Klocwork (Pro)

The Klocwork connector imports static analysis (SAST) findings from a Perforce Klocwork server. DefectDojo enumerates the server’s projects and creates a Record for each project.

Prerequisites

A Klocwork username and its login token (ltoken) — the token generated by kwauth and stored in the ltoken file. The token is never logged.

Connector Mappings

  1. Enter your Klocwork server URL in the Location field.
  2. Enter the Klocwork username the token belongs to in the Username field.
  3. Enter the login token in the Login Token (ltoken) field.
  4. Optionally, set a Minimum Severity to limit which findings are imported.

Each Klocwork project becomes a Record. Only issues Klocwork classes as actionable are imported, and only from each project’s latest build — so the findings describe the current state of the project rather than accumulating across builds.