Safety

Import Safety reports in JSON format. Safety checks installed Python packages against the PyUp advisory database.

Generate a report with:

safety check --json --output safety.json

Severity Mapping

PyUp assigns a severity only to some advisories. Its own PVE- advisories frequently carry neither a CVE nor a severity, so DefectDojo maps what is present and defaults the rest to Medium rather than inventing a scale:

Safety severityDefectDojo severity
criticalCritical
highHigh
mediumMedium
lowLow
absentMedium

Advisories that carry a CVE have it recorded as a vulnerability id; PyUp’s own numeric advisory id is always kept in vuln_id_from_tool. Advisories the user has ignored stay in Safety’s report, flagged rather than removed, and are not imported.

Sample Scan Data

Sample Safety scans can be found here.

Default Deduplication Hashcode Fields

By default, DefectDojo identifies duplicate Findings using these hashcode fields:

  • vuln_id_from_tool
  • component_name
  • component_version