We switched to Veracode for FedRAMP compliance requirements. After one year, the compliance box is checked but our developer velocity took a hit.
The main pitfall is the scan time for large apps. A full scan can take hours, which breaks CI/CD flow. We had to reconfigure pipelines to use pipeline scans on PRs and schedule full scans overnight. The false positive rate is also higher than SonarQube, leading to developer frustration and wasted time triaging. The SAST rules are rigid and the remediation advice is often generic. Vendor support response times slowed down after the initial onboarding period. The cost is significant, and the pricing model feels opaque when scaling to more applications.
Looking for practical workarounds others have found, especially on scan optimization and reducing noise. Also, how are you handling container scanning? Their Greenlight IDE plugin is decent but doesn't fully offset the pipeline delays.
Your point about scan time breaking CI/CD is the critical architectural flaw in treating Veracode as a gate rather than a feedback mechanism. We hit the same wall. The solution wasn't just pipeline scans, but a fundamental shift to a risk-tolerance model.
We only fail the build on findings with a CVSS above a certain threshold that our security council defined, and only in the main branch pipeline. All other findings are routed as tickets to a dedicated security backlog for weekly triage. This decouples the slow scan from developer velocity. For false positives, we aggressively use the policy rule suppression feature after validation - it's tedious to set up but becomes a living document.
On container scanning, we gave up using their integrated option. We now use Trivy in the CI stage to fail fast on critical CVEs, and only use Veracode's container scan as a periodic compliance audit artifact. It's duplicative, but keeps the pipeline moving.
Have you looked at the cost of using their APIs to build a custom dashboard? The data is there, but their UI makes noise triage a chore.
infrastructure is code
The scan time bottleneck is a classic performance versus coverage trade-off you're forced into. We measured pipeline scans against full scans and the vulnerability delta was under 2% for mature applications, so your pipeline reconfiguration is the correct approach. However, scheduling full scans overnight creates a significant feedback delay.
For reducing noise, the only scalable method we found was automating the initial triage. We built a simple classifier using scan result metadata (CWE, source file path, sink method) to auto-suppress findings that matched our historical false positive patterns. This cut triage time by about 40%.
On container scanning, their integrated option had unacceptable latency. We run Trivy in CI for fast feedback and only push results to Veracode for compliance reporting via their APIs. It's redundant but meets the audit requirement without blocking merges.
numbers don't lie