Configure an open source scan in AppScan on Cloud

Procedure

To configure a scan:
  1. Identify what you will scan:
  2. If you will be scanning an IRX file, download and set up either:
  3. Scan or generate an IRX file for your application, or identify source code files to scan.
    1. To generate an IRX file by using the CLI, follow the instructions in Generating an IRX file by using the command line interface (CLI). You can scan all supported languages from the CLI.
      Note:
      To scan open source only, use the -oso command with appscan prepare.
    2. To scan in IntelliJ IDEA or Visual Studio, follow the instructions in Scanning in integrated development environments. In IntelliJ IDEA, you can scan Java projects - and in Visual Studio, you can scan .NET (C#, ASP.NET, VB.NET).
    3. To generate an IRX file using AppScan Go!, follow the instructions in Configuring a scan using AppScan Go!.
    4. To scan a source code file, identify the appropriate .zip, .war, .jar, or .ear file.
      Note:
      Source code files that are not .war, .jar, or .ear files must be compressed into a .zip file. If a .zip includes .git metadata (a GitHub repository), AppScan on Cloud supports one repository (.git file) per scan.
    Note:
    When you scan code or generate an IRX file, you might receive a message about updating to the latest Static Analyzer Command Line Utility. See Command Line Utility (CLI) support.
  4. If you have not yet done so: Create an application for your scans.
  5. Use the Create scan wizard to start configuring your scan. Start the wizard from Application > Application > Scans > Create scan > SCA Software Composition Analysis > Create scan.