Publishing assessments to AppScan Source

You can publish assessments to the AppScan® Source Database for the purpose of storing and sharing assessments.

About this task

Important: This topic applies only if you have upgraded to AppScan Source version 10.0.2 or higher from a 10.0.1 or earlier version of the product. New installations of AppScan Source version 10.0.2 publish to AppScan Enterprise only.

Applications and projects must be registered with AppScan Source before assessments of them can be published. See Registering applications and projects for publishing to AppScan Source for more information. By default, if you attempt to publish an assessment of unregistered applications or projects, you will be prompted to register the applications or projects at that time (which requires Register permission).

Note: Assessments that are created as a result of scanning individual files cannot be published.
Restriction: When you scan multiple applications or projects, a parent node containing assessments for each scanned item is created in the My Assessments view. The individual child assessments cannot be managed in this case (for example, the child assessments cannot be removed or published individually). When multiple applications or projects are scanned at the same time, you can only manage the assessments as a group (the parent node).

Procedure

  1. To publish the assessment that is currently open in the Triage perspective, select File > Publish Assessment to AppScan Source in the main workbench menu.
  2. To publish an assessment in the My Assessments view, select it and click the view's Publish Assessment to AppScan Source button - or right-click the assessment and select Publish Assessment to AppScan Source.

Results

When saving an assessment, AppScan Source for Analysis writes absolute paths to the assessment file to reference items such as source files. These absolute paths may cause difficulty in sharing the file on another computer that has a different directory structure. To be able to create portable assessment files, you should create a variable (see Defining variables or Defining variables when publishing and saving).

Once published, the assessment listed in the My Assessments view will have an icon in the Published column. In addition, the assessment will appear in the Published Assessments view, which is a filter-driven view of assessments published to the AppScan Source Database. This view can be set to display only the assessments that match the filter criteria. For example, if 1,000 assessments are published, and you only want to view the assessments that you published, you could create a filter with By Publisher as the criteria and Current User or your user name as the value.