User Guide
Scanning with Fortify ScanCentral SAST
l
A Fortify Software Security Center URL or a ScanCentral SAST Controller that is integrated with a
Fortify Software Security Center server.
Note: Fortify recommends that the Fortify Software Security Center URL configured in the
analysis settings (Synchronize Options) is the same as the Fortify Software Security Center
server integrated with the ScanCentral SAST Controller.
l
A Fortify Software Security Center authentication token of type ToolsConnectToken
For instructions about how to create an authentication token, see the OpenText™ Fortify Software
Security Center User Guide.
l
An application version that exists in Fortify Software Security Center
l
Permission to access the application and application version to which you want to upload
See Also
Configuring Fortify ScanCentral SAST Options
This topic describes how to configure the default Fortify ScanCentral SAST options used when you
submit a project for analysis. You can specify how to connect to the Fortify ScanCentral
SAST Controller , whether to upload analysis results to Fortify Software Security Center, and other
Fortify ScanCentral SAST settings such as inclusion of test files, sensor pool selection, and notification
email address). You can also specify Fortify Static Code Analyzer translation and scan options to
include in the analysis.
To configure the Fortify ScanCentral SAST options:
1. Select Tools > Fortify > Analysis Settings.
2. To configure the Fortify ScanCentral SAST client location:
a. Select the Analysis Configuration tab.
b. To the right of the Fortify Executable Path box, click Browse, and do one of the following:
o
If you installed Fortify Static Code Analyzer that includes an embedded Fortify
ScanCentral SAST client, go to <sca_install_dir>/bin/and select
sourceanalyzer.exe(on Windows) or sourceanalyzer(on non-Windows).
o
To select a standalone client installed with Fortify Applications and Tools, go to <tools_
install_dir>/bin/and select scancentral.bat(on Windows) or scancentral(on
non-Windows).
o
To select a standalone client installed in a different location, select scancentral.bat
(on Windows) or scancentral(on non-Windows).
3. Select the ScanCentral SAST Configuration tab.
OpenText™ Fortify Analysis Plugin for IntelliJ IDEA and Android Studio (24.2.0)
Page 26 of 34