Skip to content

docs(connectors): Fortify connector reference#15329

Draft
devGregA wants to merge 1 commit into
DefectDojo:bugfixfrom
devGregA:sc_fortify_docs
Draft

docs(connectors): Fortify connector reference#15329
devGregA wants to merge 1 commit into
DefectDojo:bugfixfrom
devGregA:sc_fortify_docs

Conversation

@devGregA

Copy link
Copy Markdown
Contributor

What

Adds the Fortify connector to the Pro connector tool reference. Fortify (OpenText/Micro Focus) is an enterprise SAST/DAST platform; the connector imports issues from both editions — SSC (self-hosted) and Fortify on Demand (SaaS) — mapping each application (project version / release) to a product and each issue to a finding.

Companion to:

  • DefectDojo-Inc/connectors#751 (the Go connector)
  • DefectDojo-Inc/dojo-pro#1996 (Pro-UI registration)

Section covers

  • Prerequisites: an SSC FortifyToken, or an FoD OAuth Client ID + Secret.
  • Connector mappings: Location (SSC host / FoD region host), Edition SSC/FoD, FoD Client ID, Token / Client Secret, optional Minimum Severity.
  • Mapping model: application → Record; issue → finding — severity from Fortify's friority, title (category + file:line), file/line, kingdom/analyzer/engine, static vs dynamic by engine, suppressed/removed/hidden skipped, "Not an Issue" → false positive, "Exploitable"/reviewed → verified.

Live validation needs an SSC or FoD instance (NFR/eval, no free tier); details in connectors#751 (outstanding follow-up).

Base: bugfix.

Document the Fortify connector (SSC + FoD): prerequisites (FortifyToken /
FoD OAuth), the Location/Edition/Client-ID/Secret/Minimum-Severity mappings,
and the whole-account application -> Record + issue -> finding model
(friority severity, title, file/line, static vs dynamic by engine, audit
status).

Companion to connectors#751 and dojo-pro#1996.

sc-13875

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actions github-actions Bot added the docs label Jul 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant