Veracode Integration with DefectDojo
Veracode is a comprehensive cloud-based application security platform that provides static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), infrastructure as code scanning, container security, and manual penetration testing to identify and remediate vulnerabilities across web, mobile, and third-party applications throughout the software development lifecycle. The platform leverages AI-powered analysis trained on two decades of proprietary vulnerability research covering over 100 programming languages and frameworks to deliver automated flaw detection with minimal false positives, AI-driven fix recommendations that reduce remediation time by up to 60%, and unified application security posture management (ASPM) that prioritizes risks based on root cause analysis and business impact while enabling seamless integration into developer workflows and CI/CD pipelines.
Data Granularity: What Gets Imported
The following fields are captured from Veracode results and surfaced in DefectDojo findings:
| Field | Source | Notes |
|---|---|---|
| Title | Finding name from the scan | Matched to the tool's own naming |
| Severity | Critical / High / Medium / Low / Info | Mapped from the tool's own severity scale |
| Description | Finding detail from the report | Includes what the issue is and why it matters |
| Mitigation | Remediation guidance | Where the tool provides it |
Importing Into DefectDojo
Use the DefectDojo import API to create a new Test under the relevant Engagement for your product. The request body:
{
"scan_type": "Veracode",
"engagement": "<engagement-id>",
"file": "results.json"
}