX5hNsJq+ri7id9yzb4SbKxViN9fDCTzN2c/dwDbzjiwLrjq9U+Vv8XEPaux+YgdiScCK5KO1WJr/Q0j6cz32NrwCAmNT4ln2HLmT2yu+xWbjj3ExkNnsaFm6xsc72UGnE7zQoh9+2DZzKvEvFLeeWOYPmPpSjJjeEVFn99lr2LeyfPf2V8irVVJtnQH8AAAAABJRU5ErkJggg==" width="22" height="22" class="img_ev3q"><a href="https://docs.veracode.com/updates/r/c_all_was#ism-available-for-dynamic-analysis-" class="hash-link" aria-label="Direct link to ism-available-for-dynamic-analysis-" title="Direct link to ism-available-for-dynamic-analysis-" translate="no">​</a></h5><p><a href="https://docs.veracode.com/r/Internal_Scanning_Management" target="_blank" rel="noopener noreferrer" class="">Internal Scanning Management (ISM)</a> is now available for Veracode Dynamic Analysis of web applications and API specifications in the European region.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="october-18-2022">October 18, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#october-18-2022" class="hash-link" aria-label="Direct link to October 18, 2022" title="Direct link to October 18, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-scanning-adds-support-for-scriptable-request-modification">API Scanning Adds Support for Scriptable Request Modification<a href="https://docs.veracode.com/updates/r/c_all_was#api-scanning-adds-support-for-scriptable-request-modification" class="hash-link" aria-label="Direct link to API Scanning Adds Support for Scriptable Request Modification" title="Direct link to API Scanning Adds Support for Scriptable Request Modification" translate="no">​</a></h5><p><a href="https://docs.veracode.com/r/Configure_and_Run_an_API_Specification_Scan" target="_blank" rel="noopener noreferrer" class="">Veracode API Scanning adds a new option</a> for using JavaScript to modify an HTTP request, at runtime, when authenticating with a remote host.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="october-5-2022">October 5, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#october-5-2022" class="hash-link" aria-label="Direct link to October 5, 2022" title="Direct link to October 5, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-similarity-threshold-for-web-applications">New Similarity Threshold for Web Applications<a href="https://docs.veracode.com/updates/r/c_all_was#new-similarity-threshold-for-web-applications" class="hash-link" aria-label="Direct link to New Similarity Threshold for Web Applications" title="Direct link to New Similarity Threshold for Web Applications" translate="no">​</a></h5><p><a href="https://docs.veracode.com/r/c_was_conf_url3" target="_blank" rel="noopener noreferrer" class="">When configuring an analysis of a web application</a>, you can now set a threshold for ignoring similar web pages during the analysis.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="september-7-2022">September 7, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#september-7-2022" class="hash-link" aria-label="Direct link to September 7, 2022" title="Direct link to September 7, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="dynamic-analysis-now-creates-screenshots-for-consecutive-login-failures">Dynamic Analysis Now Creates Screenshots for Consecutive Login Failures<a href="https://docs.veracode.com/updates/r/c_all_was#dynamic-analysis-now-creates-screenshots-for-consecutive-login-failures" class="hash-link" aria-label="Direct link to Dynamic Analysis Now Creates Screenshots for Consecutive Login Failures" title="Direct link to Dynamic Analysis Now Creates Screenshots for Consecutive Login Failures" translate="no">​</a></h5><p><a href="https://docs.veracode.com/r/t_was_prescan" target="_blank" rel="noopener noreferrer" class="">The Veracode scan engine now creates a verification screenshot</a> if it is unable to log in to a target application after 50 attempts. The screenshot image shows when and where in the scanning process the failed login attempts occurred. You can use this information for troubleshooting.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="august-2-2022">August 2, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#august-2-2022" class="hash-link" aria-label="Direct link to August 2, 2022" title="Direct link to August 2, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-historical-details-for-dynamic-analyses-and-scans">New Historical Details for Dynamic Analyses and Scans<a href="https://docs.veracode.com/updates/r/c_all_was#new-historical-details-for-dynamic-analyses-and-scans" class="hash-link" aria-label="Direct link to New Historical Details for Dynamic Analyses and Scans" title="Direct link to New Historical Details for Dynamic Analyses and Scans" translate="no">​</a></h5><p><a href="https://docs.veracode.com/r/View_Historical_Details_for_a_Dynamic_Analysis" target="_blank" rel="noopener noreferrer" class="">You can now view detailed information</a> about all past occurrences of both a dynamic analysis and its scans.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="july-28-2022">July 28, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#july-28-2022" class="hash-link" aria-label="Direct link to July 28, 2022" title="Direct link to July 28, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="dynamic-analysis-available-for-european-region-">Dynamic Analysis available for European region <img decoding="async" loading="lazy" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABYAAAAWCAYAAADEtGw7AAAEq0lEQVR4XrVVW09UZxRdZ0B8MY3WGvGG4FyAEZgLDDJch4sCrWklOhYx1isKCjbBtiJVg0IFFDLIbQS5ysVb25f+gT761iZt4oM+tPrgX0D45ttdZ8BorX0x7U5WcrK/fdbee+19zgf8fyYGgg9i0NpqeftkyegPtMZGY8xnMz6Kfxh9wZh/OTMtEAtnMA7RwPc0Zyvfz+tMQFGoESUDD1E8+AuKh/5AYPAZCvqfGgW9jwz/jR/g77yxIvdKLXyXiuC+aEd6/Rq8mdh5ehVSmhxIaT6AlJaf4WiuAnYOK1ROCyrnBBX3lrDrrqBsVhCgr/AOMSbwTQn8g2Lxh+Ytvu4X8HY9gafzd7g6HhPPkdG1AFdIkNYpsDZ9jijp7h/nUXl/EeX3FHbORYyymQiKZyPrdg+pNZXhxZWl4wv7GhsXVxaPR+Bj0uxpMfxMlj3KhLcFWUTmCDH6EmnXBUlfBoFdk6z2gWKVGmVzGqUzGoEZgfcn+aSuSZ/85rAgd1o3XqjRK/JHdMGh89q5py2CzImIkT2ikEV4b0XgGdJwhxWc15aJy8YF5fcVSmdJyuoL7srmz3ol2HBakHdHYgpYmX+CiSiNZ0Y+rW2QvOrzAgcl87JK7y36wwLXgIZrUCH1OxI3kLiE7ZTdVSiZ1iimnnmz8lHFgFQ3nCIhu/Ezcc6YWHJui7GDRBnUOmNcgrUnZH1RlyB9WOAeoK9PI71fIfkqietJXER9SuYUAnd0dFAFk7K6jIE+Vp9D0h2jb2g5IpYss8JbcrDusKwv7BBsD4uR0ceh9WpCwdEqSDhJ4kJmDMwoFE5p5LPlnEnp6PhY0qqY2TMl1DFKCO/w67bdQwLniMRlhsxKTVIm6NHYHlKwXybxcRLnM7hwWpFUv2o7Lpc+19QSYebfCQ2z7dRhSau4IG2XdvK5zyRlom6N1B4F20XBJpM4l9nzpxT8Yxo5bNk7IfGl3bL/VC3JhsXi5bmHcA+aA2KF/dSVSB6UD7K4AU6TlEi5rgmFbRdIfITEOxicO6mopUY2dfSMyYaSLjlQd5SVMJGTQ3P3i8XVt9y2WWGv7DtyWD7MbuN2UI5U7m5yh4ajUyGpeZnYx+w5Ewq+ER1dcrNtN7FtWvL2NknlwTq+RDkc4ShhTHo3qwtJzfEa2Zh7SWDrMUkF9msa9g6FxK8F8YdInHmTEx9V1FJz2lz0sDI8AwrbhyKp5S2RvKqzOtbVo+sb92okh/SxuqBUVJ/QiGey5K6lSk1SW7uGtU0h4RyJD+4DPJxo1vjL6NTNaZs6pvdxhZgwhbrawrLS1R2p+uLoYlzG9YW1viuLa7Naua+dEcNxLQKbiXYF69VFWNvnsaVJsL66BsigPunmANoXkHL5ORwtj2Fv/o14YjiaX1gcLfOwcYW2sF0HNbVyYFazdX5hNsJq+ri7id9yzb4SbKxViN9fDCTzN2c/dwDbzjiwLrjq9U+Vv8XEPaux+YgdiScCK5KO1WJr/Q0j6cz32NrwCAmNT4ln2HLmT2yu+xWbjj3ExkNnsaFm6xsc72UGnE7zQoh9+2DZzKvEvFLeeWOYPmPpSjJjeEVFn99lr2LeyfPf2V8irVVJtnQH8AAAAABJRU5ErkJggg==" width="22" height="22" class="img_ev3q"><a href="https://docs.veracode.com/updates/r/c_all_was#dynamic-analysis-available-for-european-region-" class="hash-link" aria-label="Direct link to dynamic-analysis-available-for-european-region-" title="Direct link to dynamic-analysis-available-for-european-region-" translate="no">​</a></h5><p><a href="https://docs.veracode.com/r/Dynamic_Analysis" target="_blank" rel="noopener noreferrer" class="">Veracode Dynamic Analysis</a> is now available in the European region. If you have a Veracode Dynamic Analysis subscription, you can now perform dynamic analysis security testing and API testing on public-facing web applications and APIs.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="may-18-2022">May 18, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#may-18-2022" class="hash-link" aria-label="Direct link to May 18, 2022" title="Direct link to May 18, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="re-enabled-pause-and-resume-for-scheduled-analyses">Re-Enabled Pause and Resume for Scheduled Analyses<a href="https://docs.veracode.com/updates/r/c_all_was#re-enabled-pause-and-resume-for-scheduled-analyses" class="hash-link" aria-label="Direct link to Re-Enabled Pause and Resume for Scheduled Analyses" title="Direct link to Re-Enabled Pause and Resume for Scheduled Analyses" translate="no">​</a></h5><p><a href="https://docs.veracode.com/r/t_was_recurring" target="_blank" rel="noopener noreferrer" class="">When scheduling a Dynamic Analysis, you can now set it to pause and resume scanning</a> at specific days and times. Veracode disabled this option on October 7, 2021.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="april-28-2022">April 28, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#april-28-2022" class="hash-link" aria-label="Direct link to April 28, 2022" title="Direct link to April 28, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-status-messages-for-partial-scan-results">New Status Messages for Partial Scan Results<a href="https://docs.veracode.com/updates/r/c_all_was#new-status-messages-for-partial-scan-results" class="hash-link" aria-label="Direct link to New Status Messages for Partial Scan Results" title="Direct link to New Status Messages for Partial Scan Results" translate="no">​</a></h5><p><a href="https://docs.veracode.com/r/c_was_statuses" target="_blank" rel="noopener noreferrer" class="">Dynamic Analysis now provides status messages that indicate when Veracode is verifying partial results</a> and when partial results are available for review. Partial results can occur when a scan stops prematurely due to:</p><ul>
<li class="">Errors during scanning</li>
<li class="">Users stopping the scan early</li>
<li class="">The scan exceeding its configured duration</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-23-2022">March 23, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#march-23-2022" class="hash-link" aria-label="Direct link to March 23, 2022" title="Direct link to March 23, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-scanning-adds-support-for-openid-connect-to-oauth-20">API Scanning Adds Support for OpenID Connect to OAuth 2.0<a href="https://docs.veracode.com/updates/r/c_all_was#api-scanning-adds-support-for-openid-connect-to-oauth-20" class="hash-link" aria-label="Direct link to API Scanning Adds Support for OpenID Connect to OAuth 2.0" title="Direct link to API Scanning Adds Support for OpenID Connect to OAuth 2.0" translate="no">​</a></h5><p><a href="https://docs.veracode.com/r/Configure_and_Run_an_API_Specification_Scan" target="_blank" rel="noopener noreferrer" class="">Veracode API Scanning adds a new option to specify an OpenID Connect URL when configuring OAuth 2.0 authentication</a>.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-10-2022">March 10, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#march-10-2022" class="hash-link" aria-label="Direct link to March 10, 2022" title="Direct link to March 10, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="dynamic-analysis-adds-support-for-concurrent-browsers-running-dynamic-analysis-scans">Dynamic Analysis Adds Support for Concurrent Browsers Running Dynamic Analysis Scans<a href="https://docs.veracode.com/updates/r/c_all_was#dynamic-analysis-adds-support-for-concurrent-browsers-running-dynamic-analysis-scans" class="hash-link" aria-label="Direct link to Dynamic Analysis Adds Support for Concurrent Browsers Running Dynamic Analysis Scans" title="Direct link to Dynamic Analysis Adds Support for Concurrent Browsers Running Dynamic Analysis Scans" translate="no">​</a></h5><p><a href="https://docs.veracode.com/r/c_was_conf_url3" target="_blank" rel="noopener noreferrer" class="">Veracode Dynamic Analysis now supports concurrent browsers for running multiple Dynamic Analysis scans at the same time</a>. When configuring a web application scan, you can specify up to 12 concurrent browsers.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-8-2022">March 8, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#march-8-2022" class="hash-link" aria-label="Direct link to March 8, 2022" title="Direct link to March 8, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="api-scanning-adds-oauth-20-authentication-and-analysis-history-options">API Scanning Adds OAuth 2.0 Authentication and Analysis History Options<a href="https://docs.veracode.com/updates/r/c_all_was#api-scanning-adds-oauth-20-authentication-and-analysis-history-options" class="hash-link" aria-label="Direct link to API Scanning Adds OAuth 2.0 Authentication and Analysis History Options" title="Direct link to API Scanning Adds OAuth 2.0 Authentication and Analysis History Options" translate="no">​</a></h5><p><a href="https://docs.veracode.com/r/Configure_and_Run_an_API_Specification_Scan" target="_blank" rel="noopener noreferrer" class="">Veracode API Scanning includes these changes</a>:</p><ul>
<li class="">New option to configure OAuth 2.0 authentication for the API endpoints in your API specifications. You can select to use either the Client Credentials or Password Credentials grant type.</li>
<li class="">New Associated Analysis field on the API Specification Details page for a given API specification. This field provides options for viewing, reconfiguring, and rerunning previous scans.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-3-2022">March 3, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#march-3-2022" class="hash-link" aria-label="Direct link to March 3, 2022" title="Direct link to March 3, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="dynamic-analysis-now-detects-log4j-vulnerability-cwe-115">Dynamic Analysis Now Detects Log4j Vulnerability CWE-115<a href="https://docs.veracode.com/updates/r/c_all_was#dynamic-analysis-now-detects-log4j-vulnerability-cwe-115" class="hash-link" aria-label="Direct link to Dynamic Analysis Now Detects Log4j Vulnerability CWE-115" title="Direct link to Dynamic Analysis Now Detects Log4j Vulnerability CWE-115" translate="no">​</a></h5><p>Veracode Dynamic Analysis can now detect Log4j vulnerability CWE-115 when scanning web applications or API specifications.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="february-4-2022">February 4, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#february-4-2022" class="hash-link" aria-label="Direct link to February 4, 2022" title="Direct link to February 4, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="updated-dynamic-analysis-scan-engine">Updated Dynamic Analysis Scan Engine<a href="https://docs.veracode.com/updates/r/c_all_was#updated-dynamic-analysis-scan-engine" class="hash-link" aria-label="Direct link to Updated Dynamic Analysis Scan Engine" title="Direct link to Updated Dynamic Analysis Scan Engine" translate="no">​</a></h5><p>The Dynamic Analysis scan engine includes these updates:</p><ul>
<li class="">Updated Chromium to version 98.0.4758.80</li>
<li class="">Log4j security updates</li>
<li class="">Improved connectivity when authenticating with Veracode</li>
<li class="">Fix for insecure cookies that prevented flaw matching</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="january-25-2022">January 25, 2022<a href="https://docs.veracode.com/updates/r/c_all_was#january-25-2022" class="hash-link" aria-label="Direct link to January 25, 2022" title="Direct link to January 25, 2022" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-22110">ISM endpoint 22.1.10<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-22110" class="hash-link" aria-label="Direct link to ISM endpoint 22.1.10" title="Direct link to ISM endpoint 22.1.10" translate="no">​</a></h5><ul>
<li class="">The endpoint upgraded to Log4j 2.17.1 to address security findings.</li>
<li class="">Improved thread management for connection stability.</li>
<li class="">Advanced memory usage diagnostics.</li>
</ul></div></div></details>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2021-updates">2021 updates<a href="https://docs.veracode.com/updates/r/c_all_was#2021-updates" class="hash-link" aria-label="Direct link to 2021 updates" title="Direct link to 2021 updates" translate="no">​</a></h3>
<details class="details_lb9f alert alert--info details_b_Ee collapse-component" data-collapsed="true"><summary>2021 updates</summary><div><div class="collapsibleContent_i85q"><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="december-21-2021">December 21, 2021<a href="https://docs.veracode.com/updates/r/c_all_was#december-21-2021" class="hash-link" aria-label="Direct link to December 21, 2021" title="Direct link to December 21, 2021" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-211213">ISM endpoint 21.12.13<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-211213" class="hash-link" aria-label="Direct link to ISM endpoint 21.12.13" title="Direct link to ISM endpoint 21.12.13" translate="no">​</a></h5><ul>
<li class="">The endpoint upgraded to Log4j 2.17 to address known vulnerabilities CVE-2021-44228 and CVE-2021-45046.</li>
<li class="">Additional libraries upgraded to address security findings.</li>
</ul></div></div></details>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="2020-updates">2020 updates<a href="https://docs.veracode.com/updates/r/c_all_was#2020-updates" class="hash-link" aria-label="Direct link to 2020 updates" title="Direct link to 2020 updates" translate="no">​</a></h3>
<details class="details_lb9f alert alert--info details_b_Ee collapse-component" data-collapsed="true"><summary>2020 updates</summary><div><div class="collapsibleContent_i85q"><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="november-24-2020">November 24, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#november-24-2020" class="hash-link" aria-label="Direct link to November 24, 2020" title="Direct link to November 24, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-target-url-search-feature">New Target URL Search Feature<a href="https://docs.veracode.com/updates/r/c_all_was#new-target-url-search-feature" class="hash-link" aria-label="Direct link to New Target URL Search Feature" title="Direct link to New Target URL Search Feature" translate="no">​</a></h5><ul>
<li class="">Veracode Dynamic Analysis now allows you to search for individual URL scans in addition to searching for a specific Dynamic Analysis. This capability enables you to easily identify which scans are associated with a specified URL.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="csp-header-checks">CSP Header Checks<a href="https://docs.veracode.com/updates/r/c_all_was#csp-header-checks" class="hash-link" aria-label="Direct link to CSP Header Checks" title="Direct link to CSP Header Checks" translate="no">​</a></h5><ul>
<li class="">Veracode Dynamic Analysis now checks for missing or misconfigured script execution policies in Content Security Policy (CSP) headers of web applications.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="expanded-secure-cookie-attributes-list">Expanded Secure Cookie Attributes List<a href="https://docs.veracode.com/updates/r/c_all_was#expanded-secure-cookie-attributes-list" class="hash-link" aria-label="Direct link to Expanded Secure Cookie Attributes List" title="Direct link to Expanded Secure Cookie Attributes List" translate="no">​</a></h5><ul>
<li class="">Veracode Dynamic Analysis has expanded its list of known secure cookie attributes, such as SameSite, Secure, and HttpOnly, that are common to cloud infrastructures. Veracode checks web applications for secure cookie attributes on this list before reporting missing attributes as flaws.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="august-10-2020">August 10, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#august-10-2020" class="hash-link" aria-label="Direct link to August 10, 2020" title="Direct link to August 10, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-2085">ISM endpoint 20.8.5<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-2085" class="hash-link" aria-label="Direct link to ISM endpoint 20.8.5" title="Direct link to ISM endpoint 20.8.5" translate="no">​</a></h5><ul>
<li class="">The endpoint now supports not resolving the hostname when accessing the ISM gateway via proxy. This support enables you to only allow the gateway hostname for outbound HTTPS calls.</li>
<li class="">The endpoint now supports not resolving the hostname when accessing scanned URLs via proxy. This support simplifies proxy configuration if you do not want to access external sites, such as Okta, during the scan.</li>
<li class="">Improved interface for configuring a proxy for the endpoint installer.</li>
<li class="">The endpoint installer supports configuring hostname resolution properties.</li>
<li class="">Java WebSocket library for the endpoint upgraded to version 1.5.1.</li>
<li class="">The endpoint supports specifying non-default network interface via endpoint properties, including the option to see a list of available network interfaces.</li>
<li class="">The endpoint process name on Linux includes a Veracode identifier.</li>
<li class="">Improved endpoint logging.</li>
</ul><p>For more information, see the <a href="https://docs.veracode.com/r/c_ism_endpoint_history" target="_blank" rel="noopener noreferrer" class="">endpoint release history</a></p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="july-22-2020">July 22, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#july-22-2020" class="hash-link" aria-label="Direct link to July 22, 2020" title="Direct link to July 22, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-video---configure-dynamic-analysis-login-settings">New Video - Configure Dynamic Analysis Login Settings<a href="https://docs.veracode.com/updates/r/c_all_was#new-video---configure-dynamic-analysis-login-settings" class="hash-link" aria-label="Direct link to New Video - Configure Dynamic Analysis Login Settings" title="Direct link to New Video - Configure Dynamic Analysis Login Settings" translate="no">​</a></h5><ul>
<li class="">This video describes the different types of authentication that Veracode Dynamic Analysis can require to log in to your application and how to configure your Dynamic Analysis so that Veracode can log in.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="june-11-2020">June 11, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#june-11-2020" class="hash-link" aria-label="Direct link to June 11, 2020" title="Direct link to June 11, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="crawl-script-support-for-comprehensive-scans">Crawl Script Support for Comprehensive Scans<a href="https://docs.veracode.com/updates/r/c_all_was#crawl-script-support-for-comprehensive-scans" class="hash-link" aria-label="Direct link to Crawl Script Support for Comprehensive Scans" title="Direct link to Crawl Script Support for Comprehensive Scans" translate="no">​</a></h5><ul>
<li class="">Veracode Dynamic Analysis now supports the use of prerecorded crawl sequences to supplement the default automated crawling capability of the Veracode scan engine. You must use Selenium to record the crawl scripts and save them in SIDE test suite or HTML formats. Dynamic Analysis runs the crawl script during prescan to check for any commands that might fail during the URL scan.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="june-8-2020">June 8, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#june-8-2020" class="hash-link" aria-label="Direct link to June 8, 2020" title="Direct link to June 8, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="improved-dynamic-analysis-coverage">Improved Dynamic Analysis Coverage<a href="https://docs.veracode.com/updates/r/c_all_was#improved-dynamic-analysis-coverage" class="hash-link" aria-label="Direct link to Improved Dynamic Analysis Coverage" title="Direct link to Improved Dynamic Analysis Coverage" translate="no">​</a></h5><p>Veracode has improved the scan engine coverage with:</p><ul>
<li class="">Increased coverage for CWE 89: Improper Neutralization of Special Elements used in an SQL Command (SQL Injection).</li>
<li class="">Increased reporting for SSL issues and updated description and remediation text. The Dynamic Analysis scan engine now reports the use of Cipher Block Chaining (CBC) ciphers, and key exchange algorithms that do not provide perfect forward secrecy (such as RSA with no EDH).</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-screenshot-verifications-and-scan-notes-features">New Screenshot Verifications and Scan Notes Features<a href="https://docs.veracode.com/updates/r/c_all_was#new-screenshot-verifications-and-scan-notes-features" class="hash-link" aria-label="Direct link to New Screenshot Verifications and Scan Notes Features" title="Direct link to New Screenshot Verifications and Scan Notes Features" translate="no">​</a></h5><ul>
<li class="">Veracode Dynamic Analysis now shows additional troubleshooting information on the Prescan Details and Scan Details pages. The new Verification Screenshots section shows screenshots that the Veracode scan engine takes at predetermined points. The Scan Notes section contains observations from the scan engine on issues encountered at runtime or best practices that you can apply to the scan configuration.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="updated-video---initiate-a-dynamic-analysis-prescan">Updated Video - Initiate a Dynamic Analysis Prescan<a href="https://docs.veracode.com/updates/r/c_all_was#updated-video---initiate-a-dynamic-analysis-prescan" class="hash-link" aria-label="Direct link to Updated Video - Initiate a Dynamic Analysis Prescan" title="Direct link to Updated Video - Initiate a Dynamic Analysis Prescan" translate="no">​</a></h5><ul>
<li class="">This video shows you how to submit a Dynamic Analysis for prescan, what the Dynamic Analysis is testing during prescan, and how to tell if your Dynamic Analysis has passed prescan successfully.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="may-26-2020">May 26, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#may-26-2020" class="hash-link" aria-label="Direct link to May 26, 2020" title="Direct link to May 26, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhanced-access-control-for-ism-endpoints">Enhanced Access Control for ISM Endpoints<a href="https://docs.veracode.com/updates/r/c_all_was#enhanced-access-control-for-ism-endpoints" class="hash-link" aria-label="Direct link to Enhanced Access Control for ISM Endpoints" title="Direct link to Enhanced Access Control for ISM Endpoints" translate="no">​</a></h5><ul>
<li class=""><a href="https://docs.veracode.com/r/t_config_ep_access" target="_blank" rel="noopener noreferrer" class="">Veracode Dynamic Analysis Internal Scanning Management</a> (ISM) provides new options for granting Veracode support engineers access to your endpoints. You can now allow support access for a specific number of days, up to 30, or allow access indefinitely until you choose to disable it.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="may-21-2020">May 21, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#may-21-2020" class="hash-link" aria-label="Direct link to May 21, 2020" title="Direct link to May 21, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="client-certificate-authentication-support">Client Certificate Authentication Support<a href="https://docs.veracode.com/updates/r/c_all_was#client-certificate-authentication-support" class="hash-link" aria-label="Direct link to Client Certificate Authentication Support" title="Direct link to Client Certificate Authentication Support" translate="no">​</a></h5><ul>
<li class="">Dynamic Analysis now supports client certificate-based authentication. When you upload your certificate and the associated password, Veracode can log in to websites that require this method of authentication.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="engine-json-web-token-and-obsolete-javascript-support">Engine JSON Web Token and Obsolete JavaScript Support<a href="https://docs.veracode.com/updates/r/c_all_was#engine-json-web-token-and-obsolete-javascript-support" class="hash-link" aria-label="Direct link to Engine JSON Web Token and Obsolete JavaScript Support" title="Direct link to Engine JSON Web Token and Obsolete JavaScript Support" translate="no">​</a></h5><ul>
<li class="">Dynamic Analysis has added security auditing for JSON Web Tokens (JWT) and obsolete JavaScript resources. JWT auditing detects common flaws, including signature vulnerabilities, in sites that use JWT for authentication. Obsolete JavaScript resource detection reports known-vulnerable libraries, such as older versions of jQuery, through signature matching.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="improved-scan-status-details">Improved Scan Status Details<a href="https://docs.veracode.com/updates/r/c_all_was#improved-scan-status-details" class="hash-link" aria-label="Direct link to Improved Scan Status Details" title="Direct link to Improved Scan Status Details" translate="no">​</a></h5><ul>
<li class="">Veracode Dynamic Analysis now has improved end-user visibility into scan statuses. Additional status information is available in the status fields and columns of the All Analyses, Dynamic Analysis Summary, and URL Scan Summary pages. You now have more detailed information when scans stop due to network issues or because they exceeded the allocated scan duration time.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="updated-video---create-login-scripts-with-selenium">Updated Video - Create Login Scripts with Selenium<a href="https://docs.veracode.com/updates/r/c_all_was#updated-video---create-login-scripts-with-selenium" class="hash-link" aria-label="Direct link to Updated Video - Create Login Scripts with Selenium" title="Direct link to Updated Video - Create Login Scripts with Selenium" translate="no">​</a></h5><ul>
<li class="">This video shows you how to use the Selenium IDE plugin to create a login sequence script that enables Veracode Dynamic Analysis to scan URLs that have form-based authentication.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="may-7-2020">May 7, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#may-7-2020" class="hash-link" aria-label="Direct link to May 7, 2020" title="Direct link to May 7, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="prescan-workflow-improvements">Prescan Workflow Improvements<a href="https://docs.veracode.com/updates/r/c_all_was#prescan-workflow-improvements" class="hash-link" aria-label="Direct link to Prescan Workflow Improvements" title="Direct link to Prescan Workflow Improvements" translate="no">​</a></h5><p>Veracode has released several improvements to the Dynamic Analysis workflow to enhance these user experiences:</p><ul>
<li class="">The prescan option has moved to the Schedule page. In addition, you can now use the new prescan-only option if you want to verify your configuration before submitting the analysis.</li>
<li class="">There is a new option on the Schedule page to enable you to save your Dynamic Analysis configuration and continue working on it or submitting it later.</li>
<li class="">Icons have replaced the menu in the individual rows of the URLs table, providing greater ease of use when you want to edit the configuration, link to an application, or delete the URL.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="april-28-2020">April 28, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#april-28-2020" class="hash-link" aria-label="Direct link to April 28, 2020" title="Direct link to April 28, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-notifications-include-endpoint-names">ISM Notifications Include Endpoint Names<a href="https://docs.veracode.com/updates/r/c_all_was#ism-notifications-include-endpoint-names" class="hash-link" aria-label="Direct link to ISM Notifications Include Endpoint Names" title="Direct link to ISM Notifications Include Endpoint Names" translate="no">​</a></h5><ul>
<li class="">Emails from Veracode about your ISM endpoints now specify the endpoint names to help with troubleshooting.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="april-16-2020">April 16, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#april-16-2020" class="hash-link" aria-label="Direct link to April 16, 2020" title="Direct link to April 16, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="scheduling-improvement">Scheduling Improvement<a href="https://docs.veracode.com/updates/r/c_all_was#scheduling-improvement" class="hash-link" aria-label="Direct link to Scheduling Improvement" title="Direct link to Scheduling Improvement" translate="no">​</a></h5><ul>
<li class="">Veracode Dynamic Analysis now provides the ability to select a start date up to 90 days in the future. This enhancement enables you to initiate a one-time scan immediately as well as schedule a recurring, quarterly scan of the same Dynamic Analysis.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="update-to-supported-selenium-commands">Update to Supported Selenium Commands<a href="https://docs.veracode.com/updates/r/c_all_was#update-to-supported-selenium-commands" class="hash-link" aria-label="Direct link to Update to Supported Selenium Commands" title="Direct link to Update to Supported Selenium Commands" translate="no">​</a></h5><ul>
<li class="">Dynamic Analysis now supports these Selenium commands: <code>keyUp</code>, <code>keyDown</code>, <code>keyPress</code>, <code>assertTextPresent</code>, <code>waitForElementVisibile</code>, and <code>clickAt</code>.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-31-2020">March 31, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#march-31-2020" class="hash-link" aria-label="Direct link to March 31, 2020" title="Direct link to March 31, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="dynamic-analysis-user-agent-defaults-to-chrome">Dynamic Analysis User Agent Defaults to Chrome<a href="https://docs.veracode.com/updates/r/c_all_was#dynamic-analysis-user-agent-defaults-to-chrome" class="hash-link" aria-label="Direct link to Dynamic Analysis User Agent Defaults to Chrome" title="Direct link to Dynamic Analysis User Agent Defaults to Chrome" translate="no">​</a></h5><ul>
<li class="">When configuring a Dynamic Analysis, if you do not provide a user agent string for a browser of your choice, the user agent value now defaults to the Chrome browser.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-30-2020">March 30, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#march-30-2020" class="hash-link" aria-label="Direct link to March 30, 2020" title="Direct link to March 30, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="auto-linking-now-available-in-dynamic-analysis">Auto-Linking Now Available in Dynamic Analysis<a href="https://docs.veracode.com/updates/r/c_all_was#auto-linking-now-available-in-dynamic-analysis" class="hash-link" aria-label="Direct link to Auto-Linking Now Available in Dynamic Analysis" title="Direct link to Auto-Linking Now Available in Dynamic Analysis" translate="no">​</a></h5><ul>
<li class="">Veracode Dynamic Analysis now supports application auto-linking automation at the organization account level. Auto-linking links a Dynamic Analysis scan to an existing application profile. Auto-linking can also automatically create a new application profile to which Dynamic Analysis can link future scans, if you select that option. Linking a Dynamic Analysis to an application enables you to review the policy evaluation, download PDF results, and access the Veracode Links Report.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-26-2020">March 26, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#march-26-2020" class="hash-link" aria-label="Direct link to March 26, 2020" title="Direct link to March 26, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="screenshot-provided-for-login-script-errors">Screenshot Provided for Login Script Errors<a href="https://docs.veracode.com/updates/r/c_all_was#screenshot-provided-for-login-script-errors" class="hash-link" aria-label="Direct link to Screenshot Provided for Login Script Errors" title="Direct link to Screenshot Provided for Login Script Errors" translate="no">​</a></h5><ul>
<li class="">Veracode Dynamic Analysis now provides troubleshooting information for login script authentication failures. If you have provided a login script, the Prescan Details window links to a screenshot of the associated login errors.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-17-2020">March 17, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#march-17-2020" class="hash-link" aria-label="Direct link to March 17, 2020" title="Direct link to March 17, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="server-side-request-forgery-ssrf-attack-support">Server-Side Request Forgery (SSRF) Attack Support<a href="https://docs.veracode.com/updates/r/c_all_was#server-side-request-forgery-ssrf-attack-support" class="hash-link" aria-label="Direct link to Server-Side Request Forgery (SSRF) Attack Support" title="Direct link to Server-Side Request Forgery (SSRF) Attack Support" translate="no">​</a></h5><ul>
<li class="">Veracode Dynamic Analysis now enables Server-side Request Forgery (SSRF) attacks to find flaws, by default.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="extended-auto-login-support">Extended Auto-Login Support<a href="https://docs.veracode.com/updates/r/c_all_was#extended-auto-login-support" class="hash-link" aria-label="Direct link to Extended Auto-Login Support" title="Direct link to Extended Auto-Login Support" translate="no">​</a></h5><ul>
<li class="">The Veracode Dynamic Analysis scan engine has improved support for multi-page forms and login pages containing iframes.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-9-2020">March 9, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#march-9-2020" class="hash-link" aria-label="Direct link to March 9, 2020" title="Direct link to March 9, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-updated-with-advanced-diagnostics">ISM Endpoint Updated with Advanced Diagnostics<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-updated-with-advanced-diagnostics" class="hash-link" aria-label="Direct link to ISM Endpoint Updated with Advanced Diagnostics" title="Direct link to ISM Endpoint Updated with Advanced Diagnostics" translate="no">​</a></h5><ul>
<li class=""><a href="https://docs.veracode.com/r/c_ism_endpoint_history" target="_blank" rel="noopener noreferrer" class="">Veracode Dynamic Analysis Internal Scanning Management</a> (ISM) recently released an updated endpoint version with several new features, including advanced diagnostics options. More information is available in the <a href="https://docs.veracode.com/r/c_ism_endpoint_history" target="_blank" rel="noopener noreferrer" class="">endpoint release history</a>.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="auto-login-enhancements">Auto-Login Enhancements<a href="https://docs.veracode.com/updates/r/c_all_was#auto-login-enhancements" class="hash-link" aria-label="Direct link to Auto-Login Enhancements" title="Direct link to Auto-Login Enhancements" translate="no">​</a></h5><ul>
<li class="">Veracode Dynamic Analysis has streamlined authentication configuration with an enhanced auto-login capability. You should use auto-login to provide a username and password for auto-login, browser-generated logins, and NTLMv2. Auto-login is the default setting. A separate, basic authentication section is available to configure authentication for websites that require two forms of authentication: auto-login and browser-generated authentication. Veracode continues to support Selenium-based login scripts with these changes.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="coverage-improvements">Coverage Improvements<a href="https://docs.veracode.com/updates/r/c_all_was#coverage-improvements" class="hash-link" aria-label="Direct link to Coverage Improvements" title="Direct link to Coverage Improvements" translate="no">​</a></h5><ul>
<li class="">The latest release of Veracode Dynamic Analysis includes new generic injection techniques in the scan engine and flaw publishing process. Veracode can now detect additional vulnerabilities for CWEs 95, 89, 91, and 74. In addition, SQL Injection, OS Command Injection, Remote File Inclusion (RFI), Server-side Request Forgery (SSRF), XML External Entity (XXE), and Cross-site Scripting (XSS) detection can now attack JSON keys and values in POST bodies by default.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="february-21-2020">February 21, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#february-21-2020" class="hash-link" aria-label="Direct link to February 21, 2020" title="Direct link to February 21, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-video---view-dynamic-analysis-results">New Video - View Dynamic Analysis Results<a href="https://docs.veracode.com/updates/r/c_all_was#new-video---view-dynamic-analysis-results" class="hash-link" aria-label="Direct link to New Video - View Dynamic Analysis Results" title="Direct link to New Video - View Dynamic Analysis Results" translate="no">​</a></h5><ul>
<li class="">This video shows you how to view Dynamic Analysis results.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="february-14-2020">February 14, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#february-14-2020" class="hash-link" aria-label="Direct link to February 14, 2020" title="Direct link to February 14, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-video---create-and-run-an-unauthenticated-dynamic-analysis">New Video - Create and Run an Unauthenticated Dynamic Analysis<a href="https://docs.veracode.com/updates/r/c_all_was#new-video---create-and-run-an-unauthenticated-dynamic-analysis" class="hash-link" aria-label="Direct link to New Video - Create and Run an Unauthenticated Dynamic Analysis" title="Direct link to New Video - Create and Run an Unauthenticated Dynamic Analysis" translate="no">​</a></h5><ul>
<li class="">This video shows you how to create, configure, and schedule an unauthenticated Dynamic Analysis.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="row-selection-persistence">Row Selection Persistence<a href="https://docs.veracode.com/updates/r/c_all_was#row-selection-persistence" class="hash-link" aria-label="Direct link to Row Selection Persistence" title="Direct link to Row Selection Persistence" translate="no">​</a></h5><ul>
<li class="">When you select the number of rows you want to display in the All Dynamic Analyses table, the selection persists even if you navigate away from that table. Your selection persists until you log out.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="january-8-2020">January 8, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#january-8-2020" class="hash-link" aria-label="Direct link to January 8, 2020" title="Direct link to January 8, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-auto-publish-feature">New Auto-Publish Feature<a href="https://docs.veracode.com/updates/r/c_all_was#new-auto-publish-feature" class="hash-link" aria-label="Direct link to New Auto-Publish Feature" title="Direct link to New Auto-Publish Feature" translate="no">​</a></h5><p>Auto-Publish is now enabled in Veracode Dynamic Analysis to automatically publish some findings, providing quicker results for specific types of vulnerabilities.</p><ul>
<li class="">If every vulnerability found in all URL scans in a Dynamic Analysis meets the criteria for auto-publication, Veracode publishes the findings immediately after the analysis completes.</li>
<li class="">If one or more vulnerabilities require a review by a Veracode scan engineer, then any findings eligible for auto-publication must wait for that review. Veracode publishes all findings together within 24 hours of when the manual review is complete.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="change-to-failed-verification-status">Change to Failed Verification Status<a href="https://docs.veracode.com/updates/r/c_all_was#change-to-failed-verification-status" class="hash-link" aria-label="Direct link to Change to Failed Verification Status" title="Direct link to Change to Failed Verification Status" translate="no">​</a></h5><p>Veracode Dynamic Analysis has updated the status definition that displays when any URL scans fail verification for either a connection or authentication issue.</p><ul>
<li class="">When a single URL scan in an analysis fails verification:<!-- -->
<ul>
<li class="">The URL scan status is Verification Failed.</li>
<li class="">The Dynamic Analysis status is All Verifications Failed.</li>
</ul>
</li>
<li class="">When an analysis with multiple URL scans has one or more of the URL scans fail verification:<!-- -->
<ul>
<li class="">The failed URL scan status is Verification Failed.</li>
<li class="">The analysis status is Completed - Partial Results Available.</li>
</ul>
</li>
</ul><h1>Application Security Platform</h1><p>View the list below for highlights of previous releases.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="december-7-2020">December 7, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#december-7-2020" class="hash-link" aria-label="Direct link to December 7, 2020" title="Direct link to December 7, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="additional-sca-details-available-from-the-findings-rest-api">Additional SCA Details Available from the Findings REST API<a href="https://docs.veracode.com/updates/r/c_all_was#additional-sca-details-available-from-the-findings-rest-api" class="hash-link" aria-label="Direct link to Additional SCA Details Available from the Findings REST API" title="Direct link to Additional SCA Details Available from the Findings REST API" translate="no">​</a></h5><ul>
<li class="">With the Veracode Findings REST API, you can identify whether Software Composition Analysis findings are from agent-based scans or upload scans and whether they are from a direct or transitive dependency. You can also filter your findings by scan type or dependency type.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="november-23-2020">November 23, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#november-23-2020" class="hash-link" aria-label="Direct link to November 23, 2020" title="Direct link to November 23, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="updates-to-the-findings-rest-api">Updates to the Findings REST API<a href="https://docs.veracode.com/updates/r/c_all_was#updates-to-the-findings-rest-api" class="hash-link" aria-label="Direct link to Updates to the Findings REST API" title="Direct link to Updates to the Findings REST API" translate="no">​</a></h5><p>You can now perform these tasks with the Veracode Findings REST API:</p><ul>
<li class="">Retrieve the expiration date of the remediation grace period for findings that violate a security policy.</li>
<li class="">Retrieve findings with comments or mitigations added after a specific date, such as the date of your most recent scan.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="healthcheck-rest-api">Healthcheck REST API<a href="https://docs.veracode.com/updates/r/c_all_was#healthcheck-rest-api" class="hash-link" aria-label="Direct link to Healthcheck REST API" title="Direct link to Healthcheck REST API" translate="no">​</a></h5><ul>
<li class="">You can use the Veracode Healthcheck REST API to test the availability of Veracode core services.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="october-29-2020">October 29, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#october-29-2020" class="hash-link" aria-label="Direct link to October 29, 2020" title="Direct link to October 29, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="changes-to-owasp-mobile-policy-rules">Changes to OWASP Mobile Policy Rules<a href="https://docs.veracode.com/updates/r/c_all_was#changes-to-owasp-mobile-policy-rules" class="hash-link" aria-label="Direct link to Changes to OWASP Mobile Policy Rules" title="Direct link to Changes to OWASP Mobile Policy Rules" translate="no">​</a></h5><ul>
<li class="">
<p>Veracode has updated policy rules that include the OWASP Mobile security standard to reflect additional research. OWASP Mobile policy rules now include these CWEs: CWE-77, 78, 80, 252, 287, 319, 345, 404, 415, 416, 601, 614, 676, 693, 757.</p>
</li>
<li class="">
<p>Applications that contain these flaws may fail OWASP Mobile policy rules as a result of this update. Veracode will apply the update upon rescan of the application.</p>
</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="improved-notifications-for-delayed-scan-results">Improved Notifications for Delayed Scan Results<a href="https://docs.veracode.com/updates/r/c_all_was#improved-notifications-for-delayed-scan-results" class="hash-link" aria-label="Direct link to Improved Notifications for Delayed Scan Results" title="Direct link to Improved Notifications for Delayed Scan Results" translate="no">​</a></h5><ul>
<li class="">Veracode has improved communication about delayed scan results. You now receive email notifications that include additional details and links for the affected scan. Veracode has also improved the Veracode Platform to indicate delayed scans that are under investigation.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="october-19-2020">October 19, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#october-19-2020" class="hash-link" aria-label="Direct link to October 19, 2020" title="Direct link to October 19, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="applications-rest-api">Applications REST API<a href="https://docs.veracode.com/updates/r/c_all_was#applications-rest-api" class="hash-link" aria-label="Direct link to Applications REST API" title="Direct link to Applications REST API" translate="no">​</a></h5><ul>
<li class="">You can now view application data and create, update, and delete applications using the Veracode Applications REST API.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="september-30-2020">September 30, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#september-30-2020" class="hash-link" aria-label="Direct link to September 30, 2020" title="Direct link to September 30, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="updates-to-required-veracode-domains">Updates to Required Veracode Domains<a href="https://docs.veracode.com/updates/r/c_all_was#updates-to-required-veracode-domains" class="hash-link" aria-label="Direct link to Updates to Required Veracode Domains" title="Direct link to Updates to Required Veracode Domains" translate="no">​</a></h5><ul>
<li class=""><a href="https://docs.veracode.com/r/IP_addresses" target="_blank" rel="noopener noreferrer" class="">Veracode has introduced two URLs to which you must allow access</a>. If you restrict access to public internet sites for your organization, add app.pendo.io and analytics2.veracode.com to your allowlist.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="september-26-2020">September 26, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#september-26-2020" class="hash-link" aria-label="Direct link to September 26, 2020" title="Direct link to September 26, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="rolling-sandbox-histories">Rolling Sandbox Histories<a href="https://docs.veracode.com/updates/r/c_all_was#rolling-sandbox-histories" class="hash-link" aria-label="Direct link to Rolling Sandbox Histories" title="Direct link to Rolling Sandbox Histories" translate="no">​</a></h5><ul>
<li class="">
<p>Rolling sandbox histories let you limit sandbox data by restricting the number of retained scans for each sandbox to 15. After more than 15 scans, the Veracode Platform deletes the oldest scan, though the data remains available through Veracode Analytics. If enabled, this feature replaces the previous data limitation method of expiring old sandboxes.</p>
</li>
<li class="">
<p>To request access to rolling sandbox histories, contact Veracode Technical Support.</p>
</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="updates-to-some-xml-api-deletion-calls">Updates to Some XML API Deletion Calls<a href="https://docs.veracode.com/updates/r/c_all_was#updates-to-some-xml-api-deletion-calls" class="hash-link" aria-label="Direct link to Updates to Some XML API Deletion Calls" title="Direct link to Updates to Some XML API Deletion Calls" translate="no">​</a></h5><ul>
<li class="">To improve performance, the <code>deleteuser.do</code>, <code>deleteteam.do</code>, <code>deleteapp.do</code>, and <code>removefiles.do</code> XML API calls now return an HTTP 200 response and a change summary, instead of a list of the items remaining after the deletion.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="shareable-links-to-your-analytics-dashboards">Shareable Links to Your Analytics Dashboards<a href="https://docs.veracode.com/updates/r/c_all_was#shareable-links-to-your-analytics-dashboards" class="hash-link" aria-label="Direct link to Shareable Links to Your Analytics Dashboards" title="Direct link to Shareable Links to Your Analytics Dashboards" translate="no">​</a></h5><ul>
<li class="">You can now share links to Veracode Analytics dashboards, including Veracode dashboards and dashboards that your organization creates. To access a dashboard link, you must log in to the Veracode Platform and have permission to view the data in the dashboard.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="activity-log-updates">Activity Log Updates<a href="https://docs.veracode.com/updates/r/c_all_was#activity-log-updates" class="hash-link" aria-label="Direct link to Activity Log Updates" title="Direct link to Activity Log Updates" translate="no">​</a></h5><ul>
<li class="">You can now download a report of the full history of application profile activity, scan activity, and sandbox activity. The activity log in the Veracode Platform now displays activity data for the past 90 days.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="technique-removed-from-tsrv-format-for-accepting-risk">Technique Removed from TSRV Format for Accepting Risk<a href="https://docs.veracode.com/updates/r/c_all_was#technique-removed-from-tsrv-format-for-accepting-risk" class="hash-link" aria-label="Direct link to Technique Removed from TSRV Format for Accepting Risk" title="Direct link to Technique Removed from TSRV Format for Accepting Risk" translate="no">​</a></h5><ul>
<li class="">Veracode has removed Technique from the TSRV standard when you perform the Accept the Risk mitigation action because none of the techniques are relevant to accepting risk. Specifics, Remaining Risk, and Verification are still required fields.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="updates-to-cwe-top-25-policy-rules">Updates to CWE Top 25 Policy Rules<a href="https://docs.veracode.com/updates/r/c_all_was#updates-to-cwe-top-25-policy-rules" class="hash-link" aria-label="Direct link to Updates to CWE Top 25 Policy Rules" title="Direct link to Updates to CWE Top 25 Policy Rules" translate="no">​</a></h5><ul>
<li class="">The Latest CWE Top 25 policy rule in the Veracode Platform now reflects the 2020 CWE Top 25 standard. Veracode has also updated the 2019 CWE Top 25 policy rule to disallow the children of CWE-94: CWE-91, 95, 98, 185, and 830.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="september-17-2020">September 17, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#september-17-2020" class="hash-link" aria-label="Direct link to September 17, 2020" title="Direct link to September 17, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="improved-business-units-tab">Improved Business Units Tab<a href="https://docs.veracode.com/updates/r/c_all_was#improved-business-units-tab" class="hash-link" aria-label="Direct link to Improved Business Units Tab" title="Direct link to Improved Business Units Tab" translate="no">​</a></h5><ul>
<li class="">On the Administration page in the Veracode Platform, Veracode has improved the usability of the <strong>Business Units</strong> tab.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="september-10-2020">September 10, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#september-10-2020" class="hash-link" aria-label="Direct link to September 10, 2020" title="Direct link to September 10, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-video---create-and-manage-api-users-in-the-veracode-platform">New Video - Create and Manage API Users in the Veracode Platform<a href="https://docs.veracode.com/updates/r/c_all_was#new-video---create-and-manage-api-users-in-the-veracode-platform" class="hash-link" aria-label="Direct link to New Video - Create and Manage API Users in the Veracode Platform" title="Direct link to New Video - Create and Manage API Users in the Veracode Platform" translate="no">​</a></h5><ul>
<li class=""><a href="https://docs.veracode.com/r/c_video_create_and_manage_api_users" target="_blank" rel="noopener noreferrer" class="">This video shows you how to configure an API service account in the Veracode Platform</a>.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="august-29-2020">August 29, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#august-29-2020" class="hash-link" aria-label="Direct link to August 29, 2020" title="Direct link to August 29, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="all-applications-page-now-available-to-mitigation-approver-and-delete-scans-roles">All Applications Page Now Available to Mitigation Approver and Delete Scans Roles<a href="https://docs.veracode.com/updates/r/c_all_was#all-applications-page-now-available-to-mitigation-approver-and-delete-scans-roles" class="hash-link" aria-label="Direct link to All Applications Page Now Available to Mitigation Approver and Delete Scans Roles" title="Direct link to All Applications Page Now Available to Mitigation Approver and Delete Scans Roles" translate="no">​</a></h5><ul>
<li class="">You can now access the All Applications page in the Veracode Platform with the Mitigation Approver or Delete Scans roles. From the All Applications page, you can, then, select an application to approve mitigations or delete scans.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="cwe-74-now-disallowed-for-the-owasp-security-standard">CWE-74 Now Disallowed for the OWASP Security Standard<a href="https://docs.veracode.com/updates/r/c_all_was#cwe-74-now-disallowed-for-the-owasp-security-standard" class="hash-link" aria-label="Direct link to CWE-74 Now Disallowed for the OWASP Security Standard" title="Direct link to CWE-74 Now Disallowed for the OWASP Security Standard" translate="no">​</a></h5><ul>
<li class="">Veracode has reclassified CWE-74 "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')" as a high severity finding. CWE-74, which Veracode discovers during Dynamic Analysis, is now included on the disallowed CWE IDs list in the latest version of the OWASP security standard. If your organization is using the OWASP 2017 security standard, you may see more findings violating policy or see your application fail policy as a result of this change.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="support-for-mitre-cwe-list-version-41">Support for MITRE CWE List Version 4.1<a href="https://docs.veracode.com/updates/r/c_all_was#support-for-mitre-cwe-list-version-41" class="hash-link" aria-label="Direct link to Support for MITRE CWE List Version 4.1" title="Direct link to Support for MITRE CWE List Version 4.1" translate="no">​</a></h5><ul>
<li class="">
<p>Veracode now provides reporting based on CWE version 4.1 definitions, which changes the names and descriptions of a few existing CWE categories. The complete list of changes in CWE version 4.1 is available from the MITRE website. This new version does not impact the CWE mappings for the OWASP, CWE Top 25, or CERT security standards.</p>
</li>
<li class="">
<p>MITRE is updating their CWE list on a more frequent basis, but Veracode remains committed to staying up-to-date with each new version. As MITRE updates their CWE database, you might notice periodic changes in Veracode reports, such as differences between parent-child relationships or mappings.</p>
</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="august-21-2020">August 21, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#august-21-2020" class="hash-link" aria-label="Direct link to August 21, 2020" title="Direct link to August 21, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="findings-api-version-2">Findings API Version 2<a href="https://docs.veracode.com/updates/r/c_all_was#findings-api-version-2" class="hash-link" aria-label="Direct link to Findings API Version 2" title="Direct link to Findings API Version 2" translate="no">​</a></h5><ul>
<li class="">The Veracode Findings REST API v2 is now available. With this API, you can access information about open and mitigated findings associated with applications and sandboxes. It supports Static Analysis, Dynamic Analysis, Manual Penetration Testing, and Software Composition Analysis scans.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="july-28-2020">July 28, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#july-28-2020" class="hash-link" aria-label="Direct link to July 28, 2020" title="Direct link to July 28, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="improved-user-activity-report">Improved User Activity Report<a href="https://docs.veracode.com/updates/r/c_all_was#improved-user-activity-report" class="hash-link" aria-label="Direct link to Improved User Activity Report" title="Direct link to Improved User Activity Report" translate="no">​</a></h5><ul>
<li class="">An improved user activity report is now available to download as a CSV file, providing easier access to information about user actions.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="july-7-2020">July 7, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#july-7-2020" class="hash-link" aria-label="Direct link to July 7, 2020" title="Direct link to July 7, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="administrators-can-turn-off-optional-notifications-for-their-entire-organization">Administrators Can Turn Off Optional Notifications for Their Entire Organization<a href="https://docs.veracode.com/updates/r/c_all_was#administrators-can-turn-off-optional-notifications-for-their-entire-organization" class="hash-link" aria-label="Direct link to Administrators Can Turn Off Optional Notifications for Their Entire Organization" title="Direct link to Administrators Can Turn Off Optional Notifications for Their Entire Organization" translate="no">​</a></h5><ul>
<li class="">Administrators in the Veracode Platform can now turn off all optional notifications for all new and existing users in their organization account. Individual users have the option to turn the notifications back on for their own user account.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="june-29-2020">June 29, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#june-29-2020" class="hash-link" aria-label="Direct link to June 29, 2020" title="Direct link to June 29, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-accept-the-risk-mitigation-type">New Accept the Risk Mitigation Type<a href="https://docs.veracode.com/updates/r/c_all_was#new-accept-the-risk-mitigation-type" class="hash-link" aria-label="Direct link to New Accept the Risk Mitigation Type" title="Direct link to New Accept the Risk Mitigation Type" translate="no">​</a></h5><ul>
<li class="">Veracode now allows you to resolve a finding by stating that your business is willing to accept the risk associated with that finding. This mitigation type allows you to track and report the risk while continuing to maintain the mitigation and resolution approval process. Veracode updated the mitigationinfo.xsd file to include this mitigation type.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="june-27-2020">June 27, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#june-27-2020" class="hash-link" aria-label="Direct link to June 27, 2020" title="Direct link to June 27, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="veracode-policies-now-support-2019-cwe-top-25-security-standard">Veracode Policies Now Support 2019 CWE Top 25 Security Standard<a href="https://docs.veracode.com/updates/r/c_all_was#veracode-policies-now-support-2019-cwe-top-25-security-standard" class="hash-link" aria-label="Direct link to Veracode Policies Now Support 2019 CWE Top 25 Security Standard" title="Direct link to Veracode Policies Now Support 2019 CWE Top 25 Security Standard" translate="no">​</a></h5><ul>
<li class="">Veracode updated the PCI security standard in the Veracode Platform to include the 2019 CWE Top 25 Security Standard, previously called the SANS Top 25 standard. Applications with findings included in the new standard may fail the PCI policy or PCI standard requirement as a result. Veracode applies the update to applications upon rescan.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="june-16-2020">June 16, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#june-16-2020" class="hash-link" aria-label="Direct link to June 16, 2020" title="Direct link to June 16, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="veracode-analytics-provides-ignored-issue-sca-data">Veracode Analytics Provides Ignored Issue SCA Data<a href="https://docs.veracode.com/updates/r/c_all_was#veracode-analytics-provides-ignored-issue-sca-data" class="hash-link" aria-label="Direct link to Veracode Analytics Provides Ignored Issue SCA Data" title="Direct link to Veracode Analytics Provides Ignored Issue SCA Data" translate="no">​</a></h5><ul>
<li class="">Veracode Analytics now supports SCA agent-based scan issue data about ignored issues, including details of when a user ignored an issue and the username for the user who ignored the issue.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="june-11-2020-1">June 11, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#june-11-2020-1" class="hash-link" aria-label="Direct link to June 11, 2020" title="Direct link to June 11, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-sandbox-attributes-added-to-veracode-analytics">New Sandbox Attributes Added to Veracode Analytics<a href="https://docs.veracode.com/updates/r/c_all_was#new-sandbox-attributes-added-to-veracode-analytics" class="hash-link" aria-label="Direct link to New Sandbox Attributes Added to Veracode Analytics" title="Direct link to New Sandbox Attributes Added to Veracode Analytics" translate="no">​</a></h5><ul>
<li class="">Veracode Analytics now provides attributes for tracking sandbox usage. You can view sandbox expiration dates and determine if the Veracode Platform sandboxes are configured for Veracode to automatically recreate them after expiration.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-dynamic-analysis-dimensions-available-in-veracode-analytics">New Dynamic Analysis Dimensions Available in Veracode Analytics<a href="https://docs.veracode.com/updates/r/c_all_was#new-dynamic-analysis-dimensions-available-in-veracode-analytics" class="hash-link" aria-label="Direct link to New Dynamic Analysis Dimensions Available in Veracode Analytics" title="Direct link to New Dynamic Analysis Dimensions Available in Veracode Analytics" translate="no">​</a></h5><ul>
<li class="">Veracode Analytics now provides the Dynamic Analysis fields Path and Vulnerable Parameter, which allow you to better focus and prioritize your remediation efforts.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="june-8-2020-1">June 8, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#june-8-2020-1" class="hash-link" aria-label="Direct link to June 8, 2020" title="Direct link to June 8, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="sca-agent-data-available-in-veracode-analytics">SCA Agent Data Available in Veracode Analytics<a href="https://docs.veracode.com/updates/r/c_all_was#sca-agent-data-available-in-veracode-analytics" class="hash-link" aria-label="Direct link to SCA Agent Data Available in Veracode Analytics" title="Direct link to SCA Agent Data Available in Veracode Analytics" translate="no">​</a></h5><ul>
<li class="">The Software Composition Analysis (SCA) dashboard is updated in Veracode Analytics to reflect recommended charts for tracking your use of SCA agent-based and upload-and-scan workflows. In addition, Veracode Analytics provides two new explores for SCA agent data: SCA Agent Issues and SCA Agent Scans. These explores enable you to create your own charts and dashboards, providing a better understanding of your open-source risk.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="may-28-2020">May 28, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#may-28-2020" class="hash-link" aria-label="Direct link to May 28, 2020" title="Direct link to May 28, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="update-to-industry-values-in-application-profile">Update to Industry Values in Application Profile<a href="https://docs.veracode.com/updates/r/c_all_was#update-to-industry-values-in-application-profile" class="hash-link" aria-label="Direct link to Update to Industry Values in Application Profile" title="Direct link to Update to Industry Values in Application Profile" translate="no">​</a></h5><ul>
<li class="">
<p>Veracode has updated the values for industries in application profiles to more accurately reflect the market. Because applications include industry values to help inform the Veracode State of Software Security report, this change affects the createapp.do and updateapp.do XML API calls.</p>
</li>
<li class="">
<p>If you have a script coded with an expected value for the <code>industry</code> field, please update your script to reflect the updated values or use the default value already provided.</p>
</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="may-13-2020">May 13, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#may-13-2020" class="hash-link" aria-label="Direct link to May 13, 2020" title="Direct link to May 13, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="analytics-scan-frequency-requirements-data">Analytics Scan Frequency Requirements Data<a href="https://docs.veracode.com/updates/r/c_all_was#analytics-scan-frequency-requirements-data" class="hash-link" aria-label="Direct link to Analytics Scan Frequency Requirements Data" title="Direct link to Analytics Scan Frequency Requirements Data" translate="no">​</a></h5><ul>
<li class="">Veracode Analytics now provides visibility into scan frequency requirements for an application. These requirements include the frequency mandated by the policy, upcoming scan due dates, and any past due dates.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="may-7-2020-1">May 7, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#may-7-2020-1" class="hash-link" aria-label="Direct link to May 7, 2020" title="Direct link to May 7, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-team-admin-role">New Team Admin Role<a href="https://docs.veracode.com/updates/r/c_all_was#new-team-admin-role" class="hash-link" aria-label="Direct link to New Team Admin Role" title="Direct link to New Team Admin Role" translate="no">​</a></h5><ul>
<li class="">Veracode has added the new Team Admin user role that an administrator can grant to users. With the Team Admin role, you can create, edit, and delete users within the teams you manage. This new role makes it easier for organizations to manage permissions for a large number of users.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-mitigation-type">New Mitigation Type<a href="https://docs.veracode.com/updates/r/c_all_was#new-mitigation-type" class="hash-link" aria-label="Direct link to New Mitigation Type" title="Direct link to New Mitigation Type" translate="no">​</a></h5><ul>
<li class="">Veracode has added a new mitigation type to allow you to propose mitigations using the mitigation type <strong>Mitigated - Referred to Library Maintainer</strong>. You can classify findings related to libraries developed by another development team. Another development team may build libraries in-house, but they may not own the application Veracode is scanning.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="april-30-2020">April 30, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#april-30-2020" class="hash-link" aria-label="Direct link to April 30, 2020" title="Direct link to April 30, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-identity-rest-apis">New Identity REST APIs<a href="https://docs.veracode.com/updates/r/c_all_was#new-identity-rest-apis" class="hash-link" aria-label="Direct link to New Identity REST APIs" title="Direct link to New Identity REST APIs" translate="no">​</a></h5><ul>
<li class="">The new Identity REST APIs allow you to manage users, teams, and business units. You can also use these REST APIs to create API service accounts and manage API ID/key credentials.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="updated-greenlight-scans-explore-page">Updated Greenlight Scans Explore Page<a href="https://docs.veracode.com/updates/r/c_all_was#updated-greenlight-scans-explore-page" class="hash-link" aria-label="Direct link to Updated Greenlight Scans Explore Page" title="Direct link to Updated Greenlight Scans Explore Page" translate="no">​</a></h5><ul>
<li class="">Veracode has updated the Analytics page Greenlight Scans Explore to reflect the new terminology of IDE scan (formerly known as Greenlight) and to include pipeline scan data.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="updated-applications-list-view">Updated Applications List View<a href="https://docs.veracode.com/updates/r/c_all_was#updated-applications-list-view" class="hash-link" aria-label="Direct link to Updated Applications List View" title="Direct link to Updated Applications List View" translate="no">​</a></h5><ul>
<li class="">The All Applications page in the Veracode Platform now provides customizable columns and improved searching and filtering. Veracode is gradually releasing this feature as part of each Platform release, so it may not be immediately available to you.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-secure-coding-foundation-elearning-courses">New Secure Coding Foundation eLearning Courses<a href="https://docs.veracode.com/updates/r/c_all_was#new-secure-coding-foundation-elearning-courses" class="hash-link" aria-label="Direct link to New Secure Coding Foundation eLearning Courses" title="Direct link to New Secure Coding Foundation eLearning Courses" translate="no">​</a></h5><p>Veracode eLearning has released a new set of secure coding foundation courses:</p><ul>
<li class=""><em>Secure Coding Foundations - Authentication</em></li>
<li class=""><em>Secure Coding Foundations - Authorization</em></li>
<li class=""><em>Secure Coding Foundations - Configuration and Deployment</em></li>
<li class=""><em>Secure Coding Foundations - Data Protection</em></li>
<li class=""><em>Secure Coding Foundations - Information and Error Handling</em></li>
<li class=""><em>Secure Coding Foundations - Trust Boundaries</em></li>
<li class=""><em>Secure Coding Foundations - Validation and Encoding</em></li>
</ul><p>These courses cover application security practices and associated vulnerabilities.</p><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="elearning-user-interface-enhancements">eLearning User Interface Enhancements<a href="https://docs.veracode.com/updates/r/c_all_was#elearning-user-interface-enhancements" class="hash-link" aria-label="Direct link to eLearning User Interface Enhancements" title="Direct link to eLearning User Interface Enhancements" translate="no">​</a></h5><p>Veracode has improved these eLearning windows:</p><ul>
<li class="">Manager window you use to assign learners to a manager</li>
<li class="">Curriculum window you use to assign learners to a curriculum</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="april-21-2020">April 21, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#april-21-2020" class="hash-link" aria-label="Direct link to April 21, 2020" title="Direct link to April 21, 2020" translate="no">​</a></h4><p>Updated Applications List View</p><ul>
<li class="">The All Applications page in the Veracode Platform now provides customizable columns and improved searching and filtering.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-28-2020">March 28, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#march-28-2020" class="hash-link" aria-label="Direct link to March 28, 2020" title="Direct link to March 28, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="cwe-40-support">CWE 4.0 Support<a href="https://docs.veracode.com/updates/r/c_all_was#cwe-40-support" class="hash-link" aria-label="Direct link to CWE 4.0 Support" title="Direct link to CWE 4.0 Support" translate="no">​</a></h5><ul>
<li class="">Veracode CWE support is updated to reflect the latest changes from MITRE in the CWE 4.0 release.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="enable-automatic-re-creation-of-existing-sandboxes">Enable Automatic Re-creation of Existing Sandboxes<a href="https://docs.veracode.com/updates/r/c_all_was#enable-automatic-re-creation-of-existing-sandboxes" class="hash-link" aria-label="Direct link to Enable Automatic Re-creation of Existing Sandboxes" title="Direct link to Enable Automatic Re-creation of Existing Sandboxes" translate="no">​</a></h5><ul>
<li class="">You can now edit existing sandboxes to enable the setting for automatically re-creating the sandbox when it expires.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="due-date-notifications-for-elearning-students">Due Date Notifications for eLearning Students<a href="https://docs.veracode.com/updates/r/c_all_was#due-date-notifications-for-elearning-students" class="hash-link" aria-label="Direct link to Due Date Notifications for eLearning Students" title="Direct link to Due Date Notifications for eLearning Students" translate="no">​</a></h5><ul>
<li class="">eLearning administrators can now specify when to send email reminders to notify students about the due dates for assigned courses.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-python-and-javascript-elearning-courses">New Python and JavaScript eLearning Courses<a href="https://docs.veracode.com/updates/r/c_all_was#new-python-and-javascript-elearning-courses" class="hash-link" aria-label="Direct link to New Python and JavaScript eLearning Courses" title="Direct link to New Python and JavaScript eLearning Courses" translate="no">​</a></h5><ul>
<li class="">Veracode has added secure coding courses for Python and JavaScript to eLearning learner levels.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-19-2020">March 19, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#march-19-2020" class="hash-link" aria-label="Direct link to March 19, 2020" title="Direct link to March 19, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-grace-period-expiration-date-in-analytics">New Grace Period Expiration Date in Analytics<a href="https://docs.veracode.com/updates/r/c_all_was#new-grace-period-expiration-date-in-analytics" class="hash-link" aria-label="Direct link to New Grace Period Expiration Date in Analytics" title="Direct link to New Grace Period Expiration Date in Analytics" translate="no">​</a></h5><ul>
<li class="">Veracode Analytics now provides the date when a grace period expires. An expired grace period causes the finding to fail the policy associated with the application. Veracode calculates the date based on the First Found or Last Reopened date, whichever is more recent.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="account-lock-does-not-trigger-email-to-administrator">Account Lock Does Not Trigger Email to Administrator<a href="https://docs.veracode.com/updates/r/c_all_was#account-lock-does-not-trigger-email-to-administrator" class="hash-link" aria-label="Direct link to Account Lock Does Not Trigger Email to Administrator" title="Direct link to Account Lock Does Not Trigger Email to Administrator" translate="no">​</a></h5><ul>
<li class="">To prevent redundant notifications, Veracode no longer sends an email to Administrators in the Veracode Platform when users in their organization are locked out of their accounts. This email is now unnecessary because users can unlock their own accounts.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-3-2020">March 3, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#march-3-2020" class="hash-link" aria-label="Direct link to March 3, 2020" title="Direct link to March 3, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="improved-developer-sandbox-scanning-and-added-expiration-date">Improved Developer Sandbox Scanning and Added Expiration Date<a href="https://docs.veracode.com/updates/r/c_all_was#improved-developer-sandbox-scanning-and-added-expiration-date" class="hash-link" aria-label="Direct link to Improved Developer Sandbox Scanning and Added Expiration Date" title="Direct link to Improved Developer Sandbox Scanning and Added Expiration Date" translate="no">​</a></h5><p>Veracode has made these improvements to developer sandboxes:</p><ul>
<li class="">You can now perform up to ten sandbox scans simultaneously for a single application. Before starting additional scans, you must wait for at least one running scan to complete.</li>
<li class="">The sandbox list in the application profile now shows all sandboxes in the application that have running scans.</li>
<li class="">All sandboxes now have an expiration date. After a sandbox reaches its expiration date, you can no longer perform scans in it. Seven days after the expiration date, the Veracode Platform automatically removes the sandbox. All data about the removed sandbox is available from Veracode Analytics. You can use the re-create option to have the Veracode Platform automatically create a new sandbox with the same name as a previously-removed sandbox.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="applications-rest-api-adds-policy-compliance-information">Applications REST API Adds Policy Compliance Information<a href="https://docs.veracode.com/updates/r/c_all_was#applications-rest-api-adds-policy-compliance-information" class="hash-link" aria-label="Direct link to Applications REST API Adds Policy Compliance Information" title="Direct link to Applications REST API Adds Policy Compliance Information" translate="no">​</a></h5><ul>
<li class="">Veracode has improved the Applications REST API to include information about the policy compliance of the application.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="executive-summary-in-customizable-report-pdf-includes-informational-findings">Executive Summary in Customizable Report PDF Includes Informational Findings<a href="https://docs.veracode.com/updates/r/c_all_was#executive-summary-in-customizable-report-pdf-includes-informational-findings" class="hash-link" aria-label="Direct link to Executive Summary in Customizable Report PDF Includes Informational Findings" title="Direct link to Executive Summary in Customizable Report PDF Includes Informational Findings" translate="no">​</a></h5><ul>
<li class="">The executive summary in the downloadable PDF of the Customizable Report now shows informational findings. The informational findings provide information that can help you ensure your application meets policy compliance.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="email-notifications-for-elearning-curriculum-due-date-changes">Email Notifications for eLearning Curriculum Due Date Changes<a href="https://docs.veracode.com/updates/r/c_all_was#email-notifications-for-elearning-curriculum-due-date-changes" class="hash-link" aria-label="Direct link to Email Notifications for eLearning Curriculum Due Date Changes" title="Direct link to Email Notifications for eLearning Curriculum Due Date Changes" translate="no">​</a></h5><ul>
<li class="">eLearning administrators can now send emails to notify students and their managers when the due date for an assigned curriculum changes. They can also send emails to notify managers when a due date on a curriculum has passed and students have not completed the curriculum.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="february-21-2020-1">February 21, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#february-21-2020-1" class="hash-link" aria-label="Direct link to February 21, 2020" title="Direct link to February 21, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-javascript-elearning-courses">New JavaScript eLearning Courses<a href="https://docs.veracode.com/updates/r/c_all_was#new-javascript-elearning-courses" class="hash-link" aria-label="Direct link to New JavaScript eLearning Courses" title="Direct link to New JavaScript eLearning Courses" translate="no">​</a></h5><p>Veracode eLearning has released a new set of secure coding courses for JavaScript:</p><ul>
<li class=""><em>Secure Coding for JavaScript - Authentication &amp; Authorization</em></li>
<li class=""><em>Secure Coding for JavaScript - Configuration and Deployment</em></li>
<li class=""><em>Secure Coding for JavaScript - Data Protection</em></li>
<li class=""><em>Secure Coding for JavaScript - Information and Error Handling</em></li>
<li class=""><em>Secure Coding for JavaScript - Validation and Encoding</em></li>
</ul><p>These courses cover application security practices and associated vulnerabilities, including the OWASP Top Ten, and secure coding techniques in JavaScript, including using the AngularJS and ReachJS frameworks.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="february-19-2020">February 19, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#february-19-2020" class="hash-link" aria-label="Direct link to February 19, 2020" title="Direct link to February 19, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="updated-look-and-feel-with-new-veracode-branding">Updated Look-and-Feel with New Veracode Branding<a href="https://docs.veracode.com/updates/r/c_all_was#updated-look-and-feel-with-new-veracode-branding" class="hash-link" aria-label="Direct link to Updated Look-and-Feel with New Veracode Branding" title="Direct link to Updated Look-and-Feel with New Veracode Branding" translate="no">​</a></h5><ul>
<li class="">Veracode has updated the look-and-feel of the Veracode Platform with new branding.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="january-28-2020">January 28, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#january-28-2020" class="hash-link" aria-label="Direct link to January 28, 2020" title="Direct link to January 28, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="updates-to-sandbox-functionality">Updates to Sandbox Functionality<a href="https://docs.veracode.com/updates/r/c_all_was#updates-to-sandbox-functionality" class="hash-link" aria-label="Direct link to Updates to Sandbox Functionality" title="Direct link to Updates to Sandbox Functionality" translate="no">​</a></h5><p>Veracode has implemented these changes to improve the performance of sandbox scans:</p><ul>
<li class="">You can delete a sandbox and all of its scans when you promote it to policy.</li>
<li class="">You may have a maximum number of sandboxes you can create for each application. The default limit is 25.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="automated-emails-for-elearning-curriculum-updates">Automated Emails for eLearning Curriculum Updates<a href="https://docs.veracode.com/updates/r/c_all_was#automated-emails-for-elearning-curriculum-updates" class="hash-link" aria-label="Direct link to Automated Emails for eLearning Curriculum Updates" title="Direct link to Automated Emails for eLearning Curriculum Updates" translate="no">​</a></h5><ul>
<li class="">Veracode eLearning administrators can turn on automated email notifications to alert eLearning students and managers when the administrator assigns a curriculum to a student.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="january-24-2020">January 24, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#january-24-2020" class="hash-link" aria-label="Direct link to January 24, 2020" title="Direct link to January 24, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-video---create-a-custom-policy-in-the-veracode-platform">New Video - Create a Custom Policy in the Veracode Platform<a href="https://docs.veracode.com/updates/r/c_all_was#new-video---create-a-custom-policy-in-the-veracode-platform" class="hash-link" aria-label="Direct link to New Video - Create a Custom Policy in the Veracode Platform" title="Direct link to New Video - Create a Custom Policy in the Veracode Platform" translate="no">​</a></h5><ul>
<li class="">This video shows you how to create a custom policy in the Veracode Platform.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="january-13-2020">January 13, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#january-13-2020" class="hash-link" aria-label="Direct link to January 13, 2020" title="Direct link to January 13, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="sca-findings-dashboard-available-in-analytics">SCA Findings Dashboard Available in Analytics<a href="https://docs.veracode.com/updates/r/c_all_was#sca-findings-dashboard-available-in-analytics" class="hash-link" aria-label="Direct link to SCA Findings Dashboard Available in Analytics" title="Direct link to SCA Findings Dashboard Available in Analytics" translate="no">​</a></h5><ul>
<li class="">Veracode Analytics has a new dashboard that provides Software Composition Analysis (SCA) findings on open vulnerabilities, license risk, issue severities, and library data. Veracode Analytics does not currently display findings from agent-based scans.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="january-8-2020-1">January 8, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#january-8-2020-1" class="hash-link" aria-label="Direct link to January 8, 2020" title="Direct link to January 8, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-video---review-scan-results">New Video - Review Scan Results<a href="https://docs.veracode.com/updates/r/c_all_was#new-video---review-scan-results" class="hash-link" aria-label="Direct link to New Video - Review Scan Results" title="Direct link to New Video - Review Scan Results" translate="no">​</a></h5><ul>
<li class="">This video shows you how to view Veracode scan results in the Veracode Platform.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="january-2-2020">January 2, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#january-2-2020" class="hash-link" aria-label="Direct link to January 2, 2020" title="Direct link to January 2, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="sca-findings-available-in-veracode-analytics">SCA Findings Available in Veracode Analytics<a href="https://docs.veracode.com/updates/r/c_all_was#sca-findings-available-in-veracode-analytics" class="hash-link" aria-label="Direct link to SCA Findings Available in Veracode Analytics" title="Direct link to SCA Findings Available in Veracode Analytics" translate="no">​</a></h5><ul>
<li class="">
<p>Veracode Analytics now provides details about Software Composition Analysis (SCA) findings. If you have an SCA subscription, you can view SCA vulnerabilities displayed in the Findings Status &amp; History dashboard and the Resolution and Mitigation Details dashboard.</p>
</li>
<li class="">
<p>Veracode Analytics does not currently display findings from agent-based scans.</p>
</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="software-composition-analysis">Software Composition Analysis<a href="https://docs.veracode.com/updates/r/c_all_was#software-composition-analysis" class="hash-link" aria-label="Direct link to Software Composition Analysis" title="Direct link to Software Composition Analysis" translate="no">​</a></h4><p>View the list below for highlights of previous releases.</p><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="december-17-2020">December 17, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#december-17-2020" class="hash-link" aria-label="Direct link to December 17, 2020" title="Direct link to December 17, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="container-scanning-for-debian">Container Scanning for Debian<a href="https://docs.veracode.com/updates/r/c_all_was#container-scanning-for-debian" class="hash-link" aria-label="Direct link to Container Scanning for Debian" title="Direct link to Container Scanning for Debian" translate="no">​</a></h5><ul>
<li class="">Veracode Software Composition Analysis now supports agent-based scans of Debian Docker containers. You can scan Debian containers through the command-line interface or as part of your continuous integration pipelines.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="october-15-2020">October 15, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#october-15-2020" class="hash-link" aria-label="Direct link to October 15, 2020" title="Direct link to October 15, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="set-default-branch-to-the-most-recently-scanned-branch-or-tag">Set Default Branch to the Most Recently Scanned Branch or Tag<a href="https://docs.veracode.com/updates/r/c_all_was#set-default-branch-to-the-most-recently-scanned-branch-or-tag" class="hash-link" aria-label="Direct link to Set Default Branch to the Most Recently Scanned Branch or Tag" title="Direct link to Set Default Branch to the Most Recently Scanned Branch or Tag" translate="no">​</a></h5><ul>
<li class="">
<p>You can now set your Veracode Software Composition Analysis projects to automatically update their default branch to be the most recently scanned branch or tag. This enhancement enables the use of tags as default branches and reduces the number of issues that display in the Veracode Platform, by default.</p>
</li>
<li class="">
<p>Existing projects without a default branch selected in their project settings now use the Use Last Scanned option as the default branch.</p>
</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="october-13-2020">October 13, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#october-13-2020" class="hash-link" aria-label="Direct link to October 13, 2020" title="Direct link to October 13, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="vulnerable-method-support-for-javascript">Vulnerable Method Support for JavaScript<a href="https://docs.veracode.com/updates/r/c_all_was#vulnerable-method-support-for-javascript" class="hash-link" aria-label="Direct link to Vulnerable Method Support for JavaScript" title="Direct link to Vulnerable Method Support for JavaScript" translate="no">​</a></h5><ul>
<li class="">Veracode Software Composition Analysis supports vulnerable method analysis for agent-based scans of JavaScript applications. This feature helps prioritize your remediation actions by identifying first-party code that calls a function in a JavaScript library that makes the library vulnerable.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="october-1-2020">October 1, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#october-1-2020" class="hash-link" aria-label="Direct link to October 1, 2020" title="Direct link to October 1, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="container-scanning-for-ubuntu">Container Scanning for Ubuntu<a href="https://docs.veracode.com/updates/r/c_all_was#container-scanning-for-ubuntu" class="hash-link" aria-label="Direct link to Container Scanning for Ubuntu" title="Direct link to Container Scanning for Ubuntu" translate="no">​</a></h5><ul>
<li class="">Veracode Software Composition Analysis now supports agent-based scans of Ubuntu Docker containers. You can scan Ubuntu containers through the command-line interface or as part of your continuous integration pipelines.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="september-26-2020-1">September 26, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#september-26-2020-1" class="hash-link" aria-label="Direct link to September 26, 2020" title="Direct link to September 26, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="grace-periods-for-sca-policy-rules">Grace Periods for SCA Policy Rules<a href="https://docs.veracode.com/updates/r/c_all_was#grace-periods-for-sca-policy-rules" class="hash-link" aria-label="Direct link to Grace Periods for SCA Policy Rules" title="Direct link to Grace Periods for SCA Policy Rules" translate="no">​</a></h5><ul>
<li class="">Veracode Software Composition Analysis now allows you to include grace periods for SCA upload scans in your application security policies. You can define a grace period for all scan types, including SCA, or define a grace period that applies specifically to SCA scans.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="july-17-2020">July 17, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#july-17-2020" class="hash-link" aria-label="Direct link to July 17, 2020" title="Direct link to July 17, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="default-date-limit-applied-to-scan-data-in-agent-based-scan-workspaces">Default Date Limit Applied to Scan Data in Agent-Based Scan Workspaces<a href="https://docs.veracode.com/updates/r/c_all_was#default-date-limit-applied-to-scan-data-in-agent-based-scan-workspaces" class="hash-link" aria-label="Direct link to Default Date Limit Applied to Scan Data in Agent-Based Scan Workspaces" title="Direct link to Default Date Limit Applied to Scan Data in Agent-Based Scan Workspaces" translate="no">​</a></h5><ul>
<li class="">To improve performance and usability, the scan data for your workspaces is now limited to projects scanned in the last 30 days, by default. You can change the time window of exported projects on the workspace page in the Veracode Platform.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="july-7-2020-1">July 7, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#july-7-2020-1" class="hash-link" aria-label="Direct link to July 7, 2020" title="Direct link to July 7, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="advanced-license-risk-management-for-agent-based-scans">Advanced License Risk Management for Agent-Based Scans<a href="https://docs.veracode.com/updates/r/c_all_was#advanced-license-risk-management-for-agent-based-scans" class="hash-link" aria-label="Direct link to Advanced License Risk Management for Agent-Based Scans" title="Direct link to Advanced License Risk Management for Agent-Based Scans" translate="no">​</a></h5><ul>
<li class="">Veracode Software Composition Analysis now provides advanced license risk management capabilities for agent-based scans. You can control the acceptable risk from open-source libraries by adding rules based on Veracode license risk ratings or by rejecting specific licenses.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="june-17-2020">June 17, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#june-17-2020" class="hash-link" aria-label="Direct link to June 17, 2020" title="Direct link to June 17, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-api-endpoints-for-agent-management">New API Endpoints for Agent Management<a href="https://docs.veracode.com/updates/r/c_all_was#new-api-endpoints-for-agent-management" class="hash-link" aria-label="Direct link to New API Endpoints for Agent Management" title="Direct link to New API Endpoints for Agent Management" translate="no">​</a></h5><ul>
<li class="">The Veracode SCA Agent REST API includes new endpoints for creating and deleting agents. This update enables you to more effectively scale your agent administration and improve productivity with agent-based scans.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="may-28-2020-1">May 28, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#may-28-2020-1" class="hash-link" aria-label="Direct link to May 28, 2020" title="Direct link to May 28, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="issue-summary-for-agent-based-scans">Issue Summary for Agent-Based Scans<a href="https://docs.veracode.com/updates/r/c_all_was#issue-summary-for-agent-based-scans" class="hash-link" aria-label="Direct link to Issue Summary for Agent-Based Scans" title="Direct link to Issue Summary for Agent-Based Scans" translate="no">​</a></h5><ul>
<li class="">Veracode Software Composition Analysis now provides a summary table on each agent-based scan workspace and project page that provides a quick view of the state of your open-source issues.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="april-29-2020">April 29, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#april-29-2020" class="hash-link" aria-label="Direct link to April 29, 2020" title="Direct link to April 29, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="vulnerability-database-update">Vulnerability Database Update<a href="https://docs.veracode.com/updates/r/c_all_was#vulnerability-database-update" class="hash-link" aria-label="Direct link to Vulnerability Database Update" title="Direct link to Vulnerability Database Update" translate="no">​</a></h5><ul>
<li class="">
<p>The Veracode Vulnerability Database is updated to resolve a discrepancy in severity rating compared to the National Vulnerability Database (NVD) for approximately 200 of over 20,000 total vulnerabilities. Veracode has already contacted all organizations that have applications that fail policy as a result of this update.</p>
</li>
<li class="">
<p>If your Veracode account manager has not contacted you, you do not need to take any action.</p>
</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="april-6-2020">April 6, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#april-6-2020" class="hash-link" aria-label="Direct link to April 6, 2020" title="Direct link to April 6, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="alpine-linux-support-for-agent-based-scans">Alpine Linux Support for Agent-Based Scans<a href="https://docs.veracode.com/updates/r/c_all_was#alpine-linux-support-for-agent-based-scans" class="hash-link" aria-label="Direct link to Alpine Linux Support for Agent-Based Scans" title="Direct link to Alpine Linux Support for Agent-Based Scans" translate="no">​</a></h5><ul>
<li class="">Veracode Software Composition Analysis (SCA) now supports the Alpine Linux distribution for agent-based scans.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="organization-rules-for-agent-based-scans">Organization Rules for Agent-Based Scans<a href="https://docs.veracode.com/updates/r/c_all_was#organization-rules-for-agent-based-scans" class="hash-link" aria-label="Direct link to Organization Rules for Agent-Based Scans" title="Direct link to Organization Rules for Agent-Based Scans" translate="no">​</a></h5><ul>
<li class="">Veracode Software Composition Analysis (SCA) now supports configuring rules for agent-based scans at the organization level. Administrators can apply these rules to all workspaces in an organization to efficiently enforce a common security standard.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="april-3-2020">April 3, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#april-3-2020" class="hash-link" aria-label="Direct link to April 3, 2020" title="Direct link to April 3, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-api-endpoint-for-auditing-agent-based-scan-events">New API Endpoint for Auditing Agent-Based Scan Events<a href="https://docs.veracode.com/updates/r/c_all_was#new-api-endpoint-for-auditing-agent-based-scan-events" class="hash-link" aria-label="Direct link to New API Endpoint for Auditing Agent-Based Scan Events" title="Direct link to New API Endpoint for Auditing Agent-Based Scan Events" translate="no">​</a></h5><ul>
<li class="">The Veracode SCA Agent REST API includes a new endpoint that provides a detailed audit of events for agent-based scans.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-17-2020-1">March 17, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#march-17-2020-1" class="hash-link" aria-label="Direct link to March 17, 2020" title="Direct link to March 17, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="license-risk-details-for-agent-based-scans">License Risk Details for Agent-Based Scans<a href="https://docs.veracode.com/updates/r/c_all_was#license-risk-details-for-agent-based-scans" class="hash-link" aria-label="Direct link to License Risk Details for Agent-Based Scans" title="Direct link to License Risk Details for Agent-Based Scans" translate="no">​</a></h5><ul>
<li class="">Veracode Software Composition Analysis (SCA) provides the license risk rating of each open-source license type identified in agent-based scans to help you make informed decisions about acceptable risk.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="gem-support-for-containers">Gem Support for Containers<a href="https://docs.veracode.com/updates/r/c_all_was#gem-support-for-containers" class="hash-link" aria-label="Direct link to Gem Support for Containers" title="Direct link to Gem Support for Containers" translate="no">​</a></h5><ul>
<li class="">Agent-based scans now support the gem package manager for scanning Docker containers.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-16-2020">March 16, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#march-16-2020" class="hash-link" aria-label="Direct link to March 16, 2020" title="Direct link to March 16, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-video---set-up-an-agent-to-scan-with-veracode-software-composition-analysis">New Video - Set Up an Agent to Scan with Veracode Software Composition Analysis<a href="https://docs.veracode.com/updates/r/c_all_was#new-video---set-up-an-agent-to-scan-with-veracode-software-composition-analysis" class="hash-link" aria-label="Direct link to New Video - Set Up an Agent to Scan with Veracode Software Composition Analysis" title="Direct link to New Video - Set Up an Agent to Scan with Veracode Software Composition Analysis" translate="no">​</a></h5><p>This video shows you how to:</p><ul>
<li class="">Create a workspace</li>
<li class="">Set up an agent</li>
<li class="">Start a scan from your command line</li>
<li class="">View scan results</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-9-2020-1">March 9, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#march-9-2020-1" class="hash-link" aria-label="Direct link to March 9, 2020" title="Direct link to March 9, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="ism-endpoint-2035">ISM endpoint 20.3.5<a href="https://docs.veracode.com/updates/r/c_all_was#ism-endpoint-2035" class="hash-link" aria-label="Direct link to ISM endpoint 20.3.5" title="Direct link to ISM endpoint 20.3.5" translate="no">​</a></h5><ul>
<li class="">The endpoint installer supports client-side Java and 32-bit Java.</li>
<li class="">The endpoint installer supports proxy gateway-only property.</li>
<li class="">The endpoint supports running diagnostics through a DSE tunnel.</li>
<li class="">The endpoint supports new advanced diagnostics options.</li>
<li class="">Consolidated direct diagnostic options and diagnostics options that run through a DSE tunnel.</li>
<li class="">The ISM service from the Windows installer runs under the less privileged LocalService account instead of LocalSystem.</li>
<li class="">Proxy configuration in the installer no longer requires web access to <code>veracode.com</code>.</li>
<li class="">Resolved issue with property merge in the endpoint installer.</li>
<li class="">Improved endpoint memory management and <code>out of memory</code> protection.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="february-13-2020">February 13, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#february-13-2020" class="hash-link" aria-label="Direct link to February 13, 2020" title="Direct link to February 13, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="npm-and-pip-support-for-containers">NPM and Pip Support for Containers<a href="https://docs.veracode.com/updates/r/c_all_was#npm-and-pip-support-for-containers" class="hash-link" aria-label="Direct link to NPM and Pip Support for Containers" title="Direct link to NPM and Pip Support for Containers" translate="no">​</a></h5><ul>
<li class="">Agent-based scans now support the NPM and pip package managers for scanning Docker containers.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="january-29-2020">January 29, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#january-29-2020" class="hash-link" aria-label="Direct link to January 29, 2020" title="Direct link to January 29, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="update-to-integrated-sca-upload-and-scan">Update to Integrated SCA Upload and Scan<a href="https://docs.veracode.com/updates/r/c_all_was#update-to-integrated-sca-upload-and-scan" class="hash-link" aria-label="Direct link to Update to Integrated SCA Upload and Scan" title="Direct link to Update to Integrated SCA Upload and Scan" translate="no">​</a></h5><ul>
<li class="">If you use Veracode Integrated Software Composition Analysis without a Veracode Static Analysis subscription, you can now perform scans using the upload and scan method.</li>
</ul><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="sca-results-export">SCA Results Export<a href="https://docs.veracode.com/updates/r/c_all_was#sca-results-export" class="hash-link" aria-label="Direct link to SCA Results Export" title="Direct link to SCA Results Export" translate="no">​</a></h5><ul>
<li class="">You can now generate and download your latest Software Composition Analysis results from the Export Data page in the Veracode Platform at any time. This report does not include data from agent-based scans.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="january-24-2020-1">January 24, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#january-24-2020-1" class="hash-link" aria-label="Direct link to January 24, 2020" title="Direct link to January 24, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-video---upload-and-scan-with-veracode-software-composition-analysis">New Video - Upload and Scan with Veracode Software Composition Analysis<a href="https://docs.veracode.com/updates/r/c_all_was#new-video---upload-and-scan-with-veracode-software-composition-analysis" class="hash-link" aria-label="Direct link to New Video - Upload and Scan with Veracode Software Composition Analysis" title="Direct link to New Video - Upload and Scan with Veracode Software Composition Analysis" translate="no">​</a></h5><ul>
<li class="">This video shows you how to upload and scan applications with Veracode Software Composition Analysis.</li>
</ul><h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="january-15-2020">January 15, 2020<a href="https://docs.veracode.com/updates/r/c_all_was#january-15-2020" class="hash-link" aria-label="Direct link to January 15, 2020" title="Direct link to January 15, 2020" translate="no">​</a></h4><h5 class="anchor anchorTargetStickyNavbar_Vzrq" id="get-teams-list-with-the-sca-agent-rest-api">Get Teams List with the SCA Agent REST API<a href="https://docs.veracode.com/updates/r/c_all_was#get-teams-list-with-the-sca-agent-rest-api" class="hash-link" aria-label="Direct link to Get Teams List with the SCA Agent REST API" title="Direct link to Get Teams List with the SCA Agent REST API" translate="no">​</a></h5><ul>
<li class="">The Veracode SCA Agent REST API for Veracode Agent-Based Scan now supports retrieving a list of the teams in an organization, including filtering by the full or partial team name.</li>
</ul></div></div></details>]]></content:encoded>
        </item>
  </channel>
</rss>