Kiuwan Integration with DefectDojo
Kiuwan is a comprehensive application security platform that combines static application security testing (SAST), software composition analysis (SCA), and code quality analysis to identify security vulnerabilities, insecure open-source components, license compliance risks, and code quality issues across 30+ programming languages including legacy systems throughout the software development lifecycle. The platform integrates seamlessly into CI/CD workflows and development environments including IDEs, GitHub, Jenkins, and JIRA to deliver automated security scanning with prioritized remediation guidance, compliance reporting aligned with OWASP, CWE, PCI-DSS, and other standards, enabling development teams to proactively address security risks from code to production.
Data Granularity: What Gets Imported
The following fields are captured from Kiuwan results and surfaced in DefectDojo findings:
| Field | Source | Notes |
|---|---|---|
| Title | Finding name from the scan | Matched to the tool's own naming |
| Severity | Critical / High / Medium / Low / Info | Mapped from the tool's own severity scale |
| Description | Finding detail from the report | Includes what the issue is and why it matters |
| Mitigation | Remediation guidance | Where the tool provides it |
Importing Into DefectDojo
Use the DefectDojo import API to create a new Test under the relevant Engagement for your product. The request body:
{
"scan_type": "Kiuwan",
"engagement": "<engagement-id>",
"file": "results.json"
}