Skip to content

docs(connectors): HCL AppScan connector reference#15312

Draft
devGregA wants to merge 1 commit into
DefectDojo:bugfixfrom
devGregA:sc_hclappscan_docs
Draft

docs(connectors): HCL AppScan connector reference#15312
devGregA wants to merge 1 commit into
DefectDojo:bugfixfrom
devGregA:sc_hclappscan_docs

Conversation

@devGregA

Copy link
Copy Markdown
Contributor

What

Adds the HCL AppScan connector to the Pro connector tool reference. AppScan (AppScan on Cloud + self-hosted AppScan 360°, sharing the v4 REST API) is a DAST/SAST/IAST application-security platform; the connector syncs the whole account — application → Record, issue → finding.

Companion to:

  • DefectDojo-Inc/connectors#749 (the Go connector)
  • DefectDojo-Inc/dojo-pro#1990 (Pro-UI registration)

Section covers

  • Prerequisites: an AppScan API Key ID + Key Secret (exchanged for a short-lived session token; never logged).
  • Connector mappings: Location (ASoC https://cloud.appscan.com / EU host, or the A360 instance host), Provider ASOC/A360, API Key ID + API Key Secret, optional Minimum Severity.
  • Mapping model: application → Record; issue → finding (title suffix chain, severity Informational→Info, CWE, remediation/advisory, host:port endpoint, static/dynamic by scan technology, open→active / fixed→mitigated).

Live validation needs an ASoC trial tenant or an AppScan 360° instance; details in connectors#749 (outstanding follow-up).

Base: bugfix.

Document the HCL AppScan connector (ASoC + AppScan 360°): prerequisites
(API Key ID/Secret), the Location/Provider/Minimum-Severity mappings, and
the whole-account application -> Record + issue -> finding model (title
suffixes, severity map, CWE, remediation/advisory, host:port endpoint,
static/dynamic by scan technology, status).

Companion to connectors#749 and dojo-pro#1990.

sc-13873

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actions github-actions Bot added the docs label Jul 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant