Pro Integrations | DefectDojo Documentation

Pro Integrations (Pro)

Availability: Integrations is currently in Beta and is only available for Cloud-hosted DefectDojo Pro instances. On-premise deployments do not yet have the required infrastructure to support Integrations. If you are an on-premise customer interested in this feature, please contact support@defectdojo.com for updates on availability.

Enabling Integrations: On a Cloud instance, a superuser can turn Integrations on from Settings > Feature Flags, where it is listed as Downstream Connections. See Feature Flags. On an on-premise instance it is shown as Unavailable on This Deployment.

DefectDojo Pro’s Integrations let you push your Findings and Finding Groups to ticket tracking systems to easily integrate security remediation with your teams existing development workflow.

Supported Integrations:

Opening the Integrations page

The Integrations page can be found under Settings > Integrations in the sidebar.

Setting up an Integration

An Integrator is configured with three key components:

These components are hierarchical: Each Instance has one or more Mappings, which then have one or more Tracker Assignments.

Pushing Findings and Finding Groups

Once these components are configured, Findings and Finding Groups can be sent to a given Issue Tracker in two ways; manually, or automatically.

Automatically Push Findings

Findings can also be pushed automatically, with the Issue Tracker Assignment dictating how those objects will be pushed. These are the four options:

Push Filters

Each Issue Tracker Assignment can optionally narrow which Findings are pushed automatically:

These filters apply to automatic creation only. Updates to a Finding that already has a linked ticket are always sent, so status changes (including closures) continue to propagate. A manual Push to Integrators always ignores the filters. Leaving both at their defaults preserves the original behavior of pushing every Finding.

Assigning multiple Products

An Issue Tracker Assignment targets a single Product or Engagement. To cover several assets, create one Assignment per Product (or Engagement). If you also need vendor fields to differ per asset — for example a distinct ServiceNow Assignment group or Assigned to, or a different Jira project — create a separate Issue Tracker Mapping (with its own Custom Field Mappings) for each asset and point each Assignment at the matching Mapping.

Issue Tracker Ticket Representation

Issue Tracker Tickets are represented by a series of icons under the “Integrator Tickets” column when viewing and listing Findings and Finding Groups.

Icons from left to right:

Supported Project Integrations

Project Integrations will have varying requirements for how DefectDojo will need to interact with them. This could be in the form of an authentication mechanism, additional fields on a per “project” basis, or severity/status mappings.

For the complete list of requirements, please open the vendor specific pages below:

Error Handling and Debugging

Integrations can produce errors for a variety of reasons such as connectivity, authentication, permissions, etc.. To assist in debugging these errors, each Issue Tracker Mapping has a table of errors that list when the error occurred, the reason it occurred, and the Finding or Finding Group that failed to be pushed.

These errors can be found by looking at the Issue Tracker Mappings & Assignments page, under the ⚠️ Total Errors column.

Clicking on the Total Errors entry will bring you to a page with more detailed descriptions of errors associated with this Integration.