DefectDojo / django-DefectDojo

DevSecOps, ASPM, Vulnerability Management. All on one platform.

Home Page:https://defectdojo.com

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Not Able to import all vulnerabilites from the security tools after integration with the defect dojo

Nsai1997 opened this issue · comments

commented

2.We have integrated the Defect dojo with the below tools

2.1.SonarQube :When we integrated the Defect dojo with the sonarQube tool (its tool to tool integration via API import).When we tried importing the vulnerabilites/Security hotspots/Code smells/Bugs out of more than
100 issues only 3 got imported.

So after integration not all vulnerabilities are getting imported after integration in this release.

image

The below is the configuration set. Please suggest the changes if required

image

For the other integrated tools

Integrated Tools: Vulnerabilities imported from ADO pipelines, including Dependency Check, Trivy Scan, and Trivy Image Scan, are not consistently imported after integration. Only few of the vulnerabilities are getting imported. But for the same configuration we are able to import all vulnerabilities for the below tools in the earlier release

2.2.Dependency check
2.3.Trivy scan
2.4.Trivy Image scan

These issues hinder the effectiveness and functionality of our integration and require immediate attention to ensure seamless operation.

Best regards
sai