Skip to content

Best way to import findings from periodic scan reports #5021

Answered by damiencarol
tienthanh411 asked this question in Q&A
Discussion options

You must be logged in to vote

First, it's not one but many questions :D

There are monthly automated scans of all products. The scan produces a single report that contains all the vulnerabilities of the products. If a vulnerability has been fixed, it will not be included in the report.

I don't think implementing a new specific parser dedicated to your report format is a good thing. We prefer to stick to the raw format of the security tools.
Most of the users use DefectDojo like this. automated scans that produce reports but most of them use raw data (output from the tools directly) instead of an aggregate. I honestly it's better this way.

Based on my understanding of DefectDojo, writing a custom parser in this case …

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Answer selected by tienthanh411
Comment options

You must be logged in to vote
1 reply
@damiencarol
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants