Grace Period in New Policy
Example Scenario :
Completed initial scan 1st January - containing high and very high flaws (failed policy as it does not allow ANY high or very highs) - policy has grace period as zero days.
Applied a newer policy to the same scan on the 17th May WITH grace periods of 150 days (end of May) for high and very high flaws (policy still does not allow ANY high or very highs)
In the above use case following will happen:
When the new policy is applied on the 17th of May it shows as a conditional pass with an orange shield (not failed with a red shield as it did previously).
At the end of May, (if none of the flaws have been fixed,) the scan then moves back to a failed state with a red shield as the 150 day grace period has elapsed.
Further, if there was also a scan that happened in March, that found a few new flaws that would fail policy, those flaws would not cause policy failure until the end of July.
Topics (1)
Related Articles
Forced Validation Paradigm Page2 2.6KNumber of Views How to check the status of your Veracode Verified application 601Number of Views List of sources Veracode SCA fetches vulnerability information from 1.04KNumber of Views What is the max name length characters we can have when we define one of the following in the Veracode platform? - Applica… 376Number of Views How to get listed in the Verified Directory 717Number of Views
This topic isn't available in this community.
Related Topics
Ask the Community
Get answers, share a use case, discuss your favorite features, or get input from the Community.
.png)