Veracode | DefectDojo Documentation
Veracode
Veracode reports can be ingested in either XML or JSON Format
- Detailed XML Report
- JSON REST Findings from
/appsec/v2/applications/{application_guid}/findings/- Acceptable scan types include
STATIC,DYNAMIC, andSCA - Findings with a status of
CLOSEDwill not be imported into DefectDojo - Acceptable formats are as follows:
- Findings list
- Requires slight modification of the response returned from the API
- Example of a request being:
url <endpoint> | jq "{findings}" - Desired Format:
- Findings list
- Acceptable scan types include
{
"findings": [\
{\
...\
},\
...\
]
}
```
- Embedded
- This response can be saved directly to a file and uploaded
- Not as ideal for crafting a refined report consisting of multiple requests
- Desired Format:
```json
{
"_embedded": {
"findings": [\
{\
...\
},\
...\
]
},
"_links": {
...
},
"page": {
...
}
}
```
### Sample Scan Data
Sample Veracode scans can be found [here](https://github.com/DefectDojo/django-DefectDojo/tree/master/unittests/scans/veracode).
### Default Deduplication Hashcode Fields
By default, DefectDojo identifies duplicate Findings using these [hashcode fields](https://docs.defectdojo.com/en/working_with_findings/finding_deduplication/about_deduplication/):
- title
- cwe
- line
- file path
- description