Xygeni Integration with DefectDojo
Xygeni Integration with DefectDojo
Xygeni is a software supply chain security platform. Its scanner produces JSON reports for code vulnerabilities (SAST), open source dependency vulnerabilities (SCA), hard-coded secrets, infrastructure as code flaws, CI/CD and SCM misconfigurations, and suspect components, among others. Every report shares a common metadata envelope that names the scan kind. DefectDojo currently imports three of those kinds: SAST, SCA, and Secrets.
Xygeni Integration with DefectDojo
We run the Xygeni scanner in our pipelines because one CLI covers code, dependencies, and secrets for each repository. Importing its SAST, SCA, and secrets reports into DefectDojo puts all three next to the rest of our findings, with Xygeni's own stable identifier driving deduplication. That matters most for code findings: when someone adds lines above a flagged function, the finding keeps its identity instead of closing and reopening.
Why Xygeni Matters
Supply chain risk crosses several categories at once, and Xygeni reports on them from one tool.
- SAST results include the rule that fired, the file and line, CWE mappings, and, where available, the source-to-sink data flow.
- SCA results attach CVE and GHSA advisories to the exact dependency and version, with fixed versions and CVSS scores.
- Secrets results identify the kind of credential and where it was committed, with the secret value already redacted by the Xygeni CLI before the report is written.
- Each finding carries a
uniqueHashthat Xygeni designs to stay stable across scans.
Advantages of This Integration
What changes when Xygeni reports go through DefectDojo:
- Line shifts do not churn findings. For SAST, Xygeni's
uniqueHashcovers the detector and the normalized code but deliberately excludes the line. DefectDojo deduplicates all three Xygeni scan types on that hash, so moved code keeps its finding. - Secrets leaked many times show once. The same secret repeated on several lines of one file shares one hash. DefectDojo aggregates those into a single finding and lists every line in the description, which keeps the remediation task to one rotation.
- Dependency fixes are explicit. SCA findings carry component name and version and a mitigation such as "Upgrade package to version X or later" when Xygeni knows the fixed version.
- Data flow in the finding. SAST code flows are rendered into the description, and the source file, source line, and sink are written to DefectDojo's SAST source and sink fields.
- One workflow for three scanners. SLAs, assignment, Jira, risk acceptance, and reporting apply across code, dependency, and secret findings.
How This Integration Works
DefectDojo provides three scan types for Xygeni: Xygeni SAST Scan, Xygeni SCA Scan, and Xygeni Secrets Scan. The parser reads metadata.scanType (sast, deps, or secrets) to decide how to read the report. Import with UI Import, API Import, or Universal Importer in DefectDojo Pro.
1. Run the scanner with JSON output. DefectDojo's Xygeni documentation gives the scan form below. From the repository root, run the scanner for each kind you want to import and save its JSON output to a file:
xygeni scan --scan-type=sast --format=json
xygeni scan --scan-type=deps --format=json
xygeni scan --scan-type=secrets --format=json
See the Xygeni documentation for installation, authentication, and the full set of scanner options. A report whose metadata.scanType is something other than these three is rejected with an error naming the supported kinds.
2. Import each report under its scan type. In the UI, open the Engagement, choose Import Scan Results, pick the matching Xygeni scan type, and upload the file. Through the API, in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Xygeni SAST Scan"
-F "file=@xygeni-sast.json"
-F "product_name=checkout-service"
-F "engagement_name=CI"
-F "auto_create_context=true"
With Universal Importer in DefectDojo Pro:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Xygeni SCA Scan"
--report-path "./xygeni-sca.json"
--product-name "checkout-service"
--engagement-name "CI"
--auto-create-context
3. Reimport per scan type. Keep one Test per Xygeni scan type and reimport into it on each run, so fixed findings are mitigated and returning ones are reactivated.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Xygeni Report | Notes |
|---|---|---|
| Title (SAST) | detector |
The rule that fired |
| Title (SCA) | cve |
Falls back to the advisory id |
| Title (Secrets) | type, file name |
"type secret detected in file" |
| Severity | severity |
critical, high, medium, low, info map directly; unknown becomes Info |
| Description | explanation or description, code, data flow |
Secrets descriptions list every line when a secret repeats |
| File Path / Line | location.filepath, location.beginLine |
SAST and Secrets |
| SAST Source / Sink | codeFlows frames |
Source file, line, and injection point; sink object |
| CWE | cwe, cwes, CWE tags |
All CWEs kept; Secrets default to 798 |
| Component Name / Version | Dependency name, version |
SCA |
| Mitigation | fixedVersion (SCA); fixed text (Secrets) |
Secrets mitigation advises rotating the secret and removing it from history |
| CVSS v3 Score | overallCvssScore |
SCA, when present and not negative |
| References | references |
SCA |
| Vulnerability IDs | cve, aliases |
SCA |
| Unique ID from Tool | uniqueHash |
All three scan types |
| Vuln ID from Tool | detector or userId |
Grouping label, not a dedupe key |
| Finding type | Static | |
| Deduplication | Unique ID from tool | uniqueHash for all three scan types |
Use Cases
Pull request and main branch scanning: A team runs the three Xygeni scans on every merge to main and reimports each into its own Test. Developers see only what changed, and refactors that move code do not reopen old SAST findings.
Secret leak response: When a secrets finding appears, the description lists every line where the secret was found. The owner rotates it once, removes it from history, and the finding closes on the next reimport.
Dependency upgrade campaigns: SCA findings grouped by component name show every service still on a vulnerable library version, each with the minimum fixed version in its mitigation.
Consolidated AppSec reporting: Leadership reports on code, dependency, and secret exposure per Asset using the same SLA and metrics views as findings from other tools.
Operational Tips
- Pick the scan type that matches the report. Importing an SCA report as Xygeni SAST Scan still parses by
metadata.scanType, but labels the Test wrong and splits dedupe history. - Because deduplication relies only on
uniqueHash, keep Xygeni's report format consistent across runs. A report missing that field will not match earlier findings. - Treat
vuln_id_from_toolas a grouping label. Many findings share a detector or advisory ID, so filter on it, but do not expect it to be unique. - Give Secrets findings a short SLA. Rotation is the fix, and the mitigation text says so.
- Use
minimum_severityon SAST imports if low-severity rules are noisy while you tune your Xygeni policy. - Other Xygeni scan kinds such as IaC and misconfiguration are not imported by this parser today, so track them separately or use another supported format.