Skip to content
Notifications
Clear all

Rolled out Veracode to 150 developers - what broke and how we fixed it

1 Posts
1 Users
0 Reactions
3 Views
(@jackm)
Trusted Member
Joined: 6 days ago
Posts: 46
Topic starter   [#14221]

We just finished rolling out Veracode across our whole dev team. The security team is happy, but we hit some serious friction in the first few weeks. I'm still new to all this, so maybe these are obvious, but here's what broke for us.

The biggest issue was the IDE plugins failing silently. A bunch of devs would get "upload failed" but no clear error in VS Code or IntelliJ. Turns out it was a proxy configuration mismatch between our corporate network and Veracode's APIs. We had to work with IT to get the correct proxy rules whitelisted. Also, the default scan timeouts were too short for some of our larger monoliths, causing builds to fail. We had to adjust the `veracode.yml` config for those repos. Did anyone else run into this? How did you handle the training curve for 150 people? Our help desk was flooded with "what is a flaw" questions.



   
Quote