CxAnalytix is a background process that crawls Checkmarx SAST, OSA, and Management & Orchestration APIs to obtain data about vulnerabilities. The data is then flattened into a JSON format with the intent to be forwarded to a data analytics platform for analysis. Analysis can be performed on the data alone or in aggregate with other sources of data.
The fields available in generated documents can be found in the specification.
CxAnalytix is built on .Net Core and is therefore capable of running on Windows or Linux.
There are several installation variations:
- A Windows service
- A Linux daemon
- A command line executable
Please refere to the Installation wiki page
Please see the CxAnalytix Wiki for information related to obtaining, installing, and configuring CxAnalytix.
- 1.1.4
- FEATURES
- Added EngineStart/EngineFinished fields to the scan summary; no-change scans will be indicated with DateTime.MinValue
- BUG FIXES
- Issue #20: Date parsing error in non-US locale
- FEATURES
- 1.1.3
- BUG FIXES
- Issue #18: Error when attempting to retrieve policy violation data from SAST 9.0
- BUG FIXES
- 1.1.2
- FEATURES
- Dockerfile now available as a release artifact
- Docker base image pushed to Docker Hub as part of the build
- FEATURES
- 1.1.1
- FEATURES
- Issue #9: Resolve config values from environment variables (see the Wiki for CxConnection, CxCredentials, and CxAnalyticsService)
- BUG FIXES
- Issue #6: Now compatible with SAST 9.0
- FEATURES
- 1.1.0
- FEATURES
- Issue #4: MongoDB is now available as an output destination.
- Issue #5: Add instance identifier to each record.
- Issue #7: Add project custom fields to the output.
- FEATURES
- 1.0.0
- Initial Release
- FEATURES
- Output to flat log files
- Support for CxSAST 8.9 APIs
We appreciate feedback and contribution to this repo! Before you get started, please see the following:
Include information on how to get support. Consider adding:
- Use Issues for code-level support
- For installation assistance, schedule time with the Checkmarx Professional Services team
Project License can be found here