The Scan Engine provides options to configure application scanning and enhance
governance over Team Dev push approval. Configure which applications are scanned, the
parameters applications must have to satisfy Team Dev approval, and whether developers can
use Suite Scans for faster, focused validation.
About this task
Set filter conditions that
align with your Team Dev governance requirements. Different applications may require
different criteria based on their risk profile and deployment targets.
Procedure
-
Navigate to .
-
Select the Dev Team tab.
-
In the Table for application scanning condition field,
verify the table reference.
This field specifies which table the scan condition builder references. By
default, this is the Custom Applications [x_snc_sys_app_app] table and is
typically not changed.
-
Configure the application scanning condition using the condition builder.
The Scan Engine uses these defined conditions to determine which applications
to include in scans. By default, conditions are set to filter out system
applications and include only active, custom applications.
You can add and configure additional filter conditions by selecting
Add filter condition. You can also add and
configure OR clauses by selecting Add OR clause.
Tip: You can append filter conditions and OR clauses to existing
conditions by selecting the AND or OR options next to them.
-
Select the Enable Team Dev push approval enforcement
check box to require applications to meet approval conditions before push.
When enabled, applications must meet the conditions specified in the
Conditions for Team Dev push approval field.
Warning: Team Dev reviewers may be blocked from approving pushes
until scanning validation is satisfied.
-
Configure the conditions for Team Dev push approval using the condition
builder.
Typical criteria include:
- Finding severity limits
- Restricted module rules
- Definition suite alignment
- Custom governance conditions
- Optional:
Configure additional application scanning options.
Table 1. Additional application scanning options
| Field |
Description |
| Enforce completion criteria for application scans |
- When selected, applications must meet the conditions
specified in the Conditions for completing
application scans field.
- Distinct from Team Dev push approval enforcement.
- Allows different completion criteria from approval
criteria for flexible governance.
|
| Conditions for completing application scans |
- Conditions used to determine if an application scan is
complete or resolved for internal tracking.
- Typically used to mark an application as scanned and passed for compliance or tracking purposes.
- Separate from Team Dev approval.
|
| Allow Suite Scan for applications |
- Suite Scan runs only selected definitions for faster
validation.
- Full Scan runs all active definitions for comprehensive
validation.
- When selected, developers can choose between Full scan
and Suite scan.
- When cleared, only Full scans are available.
- Enable for faster, focused validation. Clear for
comprehensive validation.
|
-
Select Save.