fortify / FortifyVulnerabilityExporter

Export Fortify vulnerability data to GitHub, GitLab, SonarQube and more
Other
24 stars 8 forks source link

Add synchronization with external systems like bug trackers #24

Open rsenden opened 3 years ago

rsenden commented 3 years ago

Rationale

We currently provide FortifyBugTrackerUtility (FBTU) for submitting vulnerability data to bug tracking and other external systems. It makes sense to move this functionality to FortifyVulnerabilityExporter (FVE) for various reasons:

Requirements

Compatibility with FBTU is the main requirement for moving bug tracking support to FVE:

Ideas for implementation

Vulnerability loading

Enhance embed processing

Storing export details in SSC/FoD

Vulnerability grouping