Configure a scan in AppScan 360°
Procedure
To scan your application:
-
Download and set up either:
- A supported plugin.
Complete information about supported plugins is listed on the Plugins and integrations documentation page.
- AppScan Go!, the client utility graphical user interface.
- The Static Analyzer Command Line Utility, as described in Using the Static Analyzer Command Line Utility.
- A supported plugin.
-
Scan or generate an IRX file for
your application, or identify source code files to scan.
- To generate an IRX file by using the CLI, follow the instructions in Generating an IRX file by using the command line interface (CLI). You can scan all supported languages from the CLI.
- To generate an IRX file using AppScan Go!, follow the instructions in Configuring a scan using AppScan Go!.
-
To scan a source code file, identify the appropriate
.zip
,.war
,.jar
, or.ear
file.
Note: When you scan code or generate an IRX file, you might receive a message about updating to the latest Static Analyzer Command Line Utility. See Command Line Utility (CLI) support. - If you have not yet done so: Create an application for your scans.
- Use the Create scan wizard to start configuring your scan. Start the wizard from Application > Application > Scans > Create Scan > Static (SAST).
-
Upload File tab: Drag-and-drop the file to scan into the
gray area (or Click to select the file), then click
Next.
You can scan files of type
.irx
,.zip
,.war
,.jar
, or.ear
. - Click Review and Scan to proceed to the summary dialog.
- You can optionally edit the default name that was given to the scan.
- Click Scan Now.