Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Defect Dojo integration #1907

Open
1 of 6 tasks
tarrinho opened this issue Jan 26, 2024 · 1 comment
Open
1 of 6 tasks

Defect Dojo integration #1907

tarrinho opened this issue Jan 26, 2024 · 1 comment
Assignees
Labels
enhancement New feature or request needs-triage Indicates that issue is not yet triaged and assigned

Comments

@tarrinho
Copy link

Additional context
Defect dojo is an aggregator repository of vulnerabilities and it would be interesting to have an integration between ThreatMapper and it.

Describe the solution you'd like
The main goal would be to have vulnerabilities detected by Threat mapper and injected into Defect dojo (https://owasp.org/www-project-defectdojo/) where they could be correlated with other tools.

Describe alternatives you've considered
Instead of an integration, a simple extraction of information from Threat mapper could be enough. It could be just a standard extraction of data in CSV or JSON.

Components/Services

  • UI/Frontend
  • API/Backend
  • Agent
  • Deployment/YAMLs
  • CI/CD Integration
  • Other (specify)

Additional context
List of Defect Dojo integration: https://www.defectdojo.com/integrations

@tarrinho tarrinho added enhancement New feature or request needs-triage Indicates that issue is not yet triaged and assigned labels Jan 26, 2024
@shyam-dev
Copy link
Contributor

Hello @tarrinho -- Thank you for raising this request. Do feel free to submit patches if you have any handy.

Do note that while we get to roll out this feature, if defect dojo already has a HTTP endpoint readily available, ThreatMapper can send data to that HTTP endpoint.

Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request needs-triage Indicates that issue is not yet triaged and assigned
Projects
None yet
Development

No branches or pull requests

3 participants