Skip to content

KICS partial import #7966

@Acsigen

Description

@Acsigen

Bug description
When importing a KICS json report, not all vulnerabilities are displayed in DefectDojo when compared to html version of KICS.

Steps to reproduce
Steps to reproduce the behavior:

  1. Perform KICS scan with output as JSON and HTML
  2. Import the report to a DefectDojo project
  3. Compare the number of findings between DefectDojo and KICS HTML

Expected behavior
The number of vulnerabilities should be the same

Deployment method (select with an X)

  • Docker Compose
  • Kubernetes
  • GoDojo

Environment information

  • Operating System: Ubuntu 22.04
  • DefectDojo version: 2.21.0

Screenshots
KICS HTML report:
image

DefectDojo Vulnerabilities count after importing the KICS report:
image

Workaround:
Set the output format of KICS to Gitlab SAST and then import it in DefectDojo as Gitlab SAST.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions