Jump to main content
HCL Logo Product Documentation
Customer Support Community
Customer Support HCLSoftware U Community Forums Customer Idea Portal
HCL AppScan Source
  1. Home icon
  2. Welcome
  3. Reference

    Review reference information for HCL® AppScan® Source, including using utilities, plug-ins, and APIs.

  4. AppScan® Source Data Access API

    The Data Access API provides access to AppScan® Source-generated assessment results, including findings and finding details. It also provides access to assessment metrics such as analysis date and time, lines of code, V-density, and number of findings.

  5. Views and windows

    AppScan® Source for Development views and windows provide alternative presentations of findings, support code editing, and allow you to navigate the information in your workbench. A view might appear by itself, or stacked with other views in a tabbed notebook. You can change the layout of a perspective or window layout by opening and closing views and by docking them in different positions in the Workbench window.

  6. Views that assist with triage

    The views in this section are used for fine-grained scan output viewing and management.

Product logo

  • Welcome

    Welcome to the documentation for HCL® AppScan® Source.

  • What's New

    Explore new features added to AppScan® Source and note any features and capabilities deprecated in this release.

  • Installing

    Learn how to install, upgrade, and activate HCL® AppScan® Source.

  • Configuring

    Learn how to configure applications, folders, and projects, and set attributes and properties in HCL® AppScan® Source.

  • Administering

    Learn how to administer user accounts and permissions, audit user activity, and manage integrations in HCL® AppScan® Source.

  • Scanning

    This section explains how to scan your source code and manage assessments in HCL® AppScan® Source.

  • Triage and analysis

    Grouping similar findings allows security analysts or IT auditors to segment and triage source code problems. This section explains how to triage AppScan® Source assessments and analyze results.

  • Reporting

    Security analysts and risk managers can access reports of select findings or a series of audit reports that measure compliance with software security best practices and regulatory requirements. This section explains how to create reports of aggregate finding data.

  • Extending product function

    Learn how to extend the product to meet specific development requirements.

  • Reference

    Review reference information for HCL® AppScan® Source, including using utilities, plug-ins, and APIs.

    • The Ounce/Make build utility

      Ounce/Make is a tool that automates the importing of configuration information into AppScan® Source from build environments that use makefile. Ounce/Make eliminates the need to import configuration information from makefiles manually; this the recommended method of configuring these projects.

    • AppScan® Source command line interface (CLI)

      The CLI is an interface to core AppScan® Source functionality.

    • The Ounce/Ant build tool

      This section describes how to use Ounce/Ant, an AppScan® Source build utility that integrates AppScan Source and Apache Ant. Integrating Ounce/Ant with your Ant environment helps you automate builds and code assessments.

    • AppScan® Source Data Access API

      The Data Access API provides access to AppScan® Source-generated assessment results, including findings and finding details. It also provides access to assessment metrics such as analysis date and time, lines of code, V-density, and number of findings.

      • Data Access API object model

      • Using the Data Access API

        You can find complete examples for a number of Data Access API scenarios in the SamplePublished.java and SampleSdk.java files included in <install_dir>\sdk\sample\com\ouncelabs\sdk\sample (where <install_dir> is the location of your AppScan® Source installation).

      • Data Access API classes and methods

      • Ounce/Maven plug-in

        This section describes the Ounce/Maven plug-in, which uses Maven, an Apache build tool, to integrate AppScan® Source into the Maven workflow.

      • AppScan® Source for Automation

        The Automation Server (ounceautod) allows you to automate key aspects of the AppScan® Source workflow and integrate security with build environments during the software development life cycle (SDLC). The Automation Server allows you to queue requests to scan and publish assessments, and generate reports on the security of application code.

      • Framework for Frameworks handling APIs

        AppScan® Source provides a set of Java™ APIs that allow you to add support for frameworks that are used in your applications. The classes and methods offered in these APIs allow you to account for frameworks for which built-in support is not provided.

      • AppScan® Source client component error messages

      • AppScan® Source for Analysis samples

        AppScan® Source for Analysis includes a sample applicationsample applications that you can use to familiarize yourself with the product.

      • The AppScan® Source for Analysis work environment

        To get the most out of AppScan® Source, you should understand the basic concepts behind the AppScan Source for Analysis working environment and how to use the options that best fit your workflow.

      • Views and windows

        AppScan® Source for Development views and windows provide alternative presentations of findings, support code editing, and allow you to navigate the information in your workbench. A view might appear by itself, or stacked with other views in a tabbed notebook. You can change the layout of a perspective or window layout by opening and closing views and by docking them in different positions in the Workbench window.

        • Configuration views

          The views in this section are used for configuring AppScan® Source.

        • Views that assist with scan output

          The views in this section are used for viewing and managing scan output.

        • Views that assist with triage

          The views in this section are used for fine-grained scan output viewing and management.

          • Assessment Diff view

            The Assessment Diff view represents a combination of the My Assessments view and the Findings view. When you select two assessments to compare, the differences between the two assessments display.

          • Custom Findings view

            The Custom Findings view displays the user-defined or custom findings that exist in the currently opened assessment. In this view, you can create, delete, and modify custom findings for the current assessment. When a custom finding is created in the Custom Findings view, the new finding is added to the current assessment, and the assessment metrics update.

          • Views with findings

          • Sources and Sinks view

            The Sources and Sinks view provides the ability to view findings based on a trace of input and output.

        • Views that allow you to investigate a single finding

          The views in this section are used for investigating single findings.

        • Views that allow you to work with assessments

          The views in this section are used for working with assessments at a high level.

        • Bundles view

          In the Bundles view, you create new bundles, add findings to a bundle, view bundles and notes, rename, or delete a bundle. This view lists the bundle name, any notes attached to the bundle, the number of findings in the bundle, and if the bundle is excluded. Once you open the bundle to see its contents, you can move findings to other bundles, modify the findings, edit the code, or submit the bundle to a defect tracking system.

      • CWE support

        The Common Weakness Enumeration (CWE) is an industry standard list that provides common names for publicly known software weaknesses. This topic lists the CWE IDs that are supported in the current version of AppScan® Source.

    • Glossary

      Learn common product terminology.

  • Troubleshooting and support

    Self-help information, resources, and tools to help you troubleshoot issues while using HCL® AppScan® Source.

 Feedback

Views that assist with triage

The views in this section are used for fine-grained scan output viewing and management.

  • Assessment Diff view
  • Custom Findings view
  • Excluded Findings view
  • Findings view
  • Resolved Findings view
  • Modified Findings view
  • Search Results view
  • Report view
  • Sources and Sinks view
  • Assessment Diff view
    The Assessment Diff view represents a combination of the My Assessments view and the Findings view. When you select two assessments to compare, the differences between the two assessments display.
  • Custom Findings view
    The Custom Findings view displays the user-defined or custom findings that exist in the currently opened assessment. In this view, you can create, delete, and modify custom findings for the current assessment. When a custom finding is created in the Custom Findings view, the new finding is added to the current assessment, and the assessment metrics update.
  • Views with findings
  • Sources and Sinks view
    The Sources and Sinks view provides the ability to view findings based on a trace of input and output.
  • Share: Email
  • Twitter
  • Disclaimer
  • Privacy
  • Terms of use
  • Cookie Preferences