- New vulnerabilities: when a new vulnerability affects a project library, Veracode sends
VULN_ISSUES_DISCOVERED_AFTER_SCANand Flashduty triggers one alert for each issue in it. - Updated or resolved vulnerabilities: Veracode sends
VULN_ISSUES_CHANGED_AFTER_SCAN; when the issue status isRESOLVED, the matching alert recovers. - Scan success:
SCAN_SUCCESSis only a scan summary. Flashduty acknowledges it and creates nothing.
In Flashduty On-call
Get the integration push URL in either of the following ways.
Dedicated integration
- In the Flashduty console, go to Channels and open a channel
- Go to Settings → Integrations → Dedicated integration and click Add an integration
- Select Veracode SCA and click Save
- Open the integration card and copy the push URL
Shared integration
- In the Flashduty console, go to Integration Center → Alert events
- Select Veracode SCA and enter a name
- Set the default route and pick a channel; you can add more rules under Routes later
- Click Save and copy the push URL
In Veracode
Webhooks are configured per project. You need the Security Lead, Workspace Administrator, or Workspace Editor role.
1
Create the webhook
- Sign in to Veracode SCA and open the project to monitor
- Go to Settings → Notifications → Actions → Create
- Paste the full Flashduty push URL, including
integration_key, as the Payload URL
2
Select the trigger events
Select:
- Vulnerability issues discovered in project library after a scan: a new vulnerability appears
- Vulnerability issues changed in project library after a scan: an existing vulnerability is updated, including when its status becomes resolved
3
Verify
The Veracode documentation does not describe a test button for webhooks. When a new vulnerability is disclosed or one is resolved, confirm that the matching alert appears or recovers in Flashduty.
Events and recovery
One delivery can carry several issues. Flashduty processes them in issue id order, at most 200 issues per delivery; the rest are ignored.
Alert Key
The Alert Key is computed from the project id (
project.id) and the issue id (issues[].id). In the Veracode documentation examples, the same issue has the same id in the discovered and changed events, so the recovery lands on the same alert. Changes to the vulnerability title, score, or project name do not change the Alert Key. A delivery without project.id, issues[].id, or issues[].status is rejected, and the error names the missing field.
Severity
The Veracode payload carries no severity, so Flashduty maps the vulnerability’s CVSS score, using the CVSS v3 score and falling back to the CVSS v2 score:
On recovery the status becomes Ok and the severity stays at the last severity.
Labels
Flashduty does not keep the organization and user information in the payload.
Troubleshooting
- Veracode fails to save the webhook: confirm the push URL is reachable from the internet and includes
integration_key - Flashduty returns an invalid-parameter error: the message names the missing field or the unsupported event
- An alert never recovers: it recovers only when the project webhook has the changed event selected and the issue status becomes
RESOLVED,FIXED, orIGNORED. Whether Veracode sends that event when a vulnerable library is removed from dependencies depends on what Veracode actually sends