FOSSA (Pro)
On this page
The FOSSA connector imports both security vulnerabilities and license-policy violations from FOSSA. DefectDojo creates a Record for each FOSSA project.
Prerequisites
A FOSSA Full API token.
A Push-Only token will not work. FOSSA’s Push-Only tokens cannot read the APIs this connector uses, so the Sync fails to retrieve anything. This is the most common misconfiguration for this connector — make sure the token is a Full token.
Connector Mappings
- Enter
https://app.fossa.com/apiin the Location field. - Enter your FOSSA Full API token in the Secret field.
- Optionally, set a Minimum Severity to limit which findings are imported.
Each FOSSA project becomes a Record. Only your organization’s active issues are imported, covering both vulnerability and license-policy findings — so this connector can drive licence compliance work as well as security remediation.
Prev
FortifyNext
Freshservice