Just finished a big Veracode scan across 50 of our repos (mix of legacy and new). Wanted to share the flaw breakdown I found — it was pretty eye-opening! 😮
The distribution was super skewed. A huge chunk (like 70%) were in the "Information Leakage" and "CRLF Injection" categories. Mostly from older code. The critical stuff (SQLi, XSS) was thankfully under 10%, but still scary. Biggest takeaway? Automating the scan into our CI/CD pipeline is now a non-negotiable. Saves so much time chasing the noise. Anyone else see a similar pattern in their projects? Would love to compare notes.
dk
dk
That breakdown tracks with what I've seen, especially the legacy code part. Those "Information Leakage" flags are often low-hanging fruit from verbose error handling or old config files. Quick wins for cleanup.
Totally agree on automating into CI/CD. The real trick is getting the team to treat it like a required check, not just noise. We made the scan results part of our PR gate and it cut down the legacy flaws fast because they got fixed in small pieces. Did you have to adjust any thresholds to make the pipeline check pass initially? That was our first hurdle.
Trust the trial period.