YesWeHack Integration with DefectDojo
YesWeHack Integration with DefectDojo
YesWeHack is a bug bounty and vulnerability disclosure platform that connects organizations with security researchers. Programs define a scope, researchers submit reports, and each report moves through a triage workflow (new, under review, accepted, resolved, and several closing states) with a CVSS rating, a bug type, the affected scope and endpoint, and a written description and impact. DefectDojo imports YesWeHack reports from a JSON export of the reports API, and DefectDojo Pro can sync them through an API connector.
YesWeHack Integration with DefectDojo
Our bug bounty program finds issues that scanners do not, but for a long time those reports were handled in YesWeHack while everything else was fixed from DefectDojo. Bringing YesWeHack reports into DefectDojo puts researcher findings on the same Asset as our scanner results, with the triage state already applied. Accepted reports arrive verified, resolved ones arrive mitigated, and rejected ones arrive as false positives, so the queue developers see matches what triage decided.
Why YesWeHack Matters
Human researchers test running systems the way attackers do, and their findings tend to be high signal.
- Reports describe real, reproduced issues against in-scope targets.
- Triage on the platform decides validity, duplication, and scope before a report reaches your team.
- Each report carries a CVSS vector and rating, plus a bug type and category.
- A vulnerability disclosure program gives outside researchers a sanctioned channel, which is often a compliance expectation.
Advantages of This Integration
What DefectDojo adds to YesWeHack reports:
- Triage state carried over. Workflow states map to DefectDojo status, so resolved, rejected, and duplicate reports do not reappear as active work.
- Unknown states stay open. A workflow state DefectDojo does not recognize imports as active, so a new state can never silently close a finding.
- Severity with fallbacks. Severity comes from the CVSS criticity, then the priority name, then the priority slug, so a report with no criticity but a set priority keeps that priority.
- CVE extraction. CVEs found in the title, description, impact, and technical information are added as vulnerability IDs, since YesWeHack has no CVE field.
- File and connector deduplicate. The parser mirrors the DefectDojo Pro connector and uses the same scan type. Report IDs are globally unique on the platform, so findings match on that ID alone.
- Same workflow as everything else. SLAs, assignment, Jira tickets, and metrics apply to bug bounty findings, which makes payout-worthy issues visible in the same reports as scanner results.
How This Integration Works
DefectDojo supports YesWeHack with the YesWeHack - Connectors Import scan type, by file (UI Import, API Import, Universal Importer in DefectDojo Pro) or through the DefectDojo Pro API connector.
1. Get a reports export. The parser reads JSON from YesWeHack's reports endpoint. The API's items envelope is accepted, as is a bare array of reports. Save the response from a system that holds your YesWeHack token. This route is meant for organizations that cannot grant DefectDojo API credentials.
2. Import the file. In the UI, open an Engagement, choose Import Scan Results, select YesWeHack - Connectors Import, and upload the JSON. Through the API, in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=YesWeHack - Connectors Import"
-F "file=@yeswehack-reports.json"
-F "product_name=customer-portal"
-F "engagement_name=Bug Bounty"
-F "auto_create_context=true"
With Universal Importer in DefectDojo Pro:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "YesWeHack - Connectors Import"
--report-path "./yeswehack-reports.json"
--product-name "customer-portal"
--engagement-name "Bug Bounty"
--auto-create-context
3. Or use the connector (DefectDojo Pro). Create a Personal Access Token in YesWeHack under account settings, API / Personal Access Tokens. Read access to your programs is sufficient, and the token value is shown only once. In the DefectDojo Pro UI, add the YesWeHack connector, enter https://api.yeswehack.com/ in Location and the token in Secret, and optionally set a Minimum Severity. DefectDojo creates a Record for each program the token can access and imports each report as a finding.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in YesWeHack Report | Notes |
|---|---|---|
| Title | title |
Falls back to local_id, then "YesWeHack report ID" |
| Severity | cvss.criticity, then priority |
critical, high, medium, low map directly; info, informative, none become Info |
| Description | Report fields | Local ID, bug type, category, scope, endpoint, then Description and Impact sections |
| CVSS v3 Vector / Score | cvss.vector, cvss.score |
Score set when above zero |
| Endpoint | end_point |
Falls back to the program scope; scheme and port parsed |
| Date | created_at |
Several timestamp layouts accepted |
| Vulnerability IDs | Title, description, impact, technical information | CVE identifiers |
| Unique ID from Tool | id |
Numeric report ID |
| Vuln ID from Tool | local_id |
Falls back to numeric ID |
| Status | status.workflow_state |
Mapped as listed below this table |
| Tags | Fixed | yeswehack |
| Finding type | Dynamic | A researcher testing a running target |
| Deduplication | Hashcode | unique_id_from_tool |
For file imports, workflow states map as follows: new and under_review are active; accepted is active and verified; resolved and auto_close are inactive and mitigated; wont_fix is inactive and risk accepted; invalid and rejected are false positives; duplicate is marked duplicate; out_of_scope and informative are inactive.
Use Cases
Closing the loop on bounty reports: A triaged report lands in DefectDojo as verified and gets a Jira ticket for the owning team. When the fix ships and YesWeHack marks the report resolved, the next import mitigates the finding.
Comparing human and automated testing: Security leads look at bug bounty findings next to DAST and SAST results on the same Asset to see which classes of issue scanners keep missing.
VDP evidence for audits: Reports from a vulnerability disclosure program carry dates, severity, SLA status, and closure history, which demonstrates that external reports are handled.
Restricted environments: Where DefectDojo cannot hold a YesWeHack token, an administrator exports reports and uploads them. Findings deduplicate with the connector later because the scan type and IDs match.
Operational Tips
- Map each YesWeHack program to the Asset that owns its scope. The connector does this per program with Records; for file imports, export per program.
- Reimport regularly so state changes in YesWeHack, such as accepted to resolved, are reflected in DefectDojo.
- Use Minimum Severity on the connector, or
minimum_severityon file import, only if you are sure low reports are not needed for researcher follow-up. - Set SLAs for verified bug bounty findings that reflect your program's commitments to researchers.
- Put CVE references in the technical information field when triaging; DefectDojo extracts CVEs from there too.
- If you use both the file route and the connector, send both to the same Asset so their findings deduplicate.