Qwiet AI Integration with DefectDojo
Qwiet AI Integration with DefectDojo
Qwiet AI, formerly ShiftLeft and now part of the Harness platform, is an application security product that analyzes code and its dependencies. Its preZero platform reports static code findings (SAST), open source dependency findings (SCA), and secrets, and it adds a reachability signal that indicates whether an attacker-controlled data flow actually connects application input to the vulnerable code. Findings are available per application through the Qwiet API as JSON, which is also the format of a findings export.
Qwiet AI Integration with DefectDojo
We use Qwiet AI because its reachability analysis tells us which of our dependency CVEs our code can actually reach, and DefectDojo is where we act on that across the whole portfolio. Pulling Qwiet findings into DefectDojo puts SAST, SCA, and secret findings for each application on its Asset, with the source and sink of every traced flow in the description and the reachability verdict recorded as the severity justification. Two Critical findings may look the same on a dashboard, but the one marked reachable is the one we fix first.
Why Qwiet AI Matters
Most SCA tools report every vulnerable package version in the dependency tree, whether or not the application calls the affected code. That produces long lists and little prioritization.
- Qwiet traces data flows through the application, so code findings come with a source method and a sink method.
- Its reachability verdict separates dependency CVEs on a real path from those that are only present.
- Code, dependency, and secret findings come from one analysis instead of three separate tools.
- Findings carry OWASP categories, CWEs, CVEs, CVSS scores, and package URLs as tags.
- On its own, Qwiet is one more console. Remediation SLAs, ticketing, and reporting next to other scanners still need a central platform.
Advantages of This Integration
What routing Qwiet AI through DefectDojo gives us:
- Reachability kept visible. The verdict is written to the severity justification and added as a
reachability:tag, without changing Qwiet's own severity, so reviewers can filter for reachable findings. - Dependency findings with related flows count as reachable. An
oss_vulnfinding with related findings is treated as reachable even without the tag, because those related findings are the traced path. - File and API imports agree. The file parser mirrors the DefectDojo Pro connector's conversion and uses the same scan type, so a file import and an API sync deduplicate against each other.
- Stable identity. Findings are matched on
qwiet-<internal id>, the identifier that stays stable across scans, with a hash of title, severity, file path, CWE, and component as fallback. - Component data for SCA. The package URL is reduced to a component name and version, and the CVE is stored as a vulnerability ID for filtering and reporting.
- Scheduled sync in DefectDojo Pro. The connector creates a Record for each Qwiet application and keeps its findings current.
How This Integration Works
Both paths use the Qwiet Scan scan type.
Option 1: Qwiet AI connector (DefectDojo Pro). The connector imports SAST, SCA, and secret findings, with reachability, from Qwiet AI. Configure it with:
https://app.shiftleft.ioin the Location field. The host is still the legacy ShiftLeft domain, and DefectDojo appends the API path.- A Qwiet AI preZero access token in the Access Token field. The organization is read from the token.
- Optionally, an Organization ID to override the organization from the token.
- Optionally, a Minimum Severity to limit which findings are imported.
Each Qwiet application becomes a Record carrying its SAST, SCA, and secret findings together, which you map to a DefectDojo Asset.
Option 2: File import (Community Edition and DefectDojo Pro). For environments that cannot grant Qwiet API credentials, such as air-gapped networks or teams awaiting a security review, save the findings response for an application as JSON. The parser accepts Qwiet's wrapped response (ok plus a response list), a bare array of findings, or an object with a findings list. In the UI, choose Import Scan Results and select Qwiet Scan. With the API:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Qwiet Scan"
-F "file=@qwiet-findings.json"
-F "product_name=orders-api"
-F "engagement_name=Qwiet"
-F "auto_create_context=true"
DefectDojo Pro users can run the file import with Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Qwiet Scan"
--report-path "./qwiet-findings.json"
--product-name "orders-api"
--engagement-name "Qwiet"
--auto-create-context
Data Granularity: What Gets Imported
The table describes the file parser, which mirrors the connector's conversion.
| DefectDojo Field | Source in Qwiet Finding | Notes |
|---|---|---|
| Title | title |
Falls back to category, then the finding id |
| Severity | severity |
critical, high, medium, low map directly; anything else Info |
| Severity Justification | reachability tag |
Spelled-out reachability verdict |
| Description | type, category, owasp_category, source and sink methods |
Also every file location, then Qwiet's description |
| CWE | cwe_category tag |
CWE-89 becomes 89 |
| CVSS v3 Score | cvss_score tag |
Unparseable scores are ignored |
| Vulnerability IDs | cve tag |
For dependency findings |
| Component Name / Version | package_url tag |
Last path segment of the package URL |
| File Path / Line | First file_locations entry |
path:line; the full list stays in the description |
| Unique ID From Tool | internal_id |
Prefixed qwiet-; falls back to id |
| Vuln ID From Tool | internal_id |
Falls back to category |
| Tags | type, owasp_category, reachability |
For example reachability:reachable |
| Finding type | Static | All Qwiet findings are marked static |
| Deduplication | Unique ID, else hashcode | Title, severity, file path, CWE, component name |
Use Cases
Prioritizing dependency CVEs: A team with hundreds of open SCA findings filters DefectDojo on the reachability:reachable tag and works those first, while unreachable findings stay tracked under longer SLAs or risk acceptance.
Restricted networks: An organization that cannot connect DefectDojo to Qwiet's API imports exported findings files. If it later enables the connector, the shared scan type and identifiers mean existing Findings are matched instead of duplicated.
Code review of injection flows: A SAST finding for SQL injection shows its source and sink methods and every file on the path, so the reviewing engineer can confirm the flow without opening Qwiet.
Portfolio reporting: Security leaders see Qwiet results next to DAST, container, and pentest findings on each Asset, with SLA compliance measured the same way for all of them.
Operational Tips
- Use the reachability tag in saved filters and reports. It is the main reason to prefer Qwiet's SCA results over a plain dependency scan.
- Severity is Qwiet's own label. Reachability does not change it, so adjust SLAs or severity manually if your policy treats reachable findings differently.
- Only the first file location becomes the File Path. For multi-file flows, read the location list in the description.
- Set Minimum Severity on the connector, or
minimum_severityon file imports, if Info and Low findings would crowd the queue. - Pick one path per application where possible. Both paths share the scan type and identifiers, but scheduled connector syncs keep status current without manual exports.
- Keep internal IDs intact in exported files. They are the primary match key across imports.