Sonatype for Fortify SSC

327192

Sonatype Community

App Support Tiers

OpenText SUPPORTED

Support via OpenText Software Support, with a ticket filed against the associated product.

PARTNER

OpenText offers a content partnership program for select partners. Support for Partner Content offerings is provided by the partner and not by OpenText of the OpenText community.

OpenText COMMUNITY

OpenText Community Content is provided by OpenText for the benefit of customers, support for it is not available via OpenText Software Support but through specific community content forums.

COMMUNITY

Community Contributed Content is provided by OpenText customers and supported by them.

EARLY ACCESS

Show less ...Show more

The downloads referenced under the "Cybersecurity Early Access" category are made available to subscribers to mitigate time-critical issues but have not undergone formal quality and performance testing associated with official OpenText/Cybersecurity product releases. OpenText has a multi-stage Quality Assurance process. During Stage 1 we conduct a resource analysis, field mapping, ensure content level 1 functionality and analysis in our sandbox environment. Stage 2 is a complete validation including production validation. This package has cleared Stage 1 validation and therefore should be deployed with the appropriate pre-production validation. OpenText strongly recommends that any downloaded content is first checked and tested thoroughly in a non-production environment before committing to production. We welcome feedback and, should any content be shown to be faulty, detrimental or carry an incorrect claim of authorship, we shall endeavor to remove or correct such content as promptly as reasonably possible once notified and validated.

Sonatype | Community

Gain a 360 degree view of your application security posture by combining SaST, DaST, and IaST findings in Fortify SSC with the world’s leading open-source security data from Sonatype.
924 downloads
GET NEWEST
See previous releases
Share
 
  • Parser Plugin
  • Artifact History
  • Vulnerable OSS Findings
  • Vulnerable OSS Details

Description

Sonatype Lifecycle is a leading Software Composition Analysis (SCA) tool providing enterprises with real-time visibility and control over open-source dependencies across the Software Development Lifecycle (SDLC). Compliment your SaST, DaST and IaST finding in Fortify SSC with the world’s leading Open Source security vendor.

This solution is ideal for organizations seeking comprehensive, automated protection against software supply chain risks. With Lifecycle, you can:

  • Automatically identify vulnerabilities
  • Apply policies on security, legal, quality, and architectural constraints
  • Prioritize fixing issues efficiently without false positives
  • Integrate security into existing CI/CD workflows

Lifecycle’s advanced dependency management and AI-driven insights help developers maintain high code quality and security while accelerating delivery. This solution is ideal for organizations seeking comprehensive, automated protection against software supply chain risks.
Sonatype for Fortify SSC integration accomplishes this with:

  • A Service which looks for new reports in Nexus Lifecycle and pushes findings to Fortify SSC on a periodic basis (configurable)
  • A configurable mappings file to correlate application/phase reports in Lifecycle with application/version in SSC
  • A plugin for Fortify SSC which parses Lifecycle findings

This plugin is free for all Sonatype Lifecycle customers.

Minimum Requirements

The plugin parser and integration have been developed and tested with Fortify SSC versions 19 and later

Suggested apps

Suggested for you are based on app category, product compatibility, popularity, rating and newness. Some apps may not show based on entitlements. Learn more about entitlements.

Releases

Release
Date
SonatypeFortifyBundle 5.3.0
Mar 3, 2025
More info Less info
SonatypeFortifyBundle 5.2.1
Feb 11, 2025
More info Less info
SonatypeFortifyBundle 5.2.0
Feb 6, 2025
More info Less info
SonatypeFortifyBundle 5.1.3
Jan 23, 2025
More info Less info
SonatypeFortifyBundle 5.1.2
Nov 14, 2024
More info Less info
SonatypeFortifyBundle 5.1.1
Oct 7, 2024
More info Less info
SonatypeFortifyBundle 5.1.0
Sep 11, 2024
More info Less info
SonatypeFortifyBundle 5.0.1
May 22, 2024
More info Less info
SonatypeFortifyBundle 5.0.0
Apr 29, 2024
More info Less info
SonatypeFortifyBundle 4.3.1
Feb 5, 2024
More info Less info
SonatypeFortifyBundle 4.3.0
Oct 27, 2023
More info Less info
SonatypeFortifyBundle 4.2.13
Aug 22, 2023
More info Less info
SonatypeFortifyBundle 4.2.12
Jun 26, 2023
More info Less info
SonatypeFortifyBundle 4.2.11
Jun 20, 2023
More info Less info
SonatypeFortifyBundle 4.2.10
May 24, 2023
More info Less info
SonatypeFortifyBundle 4.2.9
May 2, 2023
More info Less info
SonatypeFortifyBundle 4.2.7
Feb 13, 2023
More info Less info
SonatypeFortifyBundle 4.2.6
Nov 29, 2022
More info Less info
SonatypeFortifyBundle 4.2.5
Oct 12, 2022
More info Less info
SonatypeFortifyBundle 4.2.4
Oct 10, 2022
More info Less info
SonatypeFortifyBundle 4.2.2
Aug 12, 2022
More info Less info
SonatypeFortifyBundle 4.2.0
May 6, 2022
More info Less info
SonatypeFortifyBundle 19.2.0.9
21.6 MB
  |  
Nov 13, 2019
More info Less info

Resources

Reviews

Write a review


Sonatype for Fortify SSC

Sonatype | Community




Optional


Optional - 120 characters remaining


Cancel

Aug 23, 2022

Jason Kinsfather

Nov 19, 2020

anthony baer

Dec 21, 2018

Curtis Yanko

Unsubscribe from notifications

You are receiving release updates for this item because you have subscribed to the following products:
If you unsubscribe, you will no longer receive any notifications for these products.
Tip: to update your subscription preferences, go to Manage Subscriptions from your Dashboard, uncheck the products you no longer want to receive notifications for, and click 'Save'.

Marketplace Terms of Service

In order to continue, you must accept the updated Marketplace Terms of Service
Since you are downloading an app from the OpenText Marketplace, you need to accept the updated Marketplace Terms of Service before you can continue. Use the link to review the Marketplace Terms of Service. Once complete check the, "I accept the Marketplace Terms of Service" box below and click accept to continue your download.


Your download has begun...

Your download has begun

Related content and resources

Your browser is not supported!

Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox

release-rel-2025-3-2-6337 | Mon Mar 17 22:14:31 PDT 2025