Govulncheck | DefectDojo Documentation

Govulncheck

JSON vulnerability report generated by govulncheck tool, using a command like govulncheck -json . >> report.json

Govulncheck Scanner V2

A second scan type, Govulncheck Scanner V2, is available for the streaming JSON format (govulncheck -format json ./...). It addresses several limitations of the original parser:

Use the Minimum Severity import option (e.g. High) to keep only the reachable findings, matching the default govulncheck ./... output.

The original Govulncheck Scanner parser is unchanged and remains available.

SARIF format

The Govulncheck Scanner parsers only accept govulncheck’s native JSON output (govulncheck -format json). To import govulncheck’s SARIF output (govulncheck -format sarif), use the generic SARIF scan type instead — not the Govulncheck Scanner scan type. Uploading a SARIF report to a Govulncheck Scanner parser fails with an error pointing you to the SARIF scan type.

Sample Scan Data

Sample Govulncheck scans can be found here.

Default Deduplication Hashcode Fields

By default, DefectDojo identifies duplicate Findings using these hashcode fields: