OpenText Fortify integration
Add exploitability analysis to Fortify findings and prioritize based on environment-specific conditions.
Integration details
Primary category
Static Application Security Testing
Sync direction
OpenText Fortify ↔ Konvu
Findings are ingested from OpenText Fortify into Konvu. What Konvu writes back to OpenText Fortify depends on the integration.
Status
Coming soon
What is OpenText Fortify?
OpenText Fortify provides enterprise SAST capabilities through Fortify Static Code Analyzer, identifying security vulnerabilities in source code across multiple languages.
Why connect OpenText Fortify to Konvu
- Prioritize which Fortify-detected CWEs represent exploitable vulnerabilities versus theoretical weaknesses.
- Reduce remediation backlog from Fortify scans by focusing developers on findings with supporting evidence.
- Build audit trails connecting Fortify's detailed vulnerability reports to triage outcomes.
How it works
Scan
OpenText Fortify produces findings from scans or assessments.
Ingest & enrich
Konvu ingests those findings and enriches them with code, configuration, and deployment context.
Assess exploitability
Konvu determines exploitability and recommended action with evidence attached.
Record decisions
Konvu records each verdict with its evidence. What it can write back to OpenText Fortify depends on the integration.
Quick setup
When OpenText Fortify is available, you’ll configure it from the integrations list in Konvu.
- 1Go to /configuration/integrations in Konvu and choose OpenText Fortify.
- 2Authorize access and confirm the data sources you want to sync.
- 3Save the configuration to start syncing.
Sync direction
OpenText Fortify ↔ Konvu
Findings are ingested from OpenText Fortify into Konvu. What Konvu writes back to OpenText Fortify depends on the integration.
Join the waitlist
We’ll let you know when the OpenText Fortify integration is ready. Leave your email to get updates.
More integrations
View allArnica
Add exploitability verdicts with evidence to Arnica SCA and SAST findings, and send approved SCA dismissals back to Arnica.
- SCA
- SAST
- ASPM
Black Duck
Get an exploitability verdict with evidence for Black Duck Polaris SCA findings and Coverity SAST findings.
- SCA
- SAST
Checkmarx
Send Checkmarx One SCA and SAST results to Konvu for an exploitability verdict with evidence, through the Konvu API or a report upload.
- SAST
- SCA
CodeQL
Check whether each CodeQL security alert is exploitable, and dismiss the false positives in GitHub code scanning.
- SAST
GitHub
Prioritize GitHub CodeQL and Dependabot alerts by adding exploit context to each finding.
- SAST
- SCA
- Ticketing & Messaging
GitLab
Add exploitability analysis to GitLab's built-in SAST and SCA pipeline findings.
- SCA
- SAST
- Ticketing & Messaging