Fortify Software Security Center (SSC) provides centralised management of their application security testing. Security teams use SSC to review and manage security testing activities, prioritize remediation efforts based on risk potential, measure improvements and generate cross portfolio management reports. The Fortify SSC plugin for Digital.ai Release can evaluate code against the security metrics that are most important for your organization. Built-in code analysis also ensures that code is always automatically checked against compliance requirements as part of the release process.
Steps
fortify.Server: Connection definition for Fortify SSC Server
fortify.task: Abstract base task which can be extended by other tasks
fortify.checkCompliance: Creates a gate in the release flow. If the minimum security rating isn’t met for the specified project name and version, it can stop the flow.
fortify.FortifySummaryTile: Displays issue metrics from Fortify SSC for the configured application and version.
fortify.FortifyComplianceTile: Displays the compliance status of the configured application in a given time frame.