function readOnly(count){ }
Starting November 20, the site will be set to read-only. On December 4, 2023,
forum discussions will move to the Trailblazer Community.
+ Start a Discussion
johnsmthjohnsmth 

Web Scanner report and Security Review

Hi All,

I have build a application that call some external API in schedule jobs. I want to publish this app as free app on appexchange. From quite a long time I am stucked in clearing security review. I have scanned the API calls using burp tool and it has provided below 2 issues of Information severity.

1. Email addresses disclosed

2. SSL certificate

I do not consider these issues as valid issues. Now submitting app review process require report and false positive documents. My queries are 

1. Will they raise any concerns on above issues
2. What is false positive document. Can any one share a sample document with me.

Thanks
Parul
Deepak Kumar ShyoranDeepak Kumar Shyoran
I think you should have to contact to Salesforce for this issue.
As you need to clear all security issue before and have to summit a fee for AppExchage listing. Salesforce provides support in clearing these security issue and they will help you in your case.
johnsmthjohnsmth
Hi Deepak

Thanks for your response.

My Application is free APP so I believe I do not have to pay any fee. I create a support case with Salesforce support said that we have to fix clear report or otherwise provide false positive document.

I want to know what is false positive document and anyone has sample format of this document.

Regards
Ankur
Deepak Kumar ShyoranDeepak Kumar Shyoran
It's a type a document which required when your app have not clear all security issue related to Salesforce. And you requested Salesforce to pass your App from Security check along with those risk.. may be required for your App like some query inside for loop.