Scan Your Managed Package with Salesforce Code Analyzer
As an ISV partner submitting your managed package for security review, you must scan it with the Salesforce Code Analyzer and provide test results in your solution’s AgentExchange Security Review submission. This scan is in addition to the scan that you must complete using the Source Code Scanner, also referred to as the Checkmarx scanner.
Before You Begin
User Permissions Needed
To access the Partner Community, Partner Console, and AgentExchange Security Review:
Manage Listings
When you submit your code and scan report to the AgentExchange Security Review, it’s not necessary for the scans to be 100% passing. The main requirement is that you run the scans, address all the violations you can fix, re-run the scans, and then submit the report. Some violations, like false positives, may not be fixable. The AgentExchange Security team understands these situations and adjusts their review accordingly.
Upload your clean CodeAnalyzerReport.html file to your security-review submission.
If you have false-positive documentation, upload that too.
Next Steps
If you’re unable to run the Code Analyzer CLI commands successfully, read the Salesforce Code Analyzer documentation. If you still need help, log an issue in the Salesforce Code Analyzer GitHub repository, and provide information about the errors that you encountered when generating the scan report for your security-review submission.