deepfence / deepfence/ThreatMapper

Defect Dojo integration

Open
#1,907 1 comment 0 reactions 1 assignee Claimed by @ibreakthecloud View on GitHub
enhancement needs-triage
Dominant language
TypeScript
Stars
5.3k
Forks
631
PR merge metrics
No merged PRs in 30d

Description

**Additional context**
Defect dojo is an aggregator repository of vulnerabilities and it would be interesting to have an integration between ThreatMapper and it.

**Describe the solution you'd like**
The main goal would be to have vulnerabilities detected by Threat mapper and injected into Defect dojo (https://owasp.org/www-project-defectdojo/) where they could be correlated with other tools.

**Describe alternatives you've considered**
Instead of an integration, a simple extraction of information from Threat mapper could be enough. It could be just a standard extraction of data in CSV or JSON.

**Components/Services**

- [ ] UI/Frontend
- [X] API/Backend
- [ ] Agent
- [ ] Deployment/YAMLs
- [ ] CI/CD Integration
- [ ] Other (specify)

**Additional context**
List of Defect Dojo integration: https://www.defectdojo.com/integrations

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.