
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
SonarCube plugin & Fortify
Is there any integration/Fortify plugin available for SonarCube?
-> If YES, the license to use is the same used by the Eclipse plugin, for example?
Thank you in advance,
Marcelo Muzilli

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Yes there is. I'm using Sonar to manage findings instead of SSC. You do loose some functionality that SSC has

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Also a soon-to-be option is using ThreadFix. You can either load FPRs into ThreadFix or use the SSC connector. Our entire org puts static, dynamic, other appsec tool outputs, and manual findings into ThreadFix for every application we test.
Denim Group has built a ThreadFix plugin for Sonar which should be out really soon. So your SonarQube dashboard can have quality metrics for ALL of your security tools, not just Fortify.


- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Anyone ever used ThreadFix in conjuction with things like WhiteHat? One of our biggest issues is trying to get WhiteHat, FoD, Fortify, etc... all in one place so we can have a great security picture.
Thanks,
Mike

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Any updates in feeding Fortify SCA results to ThreadFix for SonarCube results review?
http://docs.sonarqube.org/display/PLUG/Fortify+Plugin
Like , looking into a Proof Of Concept to have our static and dynamic security scanner result types that are supported by ThreadFix to feed into SonarCube for build pass/fail.