Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Automatically create new issue of Github CodeQL vulnerabilities

Harvey Tong
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 9, 2024

I have Github Advance Security CodeQL in my repo, also already integrated github to Jira, and also turn on the security.  After the CodeQL scan, there has over 5000 vulnerabilities were found.

I could create issue one by one, but there are over 5000 issues, also could it be like automatically create issues whenever a new vulnerabilities found?

jira5000.png

2 answers

0 votes
Brian Kushner
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 20, 2024

You can do an automation based on vulnerabilities found as was suggested just make sure you do a check for status is open. All vulnerabilities of all statuses are going to import. The one thing I’m struggling with is a duplicate checking logic on whether there is a similar or identical issue created based on the vulnerability. 

0 votes
Marc - Devoteam
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 9, 2024

Hi @Harvey Tong 

Welcome to the community.

I'm not familiar with this integration yet.

You could look at the automation trigger "Vulnerability" found and based on the severity.

Then add conditions and actions as in a normal automation rule.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events