All integrations

Klocwork Integration with DefectDojo

Klocwork Integration with DefectDojo

Klocwork is a static application security testing (SAST) and code quality tool from Perforce. It analyzes C, C++, C#, Java, JavaScript, Python, Kotlin, and Rust source code for security weaknesses and reliability defects such as null pointer dereferences and resource leaks. Teams typically run it in builds and from IDE plugins, with results collected on a Klocwork Server where issues are reviewed and triaged. Issues can be retrieved through the Klocwork Web API, which returns them as JSON.

Klocwork Integration with DefectDojo

Our embedded and native code goes through Klocwork, and DefectDojo is where those results get compared with everything else we know about the same applications. Klocwork's own review tooling is good at triaging issues within a project. What it doesn't give us is a single place to see Klocwork issues next to SCA, container, and pentest findings, with SLAs and ownership applied the same way. Sending Klocwork issues to DefectDojo, by file or through the DefectDojo Pro connector, does that, and it keeps the triage decisions our developers already made in Klocwork.

Why Klocwork Matters

Memory-unsafe languages still run a lot of critical software, and the defects that matter in C and C++ are hard to spot in review.

  • Klocwork's checkers target defect classes like buffer overruns, null dereferences, and leaks that other scanners in a typical pipeline don't cover.
  • It is built for large codebases and supports differential analysis, so teams can scan often without waiting on a full rebuild of results.
  • Reviewers record triage in Klocwork itself (for example, marking an issue Not a problem), and that knowledge should not be lost downstream.
  • Its severity codes give a clear ordering, as long as whatever consumes them reads the scale the right way round.

Advantages of This Integration

What we gained by routing Klocwork through DefectDojo:

  • Triage carries over. Issues with a Klocwork status of Ignore, Not a problem, or Filter import as inactive false positives. Deferred states such as Defer and Fix in Next Release stay active.
  • Correct severity. Klocwork's severityCode runs from 1 (most severe) upward. The parser maps 1 to Critical, 2 to High, 3 to Medium, 4 to Low, and codes 5 through 10, 0, or a missing code to Info.
  • File and API findings deduplicate together. The file parser uses the same scan type, Klocwork Scan, and the same identity rules as the connector, so a file import and a later API sync produce one set of findings.
  • Stable identity. Deduplication uses the Klocwork issue ID first (klocwork-<id>), then a hash of title, severity, file path, and checker code.
  • SLAs and ownership. Each issue becomes a Finding on an Asset with an owner, a due date by severity, and a status history, and it can be pushed to Jira from there.

How This Integration Works

There are two ways to get Klocwork issues into DefectDojo. Both use the Klocwork Scan scan type.

Option 1: File import (Community Edition and DefectDojo Pro). This path exists for organizations that can't grant DefectDojo API credentials to the Klocwork Server, such as air-gapped networks or environments still waiting on a security review. Save the response of a search request to the Klocwork Web API for the project you want. That response is NDJSON (one JSON object per line), and the parser reads it directly. It also accepts a JSON array of issues, an object with an issues list, or a single issue object. The trailing summary line in the response is skipped, and any row without an id is dropped.

Upload the file in the UI (Engagement, Import Scan Results, Klocwork Scan), or automate it with the API:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Klocwork Scan" 
  -F "file=@klocwork-issues.ndjson" 
  -F "product_name=firmware-core" 
  -F "engagement_name=Static Analysis" 
  -F "auto_create_context=true"

DefectDojo Pro users can run the same import with Universal Importer:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Klocwork Scan" 
  --report-path "./klocwork-issues.ndjson" 
  --product-name "firmware-core" 
  --engagement-name "Static Analysis" 
  --auto-create-context

Option 2: Klocwork connector (DefectDojo Pro). The connector pulls issues from a Klocwork Server on a schedule. Configure it with:

  1. The Klocwork server URL in the Location field.
  2. The Klocwork username the token belongs to in the Username field.
  3. The login token (ltoken), the token generated by kwauth, in the Login Token (ltoken) field. The token is never logged.
  4. Optionally, a Minimum Severity to limit which findings are imported.

DefectDojo enumerates the server's projects and creates a Record for each one, which you map to a DefectDojo Asset. The connector imports only issues Klocwork classes as actionable, and only from each project's latest build, so findings describe the current state of the project.

Data Granularity: What Gets Imported

The table below describes the file parser, which mirrors the connector's field mapping.

DefectDojo Field Source in Klocwork Issue Notes
Title code and name <checker>: <name>, falling back to either alone, then the issue ID
Severity severityCode 1 Critical, 2 High, 3 Medium, 4 Low, anything else Info
Description message, code, method, taxonomyName, status Labeled lines, empty values skipped
File Path file Part of the dedupe hash
Line line Set when present
Date dateOriginated Read as Unix milliseconds
References url The issue's Klocwork review URL
Vulnerability ID from Tool code The checker code
Unique ID from Tool id Stored as klocwork-<id>
Tags taxonomyName, code, severity Added as Finding tags
Active / False Positive status Ignore, Not a problem, Filter become inactive false positives
Finding type Static All Klocwork findings are static
Deduplication Unique ID or hashcode Unique ID first, else title, severity, file path, checker code

Numeric fields are accepted whether they arrive as JSON numbers or quoted strings.

Use Cases

For embedded and native code teams: A team building device firmware scans each release branch in Klocwork. The connector syncs the latest build of each project, so DefectDojo shows the current open issues per product line alongside third-party component findings for the same firmware.

In an air-gapped environment: A defense or industrial team can't connect DefectDojo to the Klocwork Server. They export search results inside the enclave, move the NDJSON file across, and import it. When connectivity is approved later, the connector picks up the same findings without creating duplicates.

For security leadership reporting: Klocwork issues share SLA rules and metrics with the rest of the scanners, so a security lead can report open Critical and High static analysis issues by Asset without exporting from a separate review tool.

When developers triage in Klocwork: Developers keep marking issues in Klocwork's review interface. Those marked Not a problem arrive in DefectDojo as false positives, so the security team doesn't redo work the code owners already did.

Operational Tips

  • Decide whether code 5 through 10 issues matter to you. They import as Info, and minimum_severity (or the connector's Minimum Severity) can keep them out entirely.
  • Use one connector Record or one Test per Klocwork project, so findings for different codebases don't mix on the same Asset.
  • Remember the same checker in two files is two findings, because file path is part of the hash.
  • Use a dedicated Klocwork account for the connector's login token, so automated access is easy to audit and revoke.
  • Deferred issues stay active on purpose. If your team agrees a deferred issue is acceptable for now, record that with a time-limited risk acceptance in DefectDojo.
  • If you start with file imports and later switch to the connector, keep the same Asset. Matching scan type and identity rules let the two sources merge.