All integrations

Codacy Integration with DefectDojo

Codacy Integration with DefectDojo

Codacy is a commercial code quality and code security platform. It runs static analysis on the repositories it is connected to and collects security results in its Security and Risk Management area, where each issue is a security item with a priority, a status, and a due date. Those items come from several underlying scanners, including dependency (SCA), container, and DAST checks, and each one records which detector produced it. Security items are available through the Codacy API v3 as JSON, which is what both DefectDojo integration paths consume.

Codacy Integration with DefectDojo

Our developers already live in Codacy, so we let it keep doing what it does in pull requests and send its security items into DefectDojo, where the rest of our scanner output already is. Each Codacy item becomes a Finding on the Asset for its repository, with its CVE, CWE, CVSS vector, fix versions, and the detector that raised it carried across. Items a developer dismissed in Codacy as false positives arrive already marked that way, so triage done in one place is not redone in the other.

Why Codacy Matters

Codacy sits close to the code, which is where fixes are cheapest.

  • It analyzes repositories continuously and reports results in the developer workflow, so security issues are visible before merge.
  • Its security items combine results from several scanners, tagged by scan type and by the detector that produced them, such as Trivy or ZAP.
  • Each item carries remediation advice and, for vulnerable packages, the versions that fix it.
  • Developers can ignore an item with a reason, which records triage decisions at the source.
  • A Codacy view is scoped to code. Security teams still need those results next to pentest, cloud, and infrastructure findings, and against SLAs that apply to everything.

Advantages of This Integration

What we get from running Codacy through DefectDojo:

  • No duplicate copies between paths. The file parser uses the same scan type as the connector, Codacy - Connectors Import, and the same deduplication settings, so a team that starts with file uploads and later enables the connector keeps one set of findings.
  • Identity from Codacy. Deduplication uses Codacy's internal item ID first, then falls back to a hash of title, severity, and vulnerability ID, so repeated imports update the same Finding.
  • Triage carries over. An item ignored in Codacy with the reason "false positive" is imported with the false positive flag set. Other ignore reasons, such as accepted risk, are left as real findings for DefectDojo's risk acceptance process.
  • Accurate static and dynamic flags. Items with a DAST scan type are marked dynamic; everything else is static.
  • Filtering by source scanner. Scan type, security category, and detector are added as tags.
  • One SLA model. Codacy priorities map directly to Critical, High, Medium, and Low, so code findings fall under the same SLAs as every other source.

How This Integration Works

There are two supported ways to get Codacy security items into DefectDojo. Both use the Codacy - Connectors Import scan type.

Option 1: JSON file import (Community Edition and DefectDojo Pro). This path exists for environments that cannot give DefectDojo a Codacy API token, such as air-gapped networks or teams waiting on a security review. Export security items as JSON from Codacy's security-items search endpoint in the Codacy API. The parser accepts the API response with its data envelope or a bare array of items. In the UI, open the Engagement, choose Import Scan Results, select Codacy - Connectors Import, and upload the file. To automate it:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Codacy - Connectors Import" 
  -F "file=@codacy-security-items.json" 
  -F "product_name=payments-service" 
  -F "engagement_name=Codacy" 
  -F "auto_create_context=true"

DefectDojo Pro users can run the same import with Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Codacy - Connectors Import" 
  --report-path "./codacy-security-items.json" 
  --product-name "payments-service" 
  --engagement-name "Codacy" 
  --auto-create-context

Option 2: Codacy connector (DefectDojo Pro). The connector pulls security items from the Codacy API on a schedule. Configure it with:

  1. https://app.codacy.com/api/v3 in the Location field.
  2. A Codacy account API token in the Secret field. A repository (project) token will not work, because Codacy's repository tokens are valid only on its older API version, and the failures look like an invalid key.
  3. Optionally, a Minimum Severity to limit what is imported.

DefectDojo enumerates every organization the token can see and creates a Record for each repository that has security issues. Repositories with none are not mapped. Only open Security and Risk Management items are imported, so items resolved in Codacy are reflected on the next sync.

Data Granularity: What Gets Imported

DefectDojo Field Source in Codacy Security Item Notes
Title title Falls back to "Codacy scan type - category item", then the item ID
Severity priority Critical, High, Medium, Low map directly; anything else becomes Info
Description summary, additionalInfo, plus details Adds scan type, category, detector, repository, container image, likelihood, effort to fix, dependency paths
Mitigation remediation, fixedVersion Fix versions listed as "Fixed in"
References htmlUrl Link back to the item in Codacy
Vulnerability IDs cve All CVE IDs found in the field, deduplicated
CWE cwe First CWE-<number> found
CVSS v3 cvssVector, cvssScore Vector and score
Component Name / Version Last entry of first dependency chain, affectedVersion Names the vulnerable package, not the project
Endpoint application or affectedTargets Added only when the value is a valid host
Date openedAt Today if the timestamp does not parse
False Positive ignored.reason Set only when the reason is false positive
Tags scanType, securityCategory, itemSource For example SCA, Vulnerability, Trivy
Unique ID from tool id Primary deduplication key
Vulnerability ID from tool First CVE, else itemSourceId Part of the fallback hash
Finding type scanType DAST items dynamic, all others static
Deduplication Unique ID or hashcode Unique ID from tool, then title, severity, vuln_id_from_tool

Use Cases

Centralizing code security for many repositories: An organization with dozens of repositories in Codacy enables the connector once. Each repository with security issues becomes a Record mapped to its Asset, and findings refresh on every sync without per-repository pipeline work.

Air-gapped or restricted environments: A team that cannot store a Codacy API token in DefectDojo exports security items on a trusted host and uploads the JSON. If policy later allows the connector, findings already imported deduplicate against the synced ones.

Separating container and dependency work: Tags for scan type and detector let a security lead filter container image findings for the platform team and dependency findings for application owners, while both sit on the same Asset.

Reporting across tools: Codacy findings sit in the same metrics as DAST, pentest, and cloud findings, so leadership sees open Critical and High items per application regardless of which tool found them.

Operational Tips

  • Generate an account API token for the connector. Project tokens fail against API v3 with errors that look like a bad key.
  • Do not mix scan types. Upload files with Codacy - Connectors Import so file and connector findings deduplicate.
  • Record false positives in Codacy with the false positive reason if you want that decision carried into DefectDojo. Other ignore reasons arrive as active findings.
  • Use the connector's Minimum Severity, or minimum_severity on file import, to start with Critical and High while teams adjust.
  • Filter on tags such as the detector name to route findings to the right team or Jira project.
  • If a container image or DAST target is not a valid host, no Endpoint is created, but the value is still in the description.