
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Everyone,
I've been using Fortify for a bit now, I know that SCA can scan iOS and Android apps by translating the code for SCA, but I don0t know if I can translate the Xamarin code. This is a client requeriment, they have coded their app using Xamarin with VS IDE, I know that the SCA plug in for VS works well, but we haven't tried with Xamarin yet, so My question is: Can we scan that code normally or there are some additional configurations we should do in order to scan their app?
Thanks in advance.
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Yes, you can.
And on FoD you can use the Mobile+, that includes a manual review for your apps and a DAST scan for your backend. Please, check the two papers below:
https://www.microfocus.com/media/data-sheet/fortify_on_demand_ds.pdf
Data, or do not.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Yes, you can scan this type of projects using msbuild integration for translate phase, check the SCA Guide on page 78: https://www.microfocus.com/documentation/fortify-static-code-analyzer-and-tools/1820/SCA_Guide_18.20.pdf
Try it and come back to tell us what you get.
Data, or do not.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Raphael,
We've tried and it works! Now, can we make the same type of scans in Dortify On Demand? For xamarin app code I mean. Our client is looking forward for the On Demand scheme, so now we are wondering our selves if we can buy assessment units for FoD and run the scan there and compare it with the one we've run with SCA. It's posible to do it like that?
Thanks!

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Yes, you can.
And on FoD you can use the Mobile+, that includes a manual review for your apps and a DAST scan for your backend. Please, check the two papers below:
https://www.microfocus.com/media/data-sheet/fortify_on_demand_ds.pdf
Data, or do not.