All integrations

Veracode Integration with DefectDojo

Veracode is a comprehensive cloud-based application security platform that provides static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), infrastructure as code scanning, container security, and manual penetration testing to identify and remediate vulnerabilities across web, mobile, and third-party applications throughout the software development lifecycle. The platform leverages AI-powered analysis trained on two decades of proprietary vulnerability research covering over 100 programming languages and frameworks to deliver automated flaw detection with minimal false positives, AI-driven fix recommendations that reduce remediation time by up to 60%, and unified application security posture management (ASPM) that prioritizes risks based on root cause analysis and business impact while enabling seamless integration into developer workflows and CI/CD pipelines.

Data Granularity: What Gets Imported

The following fields are captured from Veracode results and surfaced in DefectDojo findings:

FieldSourceNotes
TitleFinding name from the scanMatched to the tool's own naming
SeverityCritical / High / Medium / Low / InfoMapped from the tool's own severity scale
DescriptionFinding detail from the reportIncludes what the issue is and why it matters
MitigationRemediation guidanceWhere the tool provides it

Importing Into DefectDojo

Use the DefectDojo import API to create a new Test under the relevant Engagement for your product. The request body:

{
  "scan_type": "Veracode",
  "engagement": "<engagement-id>",
  "file": "results.json"
}