Edgescan
⚠️ Deprecated — removed in DefectDojo 3.5.0.
The Edgescan API pull path described below, and the Tool Configuration it depends on, are deprecated as of 3.2.0 and will be removed in 3.5.0 (November 2026). See the 3.2 upgrade notes.
Migrate to: the Edgescan connector (DefectDojo Pro), or import Edgescan results as a JSON file — file import is not affected by this deprecation.
Import Edgescan vulnerabilities by API or JSON file.
All parsers which using API have common basic configuration step but with different values. Please, read these steps at first.
Step 1: Add tool configuration
- Select the gear icon from the left hand side of the page.
- Click on the
Tool Configurationoption and then+ Add Tool Configurationfrom the dropdown menu. - Once presented with a series of fields, set
Tool Typeto “Edgescan” andAuthentication Typeto “API Key”. - Paste your Edgescan API key in the
API Keyfield. - Click on the
Submitbutton.
Step 2: Add and configure a product
- Select the hamburger menu icon from the left hand side of the page.
- Click on the
All Productsoption and then+ Add Product. - Fill in the fields presented.
- Once the product is added, click on the
Settingsoption thenAdd API Scan Configuration. - Select the previously added Edgescan
Tool Configuration. - Provide the edgescan asset ID(s) that you wish to import the findings for in the field
Service key 1.- Note that multiple asset IDs should be comma separated with no spacing.
- If you want to import vulnerabilities for all assets, simply leave the Service key 1 field empty.
Step 3: Importing scan results
- After the previous steps are complete, you can import the findings by selecting the
Findingsoption on the product’s page and thenImport Scan Results. - Once you are presented with a series of fields, select
Edgescan Scanas the scan type.- If you have more than one asset configured, you must also select which Edgescan
API Scan Configurationto use.
- If you have more than one asset configured, you must also select which Edgescan
- Click on the
Importbutton.
Important Reminder:
- To ensure you’re not introducing duplicate vulnerabilities, always use the “Re-Upload Scan” option when re-importing findings from Edgescan. This can be found within the engagement’s options by clicking on
Engagements, then the active engagement in question, thenEdgescan Scanand selecting “Re-Upload Scan” from the dropdown menu located on the right.