I'm wondering if anyone has integrated their Bamboo deployment with HP Fortify static code analyzer? If yes do you have any suggestions, best practices or sites with helpful information? We are a Java development shop and have a little PL/SQL too. We build our Java code with Maven. Thank you in advanced for any help you can offer.
Hi @Chris Flynn,
It looks like the fortify code analyser can be accessed via command line. This means that you can just use a script task to invoke this tool and achieve what you want.
Their documentation explains how to achieve this. A basic command sequence can be like this.
sourceanalyzer -b <build ID> <sourcecode>
sourceanalyzer -b <build ID> -scan -f <test>.fpr
fortifyclient.bat -url SSCServerUrl -authtoken XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX uploadFPR -file BuildID.fpr -project "MyProject" -version "MyProject v1.0.0"
Hope that helps.
Thank you for the help. Since we use Maven to build our applications we are able to take advantage of the HP Fortify Maven Plugin. The only thing missing is the ability to fail the build due to the scan results. However, looking at the new HP Fortify Bamboo plugin it appears the plugin has resolved this problem. So we should be all set now.
Thanks again for the help.
I am new to Fortify and trying to integrate with Bamboo, so my question is very basic, during the setup process, I have Fortify SCA and Applications installed on a Windows machine and my Bamboo is running on RHEL7 server with more than 1000 plans, so wondering do i need to installed SCA on Bamboo or do I need to install a seperate Bamboo on SCA windows server ?
I have installed Fortify SCA plugin, but it needs sce executable? confused ???
This might be a good question for the expert, but I think you would want to install a Bamboo Remote Agent on the Fortify Windows Machine. The Bamboo Fortify Plugin needs to know the location of your Fortify installation on the Windows machine, since it uses that installation to run Fortify scans. It should be a pretty straightforward configuration.
By using the Fortify Plugin for Bamboo it also sets a requirement for that plan that the agent it uses has to have the "Fortify" capability so it should automatically find that Windows machine Agent (assuming the Fortify installation is auto discovered during the remote agent installation.
This link has good information to start the Bamboo Remote Agent as a Windows Service:
This is the basic instructions for a remote agent:
Let me know if you have any other questions or if I was not clear on some point. Good luck!
@Sridhar Mudhagouni I'm sure you have this covered already, but make sure your Windows build server and the Bamboo server can communicate over the needed ports.
I went through a similar process recently and although documentation of the "Fortify App for Bamboo" plugin states it creates a Bamboo local server capability (and SCA needs to be installed on the Bamboo server), this seems to be no longer true and it actually can be used with Bamboo remote agents.
HP Fortify has a Maven Plugin that we used for the integration. We still have not taken on the challenge of failing the Bamboo build if HP Fortify finds any defects, but hopefully this new HP Fortify Bamboo Plugin will help with that functionality.
Ok cool. So in that case, you can base on the scan results file to generate a JUnit Report xml file then you can use JUnit Report Parser task to parse it
You can check it out it here:
With this way, you can configure Bamboo to fail when there is a defect