Advanced rescan - validate and accept the version

Introduction

The AIP Super Operator is responsible for validating the source code delivered before accepting the version and proceeding with the configuration and execution of the analysis.

Typically issues at this stage are due to missing files and other deficiencies that result in an incomplete source code delivery. Resolution includes either a request for the missing component or the decision (wherever possible) to proceed with a redefined analysis boundary that excludes the undelivered components.

There are significant differences in the validation process depending on whether the validation pertains to a first time delivery during a new application on-boarding or to a delivery of a new version of the source code of an application previously on-boarded (rescan). Where you are undertaking an application “rescan”, the delivery validation can often be limited to inspecting the log. Examining the delta between two deliveries can help to assess if the changes are expected or are “reasonable” and therefore do not require a partial or full re-qualification and a new on-boarding of the application.

Checks

Check execution message

When all actions have been completed, you should check the Progress window for a “success” message. A success message indicates that the steps have been processed correctly and completed without error. Any other message means that the version has not been added correctly and you should investigate why this is using the logs. Even if you have a “success” message, CAST highly recommends that you also investigate the logs to check for warning messages.

Success
ErrorIf some steps have failed or there are errors, the status message will indicate this:
StoppedIf you manually stop the process the status will also indicate this:

Check status

You should ensure that the status of the version is set to Delivered in the Version Management screen:

Check logs

To check the logs, you can click the View log option in the Progress window for each individual step that has been actioned:

Click to enlarge

The log will be displayed in Summary mode:

Click to enlarge

Switch to Content mode to view the actual log file:

Click to enlarge

Logs can be downloaded to file using the download button while in Content mode:

Click to enlarge

Check source code organization details

Move to the AIP Console screen if you are not already there:

Locate the Application and click it to access the Application - Overview page:

Scroll to the Overview > Source code organization section. The displayed diagram is based on an initial evaluation of the content of your source code delivery and this should be used only to help you validate the delivery.

Check version reports (deliver alerts) and exclusions

To check what has actually been delivered in the version and what has been excluded from analysis, use the Version details page. Move to the AIP Console screen if you are not already there:

Locate the Application and click it to access the Application - Overview page:

Click the Versions icon in the left panel to access the Application - Versions page:

Click the version in the list that you have just delivered and check the reports (this includes information about the files that have been delivered in the source code ZIP file and any delivery alerts that may have been raised). For example:

Click to enlarge

Check extensions

Extensions areautomatically installedfor EVERY single source code Version you deliver - this means that each Version will have a specific set of extensions enabled and installed, tailored to the source code that needs to be analyzed. AIP Console will also automatically install extensions it thinks are required, based on the initial “scan” of the source code uploaded in the ZIP file. You should therefore check to ensure that all the extensions you require are installed using the Included tab in the Application - Extensions screen. If you think additional extensions are required, use the Available tab to add more:

Accepting/Rejecting the delivery

Rejection

When any issue is detected and/or unresolved questions are raised, the analysis process should be halted as the delivery cannot be accepted until these issues are fully resolved. The AIP Super Operator should therefore reject the delivery using the Version details page:

Click to enlarge

Acceptance

Accepting the delivery is a two step process that results in the transfer of the delivered source code into the Deployment folder, and sets the version as “current”, ready for analysis. Use the Version details page to first accept the version:

Click to enlarge

Ensure this action is successful and that the version’s status changes to Accepted:

Click to enlarge

Then set the version as current (i.e. will be used for any subsequent analysis):

Again ensure that the action is successful (the status will remain at Accepted) and that the green icon is displayed for the version indicating that it is now “current”: