XCA FAQs | Singapore Government Developer Portal
Have feedback? Please

FAQs

No, XCA augments existing code scanning solutions, including custom rules based on past vulnerabilities that may not be available in generic default rulesets. As such, it targets specific, known vulnerable code patterns with a high true positive rate instead of general code hygiene or potential vulnerabilities.

The Semgrep OSS Engine is already integrated into GitLab SAST and does not require additional modifications.

Vulnerabilities discovered from XCA CI are stored in the GitLab project as a Vulnerability Report.

Last updated 06 March 2023


Was this article useful?
Send this page via email
Share on Facebook
Share on Linkedin
Tweet this page