Veracode DevSecOps Pipeline
Unified workflow capability for integrating Veracode application security into DevSecOps pipelines. Enables development teams and security engineers to automate application onboarding, trigger security scans, retrieve findings filtered by severity and policy compliance, and generate compliance reports — all through a single unified API. Combines the Applications, Findings, and Reporting APIs.
What You Can Do
MCP Tools
list-applications
List Veracode applications, optionally filtered by policy compliance status or name
get-application
Get details for a specific Veracode application by GUID
create-application
Create a new application profile in the Veracode Platform
get-policy-compliance
Get policy compliance evaluation status for an application
list-findings
List security findings for a Veracode application, filterable by scan type, severity, CWE, and policy violations
get-static-flaw-info
Get static analysis flaw code path details for a specific finding
generate-security-report
Generate an asynchronous security findings or compliance report
get-security-report
Retrieve a generated security report by ID