All integrations

Xygeni Integration with DefectDojo

Xygeni Integration with DefectDojo

Xygeni is a software supply chain security platform. Its scanner produces JSON reports for code vulnerabilities (SAST), open source dependency vulnerabilities (SCA), hard-coded secrets, infrastructure as code flaws, CI/CD and SCM misconfigurations, and suspect components, among others. Every report shares a common metadata envelope that names the scan kind. DefectDojo currently imports three of those kinds: SAST, SCA, and Secrets.

Xygeni Integration with DefectDojo

We run the Xygeni scanner in our pipelines because one CLI covers code, dependencies, and secrets for each repository. Importing its SAST, SCA, and secrets reports into DefectDojo puts all three next to the rest of our findings, with Xygeni's own stable identifier driving deduplication. That matters most for code findings: when someone adds lines above a flagged function, the finding keeps its identity instead of closing and reopening.

Why Xygeni Matters

Supply chain risk crosses several categories at once, and Xygeni reports on them from one tool.

  • SAST results include the rule that fired, the file and line, CWE mappings, and, where available, the source-to-sink data flow.
  • SCA results attach CVE and GHSA advisories to the exact dependency and version, with fixed versions and CVSS scores.
  • Secrets results identify the kind of credential and where it was committed, with the secret value already redacted by the Xygeni CLI before the report is written.
  • Each finding carries a uniqueHash that Xygeni designs to stay stable across scans.

Advantages of This Integration

What changes when Xygeni reports go through DefectDojo:

  • Line shifts do not churn findings. For SAST, Xygeni's uniqueHash covers the detector and the normalized code but deliberately excludes the line. DefectDojo deduplicates all three Xygeni scan types on that hash, so moved code keeps its finding.
  • Secrets leaked many times show once. The same secret repeated on several lines of one file shares one hash. DefectDojo aggregates those into a single finding and lists every line in the description, which keeps the remediation task to one rotation.
  • Dependency fixes are explicit. SCA findings carry component name and version and a mitigation such as "Upgrade package to version X or later" when Xygeni knows the fixed version.
  • Data flow in the finding. SAST code flows are rendered into the description, and the source file, source line, and sink are written to DefectDojo's SAST source and sink fields.
  • One workflow for three scanners. SLAs, assignment, Jira, risk acceptance, and reporting apply across code, dependency, and secret findings.

How This Integration Works

DefectDojo provides three scan types for Xygeni: Xygeni SAST Scan, Xygeni SCA Scan, and Xygeni Secrets Scan. The parser reads metadata.scanType (sast, deps, or secrets) to decide how to read the report. Import with UI Import, API Import, or Universal Importer in DefectDojo Pro.

1. Run the scanner with JSON output. DefectDojo's Xygeni documentation gives the scan form below. From the repository root, run the scanner for each kind you want to import and save its JSON output to a file:

xygeni scan --scan-type=sast --format=json
xygeni scan --scan-type=deps --format=json
xygeni scan --scan-type=secrets --format=json

See the Xygeni documentation for installation, authentication, and the full set of scanner options. A report whose metadata.scanType is something other than these three is rejected with an error naming the supported kinds.

2. Import each report under its scan type. In the UI, open the Engagement, choose Import Scan Results, pick the matching Xygeni scan type, and upload the file. Through the API, in Community Edition or DefectDojo Pro:

curl "https://YOUR_INSTANCE/api/v2/import-scan/" 
  -H "Authorization: Token $DD_API_TOKEN" 
  -F "scan_type=Xygeni SAST Scan" 
  -F "file=@xygeni-sast.json" 
  -F "product_name=checkout-service" 
  -F "engagement_name=CI" 
  -F "auto_create_context=true"

With Universal Importer in DefectDojo Pro:

universal-importer import 
  --defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/" 
  --scan-type "Xygeni SCA Scan" 
  --report-path "./xygeni-sca.json" 
  --product-name "checkout-service" 
  --engagement-name "CI" 
  --auto-create-context

3. Reimport per scan type. Keep one Test per Xygeni scan type and reimport into it on each run, so fixed findings are mitigated and returning ones are reactivated.

Data Granularity: What Gets Imported

DefectDojo Field Source in Xygeni Report Notes
Title (SAST) detector The rule that fired
Title (SCA) cve Falls back to the advisory id
Title (Secrets) type, file name "type secret detected in file"
Severity severity critical, high, medium, low, info map directly; unknown becomes Info
Description explanation or description, code, data flow Secrets descriptions list every line when a secret repeats
File Path / Line location.filepath, location.beginLine SAST and Secrets
SAST Source / Sink codeFlows frames Source file, line, and injection point; sink object
CWE cwe, cwes, CWE tags All CWEs kept; Secrets default to 798
Component Name / Version Dependency name, version SCA
Mitigation fixedVersion (SCA); fixed text (Secrets) Secrets mitigation advises rotating the secret and removing it from history
CVSS v3 Score overallCvssScore SCA, when present and not negative
References references SCA
Vulnerability IDs cve, aliases SCA
Unique ID from Tool uniqueHash All three scan types
Vuln ID from Tool detector or userId Grouping label, not a dedupe key
Finding type Static
Deduplication Unique ID from tool uniqueHash for all three scan types

Use Cases

Pull request and main branch scanning: A team runs the three Xygeni scans on every merge to main and reimports each into its own Test. Developers see only what changed, and refactors that move code do not reopen old SAST findings.

Secret leak response: When a secrets finding appears, the description lists every line where the secret was found. The owner rotates it once, removes it from history, and the finding closes on the next reimport.

Dependency upgrade campaigns: SCA findings grouped by component name show every service still on a vulnerable library version, each with the minimum fixed version in its mitigation.

Consolidated AppSec reporting: Leadership reports on code, dependency, and secret exposure per Asset using the same SLA and metrics views as findings from other tools.

Operational Tips

  • Pick the scan type that matches the report. Importing an SCA report as Xygeni SAST Scan still parses by metadata.scanType, but labels the Test wrong and splits dedupe history.
  • Because deduplication relies only on uniqueHash, keep Xygeni's report format consistent across runs. A report missing that field will not match earlier findings.
  • Treat vuln_id_from_tool as a grouping label. Many findings share a detector or advisory ID, so filter on it, but do not expect it to be unique.
  • Give Secrets findings a short SLA. Rotation is the fix, and the mitigation text says so.
  • Use minimum_severity on SAST imports if low-severity rules are noisy while you tune your Xygeni policy.
  • Other Xygeni scan kinds such as IaC and misconfiguration are not imported by this parser today, so track them separately or use another supported format.