Cadet 3rd Class
Cadet 3rd Class
4352 views

VSTS plugin, no email detected for cloud controller

I'm attempting to use the Fortify plugin for VSTS, https://marketplace.visualstudio.com/items?itemName=fortifyvsts.hpe-security-fortify-vsts

Fortify has successfully been setup for our build and cloud also works for automated scans and uploads to SSC.

However, we would also like to be able to use the email functionality build into the cloud controller software.  Unfortunately adding -email <user_email@domain.com> to the Addition Scan Parameters section does not appear to work.

It looks like the email address gets appeneded after the -scan parameter and the following messages is displayed: "no email detected"

The reason we would like email integration is because the cloud controller provides automated alerts regarding the scan status (queued, completed, failed, etc).  It also provides the link to download the results if successful.

Is there a work around for getting cloud scan email integration with VSTS, or is there a plan for an update as this is a useful feature.

0 Likes
1 Reply
Micro Focus Expert
Micro Focus Expert

That field for "Additional Scan Parameters" refers to options available with SCA such as {-mt} or {-show-files}.  The SCA scanner does not have a {-email} parameter.  For your reference, I have attached a recent listing from SCA 17.20.  The prior radio buttons attempt to make it a little simpler for the user, as enabling them will include the parameters for Clean {-clean}, {-logfile <filename>}, Verbose Output {-verbose}, and Debug Information {-debug}.

I believe that to get an alert, you will have to formulate more than this option.  Your Build Task in VSTS might have an option for this, so you could create your own triggers and notifications script.  The SSC Server offers Alerts via email, so when your VSTS/SCA scan is uploaded those could be triggered.  Fortify CloudScan offers email alerts as well, but they notify SSC to send them and they only complete if the associated SSC Server has that feature enabled and configured.


-- Habeas Data
Micro Focus Fortify Customers-Only Forums – https://community.softwaregrp.com/t5/Fortify/ct-p/fortify
0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.