User Guide
Fortify Plugin for Bamboo
8. To run a scan, select the Run Fortify SCA Scan check box, and then specify the scan settings:
a. In the Result file box, type a name (and optionally the location) for the analysis results file
(<filename>.fpr).
b. To use a custom issue template for the scan, type the path to the template file in the Issue
Template box.
Note: This only affects scans on the local machine. If you upload the FPR to Fortify
Software Security Center, the results display uses the issue template assigned to the
application version.
c. (Optional) Specify any additional analysis options.
Note: Enclose each option and parameter in double quotes.
In the following example, two analyzers and quick scan mode are enabled for the scan:
"-analyzers" "controlflow,dataflow" "-quick".
d. To enable the debug or verbose options or to specify a custom location for the Fortify Static
Code Analyzer log file, click Advanced options.
9. To upload the scan results to Fortify Software Security Center, select the Upload Fortify
SCA scan results to Fortify Software Security Center, and then specify the upload settings:
a. In the Fortify Software Security Center URL box, type the Fortify Software Security Center
server URL.
b. To connect to the Fortify Software Security Center with a proxy server, select Configure proxy
server, and then specify the proxy information.
Note: Use the following syntax for the Proxy server URL:
<protocol>://<address>:<port>
c. Provide your Fortify Software Security Center credentials.
You must provide either:
o
A Fortify Software Security Center user name and password
o
A Fortify Software Security Center authentication token of type CIToken
Note: With Fortify Software Security Center versions 19.2.x and earlier, you can use
the authentication token type JenkinsToken.
d. Specify an application name and version.
To create a new application version, select Create new application version. This creates a
new application version if the application name and version specified do not currently exist on
Fortify Software Security Center.
e. To trigger a build failure based on scan results, type a search query in the Build failure criteria
box.
For example, the following search query causes the build to fail if any critical issues exist in the
scan results:
[fortify priority order]:critical
Micro Focus Fortify Plugin for Bamboo (1.10)
Page 12 of 14