Klocwork Integration with DefectDojo
Klocwork Integration with DefectDojo
Klocwork is a static application security testing (SAST) and code quality tool from Perforce. It analyzes C, C++, C#, Java, JavaScript, Python, Kotlin, and Rust source code for security weaknesses and reliability defects such as null pointer dereferences and resource leaks. Teams typically run it in builds and from IDE plugins, with results collected on a Klocwork Server where issues are reviewed and triaged. Issues can be retrieved through the Klocwork Web API, which returns them as JSON.
Klocwork Integration with DefectDojo
Our embedded and native code goes through Klocwork, and DefectDojo is where those results get compared with everything else we know about the same applications. Klocwork's own review tooling is good at triaging issues within a project. What it doesn't give us is a single place to see Klocwork issues next to SCA, container, and pentest findings, with SLAs and ownership applied the same way. Sending Klocwork issues to DefectDojo, by file or through the DefectDojo Pro connector, does that, and it keeps the triage decisions our developers already made in Klocwork.
Why Klocwork Matters
Memory-unsafe languages still run a lot of critical software, and the defects that matter in C and C++ are hard to spot in review.
- Klocwork's checkers target defect classes like buffer overruns, null dereferences, and leaks that other scanners in a typical pipeline don't cover.
- It is built for large codebases and supports differential analysis, so teams can scan often without waiting on a full rebuild of results.
- Reviewers record triage in Klocwork itself (for example, marking an issue Not a problem), and that knowledge should not be lost downstream.
- Its severity codes give a clear ordering, as long as whatever consumes them reads the scale the right way round.
Advantages of This Integration
What we gained by routing Klocwork through DefectDojo:
- Triage carries over. Issues with a Klocwork status of
Ignore,Not a problem, orFilterimport as inactive false positives. Deferred states such asDeferandFix in Next Releasestay active. - Correct severity. Klocwork's
severityCoderuns from 1 (most severe) upward. The parser maps 1 to Critical, 2 to High, 3 to Medium, 4 to Low, and codes 5 through 10, 0, or a missing code to Info. - File and API findings deduplicate together. The file parser uses the same scan type, Klocwork Scan, and the same identity rules as the connector, so a file import and a later API sync produce one set of findings.
- Stable identity. Deduplication uses the Klocwork issue ID first (
klocwork-<id>), then a hash of title, severity, file path, and checker code. - SLAs and ownership. Each issue becomes a Finding on an Asset with an owner, a due date by severity, and a status history, and it can be pushed to Jira from there.
How This Integration Works
There are two ways to get Klocwork issues into DefectDojo. Both use the Klocwork Scan scan type.
Option 1: File import (Community Edition and DefectDojo Pro). This path exists for organizations that can't grant DefectDojo API credentials to the Klocwork Server, such as air-gapped networks or environments still waiting on a security review. Save the response of a search request to the Klocwork Web API for the project you want. That response is NDJSON (one JSON object per line), and the parser reads it directly. It also accepts a JSON array of issues, an object with an issues list, or a single issue object. The trailing summary line in the response is skipped, and any row without an id is dropped.
Upload the file in the UI (Engagement, Import Scan Results, Klocwork Scan), or automate it with the API:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Klocwork Scan"
-F "file=@klocwork-issues.ndjson"
-F "product_name=firmware-core"
-F "engagement_name=Static Analysis"
-F "auto_create_context=true"
DefectDojo Pro users can run the same import with Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Klocwork Scan"
--report-path "./klocwork-issues.ndjson"
--product-name "firmware-core"
--engagement-name "Static Analysis"
--auto-create-context
Option 2: Klocwork connector (DefectDojo Pro). The connector pulls issues from a Klocwork Server on a schedule. Configure it with:
- The Klocwork server URL in the Location field.
- The Klocwork username the token belongs to in the Username field.
- The login token (
ltoken), the token generated bykwauth, in the Login Token (ltoken) field. The token is never logged. - Optionally, a Minimum Severity to limit which findings are imported.
DefectDojo enumerates the server's projects and creates a Record for each one, which you map to a DefectDojo Asset. The connector imports only issues Klocwork classes as actionable, and only from each project's latest build, so findings describe the current state of the project.
Data Granularity: What Gets Imported
The table below describes the file parser, which mirrors the connector's field mapping.
| DefectDojo Field | Source in Klocwork Issue | Notes |
|---|---|---|
| Title | code and name |
<checker>: <name>, falling back to either alone, then the issue ID |
| Severity | severityCode |
1 Critical, 2 High, 3 Medium, 4 Low, anything else Info |
| Description | message, code, method, taxonomyName, status |
Labeled lines, empty values skipped |
| File Path | file |
Part of the dedupe hash |
| Line | line |
Set when present |
| Date | dateOriginated |
Read as Unix milliseconds |
| References | url |
The issue's Klocwork review URL |
| Vulnerability ID from Tool | code |
The checker code |
| Unique ID from Tool | id |
Stored as klocwork-<id> |
| Tags | taxonomyName, code, severity |
Added as Finding tags |
| Active / False Positive | status |
Ignore, Not a problem, Filter become inactive false positives |
| Finding type | Static | All Klocwork findings are static |
| Deduplication | Unique ID or hashcode | Unique ID first, else title, severity, file path, checker code |
Numeric fields are accepted whether they arrive as JSON numbers or quoted strings.
Use Cases
For embedded and native code teams: A team building device firmware scans each release branch in Klocwork. The connector syncs the latest build of each project, so DefectDojo shows the current open issues per product line alongside third-party component findings for the same firmware.
In an air-gapped environment: A defense or industrial team can't connect DefectDojo to the Klocwork Server. They export search results inside the enclave, move the NDJSON file across, and import it. When connectivity is approved later, the connector picks up the same findings without creating duplicates.
For security leadership reporting: Klocwork issues share SLA rules and metrics with the rest of the scanners, so a security lead can report open Critical and High static analysis issues by Asset without exporting from a separate review tool.
When developers triage in Klocwork: Developers keep marking issues in Klocwork's review interface. Those marked Not a problem arrive in DefectDojo as false positives, so the security team doesn't redo work the code owners already did.
Operational Tips
- Decide whether code 5 through 10 issues matter to you. They import as Info, and
minimum_severity(or the connector's Minimum Severity) can keep them out entirely. - Use one connector Record or one Test per Klocwork project, so findings for different codebases don't mix on the same Asset.
- Remember the same checker in two files is two findings, because file path is part of the hash.
- Use a dedicated Klocwork account for the connector's login token, so automated access is easy to audit and revoke.
- Deferred issues stay active on purpose. If your team agrees a deferred issue is acceptable for now, record that with a time-limited risk acceptance in DefectDojo.
- If you start with file imports and later switch to the connector, keep the same Asset. Matching scan type and identity rules let the two sources merge.