Coverity Scan JSON Report

File Types

This DefectDojo parser accepts JSON files created from the Synopsys Coverity CLI using the following command: coverity scan.

Documentation for CLI can be found here.

Example Commands to retrieve JSON output

Run coverity scan --project-dir <project_dir> --local <result_file> --local-format json to create the JSON report.

Sample Scan Data

Sample Coverity scans can be found here.

Default Deduplication Hashcode Fields

By default, DefectDojo identifies duplicate Findings using these hashcode fields:

  • title
  • cwe
  • line
  • file path
  • description