Codacy Integration with DefectDojo
Codacy Integration with DefectDojo
Codacy is a commercial code quality and code security platform. It runs static analysis on the repositories it is connected to and collects security results in its Security and Risk Management area, where each issue is a security item with a priority, a status, and a due date. Those items come from several underlying scanners, including dependency (SCA), container, and DAST checks, and each one records which detector produced it. Security items are available through the Codacy API v3 as JSON, which is what both DefectDojo integration paths consume.
Codacy Integration with DefectDojo
Our developers already live in Codacy, so we let it keep doing what it does in pull requests and send its security items into DefectDojo, where the rest of our scanner output already is. Each Codacy item becomes a Finding on the Asset for its repository, with its CVE, CWE, CVSS vector, fix versions, and the detector that raised it carried across. Items a developer dismissed in Codacy as false positives arrive already marked that way, so triage done in one place is not redone in the other.
Why Codacy Matters
Codacy sits close to the code, which is where fixes are cheapest.
- It analyzes repositories continuously and reports results in the developer workflow, so security issues are visible before merge.
- Its security items combine results from several scanners, tagged by scan type and by the detector that produced them, such as Trivy or ZAP.
- Each item carries remediation advice and, for vulnerable packages, the versions that fix it.
- Developers can ignore an item with a reason, which records triage decisions at the source.
- A Codacy view is scoped to code. Security teams still need those results next to pentest, cloud, and infrastructure findings, and against SLAs that apply to everything.
Advantages of This Integration
What we get from running Codacy through DefectDojo:
- No duplicate copies between paths. The file parser uses the same scan type as the connector, Codacy - Connectors Import, and the same deduplication settings, so a team that starts with file uploads and later enables the connector keeps one set of findings.
- Identity from Codacy. Deduplication uses Codacy's internal item ID first, then falls back to a hash of title, severity, and vulnerability ID, so repeated imports update the same Finding.
- Triage carries over. An item ignored in Codacy with the reason "false positive" is imported with the false positive flag set. Other ignore reasons, such as accepted risk, are left as real findings for DefectDojo's risk acceptance process.
- Accurate static and dynamic flags. Items with a DAST scan type are marked dynamic; everything else is static.
- Filtering by source scanner. Scan type, security category, and detector are added as tags.
- One SLA model. Codacy priorities map directly to Critical, High, Medium, and Low, so code findings fall under the same SLAs as every other source.
How This Integration Works
There are two supported ways to get Codacy security items into DefectDojo. Both use the Codacy - Connectors Import scan type.
Option 1: JSON file import (Community Edition and DefectDojo Pro). This path exists for environments that cannot give DefectDojo a Codacy API token, such as air-gapped networks or teams waiting on a security review. Export security items as JSON from Codacy's security-items search endpoint in the Codacy API. The parser accepts the API response with its data envelope or a bare array of items. In the UI, open the Engagement, choose Import Scan Results, select Codacy - Connectors Import, and upload the file. To automate it:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Codacy - Connectors Import"
-F "file=@codacy-security-items.json"
-F "product_name=payments-service"
-F "engagement_name=Codacy"
-F "auto_create_context=true"
DefectDojo Pro users can run the same import with Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Codacy - Connectors Import"
--report-path "./codacy-security-items.json"
--product-name "payments-service"
--engagement-name "Codacy"
--auto-create-context
Option 2: Codacy connector (DefectDojo Pro). The connector pulls security items from the Codacy API on a schedule. Configure it with:
https://app.codacy.com/api/v3in the Location field.- A Codacy account API token in the Secret field. A repository (project) token will not work, because Codacy's repository tokens are valid only on its older API version, and the failures look like an invalid key.
- Optionally, a Minimum Severity to limit what is imported.
DefectDojo enumerates every organization the token can see and creates a Record for each repository that has security issues. Repositories with none are not mapped. Only open Security and Risk Management items are imported, so items resolved in Codacy are reflected on the next sync.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Codacy Security Item | Notes |
|---|---|---|
| Title | title |
Falls back to "Codacy scan type - category item", then the item ID |
| Severity | priority |
Critical, High, Medium, Low map directly; anything else becomes Info |
| Description | summary, additionalInfo, plus details |
Adds scan type, category, detector, repository, container image, likelihood, effort to fix, dependency paths |
| Mitigation | remediation, fixedVersion |
Fix versions listed as "Fixed in" |
| References | htmlUrl |
Link back to the item in Codacy |
| Vulnerability IDs | cve |
All CVE IDs found in the field, deduplicated |
| CWE | cwe |
First CWE-<number> found |
| CVSS v3 | cvssVector, cvssScore |
Vector and score |
| Component Name / Version | Last entry of first dependency chain, affectedVersion |
Names the vulnerable package, not the project |
| Endpoint | application or affectedTargets |
Added only when the value is a valid host |
| Date | openedAt |
Today if the timestamp does not parse |
| False Positive | ignored.reason |
Set only when the reason is false positive |
| Tags | scanType, securityCategory, itemSource |
For example SCA, Vulnerability, Trivy |
| Unique ID from tool | id |
Primary deduplication key |
| Vulnerability ID from tool | First CVE, else itemSourceId |
Part of the fallback hash |
| Finding type | scanType |
DAST items dynamic, all others static |
| Deduplication | Unique ID or hashcode | Unique ID from tool, then title, severity, vuln_id_from_tool |
Use Cases
Centralizing code security for many repositories: An organization with dozens of repositories in Codacy enables the connector once. Each repository with security issues becomes a Record mapped to its Asset, and findings refresh on every sync without per-repository pipeline work.
Air-gapped or restricted environments: A team that cannot store a Codacy API token in DefectDojo exports security items on a trusted host and uploads the JSON. If policy later allows the connector, findings already imported deduplicate against the synced ones.
Separating container and dependency work: Tags for scan type and detector let a security lead filter container image findings for the platform team and dependency findings for application owners, while both sit on the same Asset.
Reporting across tools: Codacy findings sit in the same metrics as DAST, pentest, and cloud findings, so leadership sees open Critical and High items per application regardless of which tool found them.
Operational Tips
- Generate an account API token for the connector. Project tokens fail against API v3 with errors that look like a bad key.
- Do not mix scan types. Upload files with Codacy - Connectors Import so file and connector findings deduplicate.
- Record false positives in Codacy with the false positive reason if you want that decision carried into DefectDojo. Other ignore reasons arrive as active findings.
- Use the connector's Minimum Severity, or
minimum_severityon file import, to start with Critical and High while teams adjust. - Filter on tags such as the detector name to route findings to the right team or Jira project.
- If a container image or DAST target is not a valid host, no Endpoint is created, but the value is still in the description.