SOOS Integration with DefectDojo
SOOS Integration with DefectDojo
SOOS (soos.io) is an application security testing platform that runs several kinds of scan behind one service: software composition analysis (SCA), static analysis (SAST), container scanning, SBOM analysis, and dynamic application testing (DAST). Every issue SOOS reports is stamped with the scan type that produced it, along with severity, package or location details, and its triage status in SOOS. Issues can be read through the SOOS API as JSON, which DefectDojo imports from a file, and DefectDojo Pro also offers a SOOS connector for SCA findings.
SOOS Integration with DefectDojo
We use SOOS for dependency and web application scanning, and we use DefectDojo for everything else, so the question was how to avoid two separate queues. Importing SOOS issues into DefectDojo puts them on the same Assets as the rest of our scanner results. The part that mattered most to us is that SOOS-side triage carries over: an issue our team already marked false positive or accepted in SOOS does not reappear as an active Finding every time we sync.
Why SOOS Matters
Many teams adopt SOOS to cover more than one testing category with a single vendor. That is convenient, but it also means one tool's output spans static and dynamic results that need different handling.
- SOOS covers open source dependencies, first-party code, containers, SBOMs, and running web applications.
- Each issue records which scan found it, so dependency issues and DAST issues can be told apart.
- SOOS keeps its own triage states, such as false positive and accepted, which represent decisions the team has already made.
- Issues include CVE, CWE, CVSS vector and score, fixed version, and remediation text when SOOS has them.
- Results from one platform still need to be compared with other tools and tracked against SLAs across the organization.
Advantages of This Integration
What we gained by sending SOOS issues through DefectDojo:
- Triage that carries across. SOOS
False positiveimports as an inactive false positive,Acceptedas an inactive risk-accepted Finding, andIgnored,Dismissed,Resolved, orFixedas inactive and mitigated. Everything else is active. - Static and dynamic decided per issue. SCA, SAST, container (
csa), and SBOM issues import as static Findings; DAST issues import as dynamic, and their URL becomes the Finding's endpoint. - Scan type as a tag. Each Finding is tagged with its SOOS scan type, so an SCA and a DAST Finding on the same Asset stay easy to separate.
- Fix guidance. Mitigation uses SOOS's remediation text, or names the fixed version (and package) when there is no remediation text.
- Consistent with the connector. The file parser uses the same scan type as the DefectDojo Pro connector, SOOS - Connectors Import, and mirrors its field mapping so file and API findings line up.
- Shared SLAs and reporting. SOOS severities map directly onto DefectDojo's scale, so SOOS issues are measured with the same SLA rules as every other tool.
How This Integration Works
There are two supported ways to bring SOOS issues into DefectDojo.
Option 1: File import (Community Edition and DefectDojo Pro). This path exists for organizations that cannot grant SOOS API credentials. Save the SOOS issues response as JSON. The parser reads the entries list SOOS returns, and also accepts items, issues, data, or results lists, or a bare array. Import it with the SOOS - Connectors Import scan type. In the UI, open the Engagement, choose Import Scan Results, select the scan type, and upload the file. To automate it:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=SOOS - Connectors Import"
-F "file=@soos-issues.json"
-F "product_name=customer-portal"
-F "engagement_name=SOOS"
-F "auto_create_context=true"
DefectDojo Pro users can run the same import with Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "SOOS - Connectors Import"
--report-path "./soos-issues.json"
--product-name "customer-portal"
--engagement-name "SOOS"
--auto-create-context
Option 2: SOOS connector (DefectDojo Pro). The connector imports SCA findings from SOOS on a schedule and creates a Record for each SOOS project on the account. It needs two credentials, both found under SOOS, Integrations, and neither works on its own:
- Location:
https://api.soos.io/api/ - Client ID: your SOOS Client ID, which forms part of every request path.
- API Key: your SOOS API key, sent as a request header.
- Minimum Severity (optional): limits which findings are imported.
Each project's Record carries the vulnerabilities of its scanned dependencies. If you need SAST, container, SBOM, or DAST issues in DefectDojo, use the file import path for those.
Data Granularity: What Gets Imported
The table describes the file parser, which mirrors the connector's converter.
| DefectDojo Field | Source in SOOS Issue | Notes |
|---|---|---|
| Title | title |
|
| Severity | severity |
Critical through Info map directly; Unknown and unrecognized values become Info |
| Description | description |
When empty, states which SOOS scan reported the issue |
| Mitigation | remediation, else fixedVersion |
For example Upgrade example-utils to 4.17.21 or later |
| Component Name / Version | packageName, packageVersion |
|
| File Path / Line | fileName, line |
Source and dependency issues; a line of 0 is left empty |
| Endpoint | url |
DAST issues; URLs DefectDojo cannot accept are skipped |
| CVE | cve |
Also stored as the tool ID |
| CWE | cwe |
Accepts CWE-79 or 79 |
| CVSS v3 | cvssVector, cvssScore |
Vector and score |
| References | references |
|
| Date | firstDetected |
Date portion only |
| Unique ID from Tool | id |
SOOS issue ID |
| Status | status |
False positive, risk accepted, mitigated, or active |
| Finding type | scanType |
Static for sca, sast, csa, sbom; dynamic for dast and anything unrecognized |
| Deduplication | Legacy | No per-parser configuration, matching the connector's findings |
Use Cases
For teams using several SOOS scan types: A team running SOOS SCA and DAST imports both into the same Asset. Tags separate dependency issues from web application issues, and the DAST Findings carry their URLs as endpoints for anyone testing the fix.
For SCA at scale with DefectDojo Pro: The connector syncs every SOOS project as a Record. Security leads see dependency vulnerabilities for all projects in DefectDojo, with SLAs applied, without asking teams to upload files.
In restricted environments: Organizations that cannot share SOOS API credentials with DefectDojo save the issues response and import it on a schedule, using the same scan type the connector would use.
When consolidating triage: Because SOOS dispositions carry over, a team that already triaged hundreds of issues in SOOS starts in DefectDojo with those decisions intact instead of redoing them.
Operational Tips
- An unrecognized or missing SOOS scan type imports as a dynamic Finding. If SOOS adds a new scan type, check how its issues are flagged after import.
Unknownis a real SOOS severity and imports as Info. Review those Findings rather than filtering them out, since SOOS could not grade them but still reported them.- This scan type uses DefectDojo's Legacy deduplication algorithm. If you change deduplication settings for it, the connector's findings are affected too.
- Decide where triage lives. SOOS dispositions are read when issues are imported, and decisions made only in DefectDojo are not written back to SOOS.
- Use
minimum_severity, or the connector's Minimum Severity setting, to keep Info and Low issues out of the main queue if they would bury higher-priority work. - Filter by the scan type tag to send DAST Findings to the web team and SCA Findings to service owners.