Ingest results from unsupported scanners
You can ingest results from scanners that don't support SARIF.
You can ingest custom issues from any scanning tool. STO supports a generic JSON format for ingesting data from unsupported scanners that cannot publish to SARIF.
Important notes for importing data from unsupported scanners into STO
This workflow is intended for scanners that have no supported integration in STO. Harness recommends that you always use the documented workflow for supported scanners. For a list of all STO-supported scanners, go to What's supported and click Harness STO scanner support to expand.
SARIF is an open data format supported by many scan tools. If your scanner supports this format, publish your results to SARIF. For more information, go to Ingest SARIF results.
For STO to ingest your scan results, the ingestion file must match the JSON format specified below.
Required steps to ingest data from unsupported scanners into STO
Add a shared path such as
/shared/scan_resultsto the stage. Go to Overview > Shared Paths in the visual editor, or add it to the YAML like this:- stage: spec: sharedPaths: - /shared/scan_resultsGenerate your issues data in the required JSON format described below and then save it in the shared folder. You might want to set up a Run step to generate your scans automatically whenever the pipeline runs. Go to Ingest Scan Results into an STO Pipeline for an example.
Add a Custom Ingest step and configure the scanner to ingest the results of the scan. For information about how to configure this step, go to Custom Ingest settings reference.
JSON data format reference
The following example illustrates the required format for your data. This comprehensive example shows all supported fields:
{
"meta": {
"key": ["issueName"],
"subproduct": "MyCustomScanner"
},
"issues": [
{
"issueType": "SAST",
"issueName": "Complete Example Issue",
"issueDescription": "This is a comprehensive example showing every possible field in the RefinedIssue class.",
"subproduct": "MyCustomScanner",
"referenceIdentifiers": [
{
"type": "cve",
"id": "2023-12345"
},
{
"type": "cwe",
"id": "79"
},
{
"type": "ghsa",
"id": "xxxx-yyyy-zzzz"
}
],
"cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"cvssVersion": "CVSS v3.1",
"cvss": 6.1,
"baseScore": 6.1,
"exploitabilityScore": 2.8,
"impactScore": 2.7,
"epss": 0.45,
"confidence": "High",
"effort": "Medium",
"originalSeverity": "High",
"severity": 8.0,
"remediationSteps": "Fix me fast by applying the latest security patch.",
"referenceUrls": "https://example.com/advisory,https://nvd.nist.gov/vuln/detail/CVE-2023-12345",
"fileName": "homepage-jobs.php",
"lineNumber": 127,
"endLine": 130,
"startCol": 8,
"linesOfCodeImpacted": 4,
"codeSnippet": "```php\necho $_GET['input'];\n// More vulnerable code here\n```",
"libraryName": "vulnerable-lib",
"licenseName": "MIT",
"currentVersion": "1.2.3",
"upgradeVersion": "1.2.4",
"author": "Library Author",
"fixAvailable": true,
"imageRegistry": "docker.io/mycompany/webapp",
"imageTag": "v2.1.0",
"dockerManifestDigest": "sha256:abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890",
"dockerIndexDigest": "sha256:1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdef",
"imageLayerId": "sha256:layer1234567890abcdef",
"host": "https://api.example.com",
"ip": "192.0.2.100",
"port": 8443,
"path": "/api/v1/users",
"method": "POST",
"project": "MyProjectName",
"_raw": {
"scannerVersion": "2.5.1",
"ruleId": "CUSTOM-001",
"customMetric": 42,
"tags": ["security", "injection", "web"],
"anyOtherField": "Scanners can include any additional custom data here"
}
}
]
}The basic schema includes a “meta” section, which requires the following:
“key”The name of the attribute used to deduplicate multiple occurrences of an issue. In the example data file above,
"key"="issueName". Thus if the data includes multiple occurrences of an issue with the same"issueName", the pipeline combines these occurrences into one issue. The resulting issue includes a list of all occurrences and the data for each individual occurrence.The key used for deduplication must be a Harness field. Do not try to deduplicate based on non-Harness fields.
“subproduct”The scan tool name to apply to the overall issue. The product will be "Custom", so specifying a subproduct like "MyScanner" will display as "Custom - MyScanner" in the Harness UI (in scanner dropdowns, etc.).
The full JSON takes the form:
Required fields
Name
Format
Description
issueName
String
Name of vulnerability, license issue, compliance issue, etc.
issueDescription
String (long)
Description of vulnerability, license issue, compliance issue, etc. Supports Markdown formatting, which will be rendered in the Harness UI.
subProduct
String
The scan tool name to apply to the individual occurrence of the issue. Displays as "Custom - [subProduct]" in the Harness UI.
severity
Float
CVSS 3.0 score (a number from 1.0-10.0).
Other supported fields
Name
Format
Description
issueType
String
Type of issue. Valid values: SAST, DAST, SCA, IAC, SECRET, MISCONFIG, BUG_SMELLS, CODE_SMELLS, CODE_COVERAGE, EXTERNAL_POLICY.
referenceIdentifiers
Array
An array of vulnerability identifiers, such as cve, cwe, ghsa, etc. Note that the type value must be lowercase. Example: "referenceIdentifiers": [{"type": "cve", "id": "2023-12345"}, {"type": "cwe", "id": "79"}]
remediationSteps
String (long)
Remediation instructions, often provided by the scan tool.
referenceUrls
String
Comma-separated list of reference URLs for the vulnerability.
cvss
Float
The CVSS score value.
cvssVector
String
The full CVSS vector string. Example: "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
cvssVersion
String
The CVSS version used. Example: "CVSS v3.1"
baseScore
Float
The CVSS base score.
exploitabilityScore
Float
The CVSS exploitability sub-score.
impactScore
Float
The CVSS impact sub-score.
epss
Float
The Exploit Prediction Scoring System (EPSS) score (0.0-1.0).
originalSeverity
String
The original severity as reported by the scanner. Example: High, Medium, Low, Critical.
confidence
String
Confidence level of the finding. Example: High, Medium, Low.
effort
String
The estimated effort required to remediate. Example: Low, Medium, High.
fileName
String
The file where the issue was found.
lineNumber
Integer
The starting line number of the issue.
endLine
Integer
The ending line number of the issue.
startCol
Integer
The starting column number of the issue.
linesOfCodeImpacted
Integer
The number of lines of code affected by the issue.
codeSnippet
String
A code snippet showing the vulnerable code. Supports Markdown code blocks.
libraryName
String
The name of the vulnerable library or dependency.
currentVersion
String
The current version of the vulnerable library.
upgradeVersion
String
The recommended version to upgrade to for remediation.
fixAvailable
Boolean
Indicates whether a fix is available for the vulnerability.
licenseName
String
The license of the library. Example: MIT, Apache-2.0.
author
String
The author or maintainer of the library.
imageRegistry
String
The container image registry and repository. Example: docker.io/mycompany/webapp
imageTag
String
The container image tag. Example: v2.1.0
dockerManifestDigest
String
The SHA256 digest of the Docker manifest.
dockerIndexDigest
String
The SHA256 digest of the Docker index.
imageLayerId
String
The ID of the image layer where the issue was found.
imageNamespace
String
Logical metadata field for image namespace.
host
String
The target host URL. Example: https://api.example.com
ip
String
The target IP address.
port
Integer
The target port number.
path
String
The URL path where the issue was found. Example: /api/v1/users
method
String
The HTTP method used. Example: GET, POST, PUT, DELETE.
url
String
The full URL where the issue was found.
project
String
Logical metadata field that can be used for tracking of project(s).
product
String
Logical metadata field that can be used for tracking of product(s).
scanSeverity
String
The severity as reported by the scan tool.
scanStatus
String
Recommended for measuring scan duration and status.
tags
String
Logical metadata tags for describing asset owners, teams, business units, etc.
link
String
A link to additional information about the issue.
Custom fields
You can add custom fields to an issue to include scanner specific data that isn't covered by the standard fields. There are two approaches:
Option 1: Use the _raw object
You can include a _raw object in your issue to store any additional custom data. This is the recommended approach for grouping related custom fields:
Option 2: Use _raw prefix for individual fields
Alternatively, you can add the prefix _raw to individual field names:
The custom fields will get grouped together at the end of the issue details like this:
Reserved keywords for Harness STO JSON schema
The following keywords are reserved and cannot be used in your JSON file:
alertRulesetscustomerIddiscoveryIssueIddiscoveryRunTimediscoveryTimespanignoreignoreRulesetsjobIdpolicyIdpolicyNamerefinementVersionremediationRunTimeremediationTimespanrunTimescenarioIdseverityCodetargettargetId
Pipeline example for ingesting data from an unsupported schema into STO
The following pipeline shows an end-to-end ingestion workflow. The pipeline consist of a Security stage with two steps:
A Run step that generates a JSON data file
/shared/scan_results/example.jsonin the format described above.A Custom Ingest step that ingests and normalizes the data from
/shared/scan_results/example.json.
jq filters
You can use jq filters to transform scanner results into the format needed for ingestion. Find the specific filter for your scanner below. Save this filter to a file (e.g., my_filter.jq). Then, process the scan results by passing the filter file and the results file to jq like this:
This command uses the filter to generate the correctly formatted output.
Last updated
Was this helpful?