Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Excluding Security Hotspots During SonarQube API Vulnerability Import into Defect Dojo #9785

Closed
sametr35 opened this issue Mar 19, 2024 · 6 comments

Comments

@sametr35
Copy link

Hello,

I've been able to exclude bugs and code smells when importing SonarQube vulnerabilities with API into Defect Dojo, which is great. However, I'm encountering difficulty in excluding security hotspots. Is there a way to exclude them as well? Thank you for your assistance.

@dsever
Copy link
Contributor

dsever commented Mar 19, 2024

@sametr35
Copy link
Author

Yes, In the documentation. I could not see anything about security hotspot exclusion.

@dsever
Copy link
Contributor

dsever commented Mar 20, 2024

Yes, In the documentation. I could not see anything about security hotspot exclusion.

I have to dive into the code, I was implementing it 2 year ago :)

@KarthikY18
Copy link

Any Update on this?

@sametr35
Copy link
Author

Hi @KarthikY18, Security Hotspots are generally of low severity. When importing issues please choose minimum severity=medium, Security Hotspots will not be included. If you need to include low severity issues, there is currently no solution for that. You will see security hotspots.

@KarthikY18
Copy link

Thank you @sametr35, this helps me.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants