Replies: 4 comments 6 replies
-
Yes, I am looking for the same. Snyk SCA data digests easily into Dojo, but SAST (snykcode) isn't readable by DefectDojo. |
Beta Was this translation helpful? Give feedback.
-
One of the ways this happens is someone who currently has access to that tool provides a sample file - without an example of the tools output, it's not possible to write a parser. As it seems that @botbuckle and @upatel2227 have access to the output from synkcode, could one of you provide a sample file of a scan of some open source repo? |
Beta Was this translation helpful? Give feedback.
-
Hello @mtesauro Thanks for the reply, I will try to upload some sample docs shortly after I get it. |
Beta Was this translation helpful? Give feedback.
-
Hi @botbuckle, the following issue tracks the progress to advance this parser: #9270 |
Beta Was this translation helpful? Give feedback.
-
We kindly urge the inclusion or enhancement of a feature within DefectDojo to facilitate the direct import of Snyk SAST data, complementing the existing support for Snyk SCA data. This addition would enable organizations to seamlessly consolidate both Snyk SAST and SCA findings, providing a comprehensive view of application security. By expanding the integration's capabilities, we can enhance vulnerability management and empower teams to address security issues more comprehensively. Your consideration of this enhancement is greatly appreciated by the security community.
Beta Was this translation helpful? Give feedback.
All reactions