Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
Community Members
Community Events
Community Groups

Has anyone integrated Bamboo with HPE/Micro Focus Fortify?


I'm wondering if anyone has integrated their Bamboo deployment with HP Fortify static code analyzer? If yes do you have any suggestions, best practices or sites with helpful information? We are a Java development shop and have a little PL/SQL too. We build our Java code with Maven. Thank you in advanced for any help you can offer.

3 answers

Hi @Chris Flynn,

It looks like the fortify code analyser can be accessed via command line. This means that you can just use a script task to invoke this tool and achieve what you want.

Their documentation explains how to achieve this. A basic command sequence can be like this.

  • builds the code using
sourceanalyzer -b <build ID> <sourcecode>
  • scans the build with
sourceanalyzer -b <build ID> -scan -f <test>.fpr
  •  Upload to server
fortifyclient.bat -url SSCServerUrl -authtoken XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX uploadFPR -file BuildID.fpr -project "MyProject" -version "MyProject v1.0.0"

Hope that helps. 

Thank you for the help. Since we use Maven to build our applications we are able to take advantage of the HP Fortify Maven Plugin. The only thing missing is the ability to fail the build due to the scan results. However, looking at the new HP Fortify Bamboo plugin it appears the plugin has resolved this problem. So we should be all set now.

Thanks again for the help.

Hi Chris,

I am new to Fortify and trying to integrate with Bamboo, so my question is very basic, during the setup process, I have Fortify SCA and Applications installed on a Windows machine and my Bamboo is running on RHEL7 server with more than 1000 plans, so wondering do i need to installed SCA on Bamboo or do I need to install a seperate Bamboo on SCA windows server ?

I have installed Fortify SCA plugin, but it needs sce executable? confused ???




Like Chris Flynn likes this

This might be a good question for the expert, but I think you would want to install a Bamboo Remote Agent on the Fortify Windows Machine. The Bamboo Fortify Plugin needs to know the location of your Fortify installation on the Windows machine, since it uses that installation to run Fortify scans. It should be a pretty straightforward configuration.

By using the Fortify Plugin for Bamboo it also sets a requirement for that plan that the agent it uses has to have the "Fortify" capability so it should automatically find that Windows machine Agent (assuming the Fortify installation is auto discovered during the remote agent installation.

This link has good information to start the Bamboo Remote Agent as a Windows Service:

This is the basic instructions for a remote agent:


Let me know if you have any other questions or if I was not clear on some point. Good luck!

Thanks Chris, I did install Bamboo Agent on the Windows machine and created a Bamboo plan but looks like i have some failures related to Fortify scan -clean

Thanks again for a quick respoonse

Sridhar Mudhagouni

Like Chris Flynn likes this

@Sridhar Mudhagouni I'm sure you have this covered already, but make sure your Windows build server and the Bamboo server can communicate over the needed ports.

Hi Sridhar,

I went through a similar process recently and although documentation of the "Fortify App for Bamboo" plugin states it creates a Bamboo local server capability (and SCA needs to be installed on the Bamboo server), this seems to be no longer true and it actually can be used with Bamboo remote agents.




0 votes
Jeyanthan I Atlassian Team Apr 07, 2018

Glad you figured it out :)

Like Jeyanthan I likes this
0 votes
Minh Tran Atlassian Team Apr 05, 2018

Hi @Chris Flynn, I haven't used HP Fortify static code analyzer before. Does HP Fortify static code analyzer provide a CLI tool for running? 

HP Fortify has a Maven Plugin that we used for the integration. We still have not taken on the challenge of failing the Bamboo build if HP Fortify finds any defects, but hopefully this new HP Fortify Bamboo Plugin will help with that functionality.

Minh Tran Atlassian Team Apr 06, 2018

@Chris Flynn Does HP Fortify generate any kind of reports when having any defects?

Hi @Minh Tran, You should watch the little video that comes with the plugin, it is pretty informative.

The HP Fortify scan does produce a FPR file with the scan results.

Minh Tran Atlassian Team Apr 08, 2018

Ok cool. So in that case, you can base on the scan results file to generate a JUnit Report xml file then you can use JUnit Report Parser task to parse it

You can check it out it here:


With this way, you can configure Bamboo to fail when there is a defect

Hi @Minh Tran -- just to follow up, I don't think the FPR file produced by the Fortify scan is in the JUnit xml format. Thank you for the help though.

Suggest an answer

Log in or Sign up to answer

Atlassian Community Events