Skip to content

docs(connectors): document the YesWeHack connector#15288

Draft
devGregA wants to merge 1 commit into
DefectDojo:bugfixfrom
devGregA:sc-yeswehack_docs
Draft

docs(connectors): document the YesWeHack connector#15288
devGregA wants to merge 1 commit into
DefectDojo:bugfixfrom
devGregA:sc-yeswehack_docs

Conversation

@devGregA

Copy link
Copy Markdown
Contributor

Document the YesWeHack connector

Documentation for the new YesWeHack bug-bounty findings connector.

  • connectors_tool_reference.md — adds a YesWeHack section (alphabetical) covering:
    • Personal Access Token prerequisite (noting some accounts require TOTP/MFA at token creation).
    • Connector mappings: https://api.yeswehack.com/ in Location, the PAT in Secret, optional Minimum Severity.
    • The whole-account model — a Record per program the token can access — and how findings are mapped: severity from the report's CVSS rating (falling back to triage priority) and status from the report's workflow state (resolved → mitigated, invalid/out-of-scope → inactive).
  • about_connectors.md — lists YesWeHack among the supported connectors.

Companion PRs: connector implementation (DefectDojo-Inc/connectors#733) and DefectDojo-side registration (dojo-pro#1941).

Adds a YesWeHack section to the connectors tool reference (PAT auth via the
Location + Secret fields, whole-account program -> Record model, CVSS-based
severity and workflow-state-based status) and lists YesWeHack among the
supported connectors.
@github-actions github-actions Bot added the docs label Jul 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant