Endor Labs integration
Add an exploitability verdict with evidence to Endor Labs SCA findings, on top of Endor's own reachability.
Integration details
Primary category
Software Composition Analysis
Sync direction
Endor Labs → Konvu
Konvu reads Endor Labs findings once a day and on demand with read-only credentials. Verdicts go out as fix pull requests, Slack alerts, and through the Konvu API.
Status
Available
Reachable is not the same as exploitable
Endor Labs tells you whether a vulnerable function is reachable. The vulnerability may still need a configuration, a runtime, or input an attacker cannot supply. Konvu reads Endor Labs findings with their reachability tags and checks those remaining conditions in your code, then returns a verdict with evidence. Exploitable findings can go straight to a fix pull request.
Endor Labs findings Konvu analyzes
SCA
Endor Labs
Open source dependency findings, with the reachability tags Endor Labs assigned.
Not imported today
- Endor Labs findings outside the SCA category
Access and setup
An Endor Labs API key and secret, created under Settings > API Keys, plus the namespace to import. One connection covers one namespace.
To read findings
- Read access to Projects
- Read access to Findings
To write back
No write access is needed.
- Konvu reads your code through your GitHub or GitLab connection, not through Endor Labs.
How Konvu investigates Endor Labs findings
What Konvu receives
The Endor Labs finding: the package, version, advisory, and Endor's reachability tags.
What Konvu checks
- Whether the reachable function is called with input an attacker controls.
- Whether your runtime, framework, and configuration match what the exploit needs.
- Whether a safe API variant or validation sits between the input and the vulnerable call.
What decides the verdict
Konvu returns exploitable, false positive, or inconclusive, with the reasoning behind it: the code it read, the conditions it tested, and what settled the call. When the answer depends on something only your team knows, Konvu asks a question instead of guessing.
Illustrative example
A SnakeYAML finding from Endor Labs
A made-up service, written to show how an investigation reads. Not a customer result.
- 1
Scanner finding
Endor Labs reports CVE-2022-1471 in SnakeYAML 1.33 for a Java service and tags the vulnerable constructor as reachable. SnakeYAML before 2.0 can create arbitrary types when it loads untrusted YAML with its default constructor.
- 2
Application context
The service accepts YAML workflow definitions through an authenticated API endpoint.
- 3
Investigation
Konvu follows the request body from the upload endpoint to new Yaml().load(), which uses the default constructor with no type restrictions. Any authenticated user can reach the endpoint, and no SafeConstructor or type allowlist sits in between.
- 4
Verdict
Exploitable. An authenticated user can send YAML that creates arbitrary classes on the classpath.
- 5
Evidence
The endpoint, the path from the request body to Yaml.load, and the constructor configuration Konvu checked.
- 6
Where it ends up
The finding is marked exploitable in Konvu with its evidence, and Konvu can propose the SnakeYAML upgrade as a pull request through your GitHub or GitLab connection.
Writeback and controls
Where results go
- Exploitable dependency findings can become a fix pull request in GitHub or GitLab, opened automatically if you turn that on for the repository.
- Exploitable findings can be posted to Slack, so the team hears about them without opening Konvu.
- Every verdict and its evidence can be pulled into your own tools through the Konvu API or CLI.
Who triggers it
Konvu imports findings on its daily schedule and when you run a sync. What to do with a verdict is up to your team.
What stays with your team
- Dismissing or updating findings in Endor Labs.
The technical detail
More integrations
View allArnica
Add exploitability verdicts with evidence to Arnica SCA and SAST findings, and send approved SCA dismissals back to Arnica.
- SCA
- SAST
- ASPM
Black Duck
Get an exploitability verdict with evidence for Black Duck Polaris SCA findings and Coverity SAST findings.
- SCA
- SAST
Checkmarx
Send Checkmarx One SCA and SAST results to Konvu for an exploitability verdict with evidence, through the Konvu API or a report upload.
- SAST
- SCA
Dependabot
Get an exploitability verdict for each Dependabot alert, and dismiss the false positives in GitHub with the evidence linked.
- SCA
GitHub
Prioritize GitHub CodeQL and Dependabot alerts by adding exploit context to each finding.
- SAST
- SCA
- Ticketing & Messaging
GitLab
Add exploitability analysis to GitLab's built-in SAST and SCA pipeline findings.
- SCA
- SAST
- Ticketing & Messaging