User Guide
Getting Started
Getting Started
This guide provides information about how to install and use the Fortify Security Assistant Plugin for
Eclipse.
Fortify Security Assistant Plugin for Eclipse
Fortify Security Assistant Plugin for Eclipse (Fortify Security Assistant for Eclipse) is a plugin that
integrates with the Eclipse Java development environment. Fortify Security Assistant for Eclipse
works with a portion of the Fortify security content to provide alerts to potential security issues as
you write your Java code. Fortify Security Assistant for Eclipse provides detailed information about
security risks and recommendations for how to secure the potential issue.
Fortify Security Assistant includes the semantic and intra-class data flow analyzers to detect:
l
Potentially dangerous uses of functions and APIs
l
Issues caused by tainted data reaching vulnerable functions and APIs at the intra-class level
Software Requirements
Fortify Security Assistant for Eclipse requires:
l
A valid Fortify license
You are prompted to provide a license file the first time you make edits to source code, request to
analyze a project, or load Fortify Software Security Content. For information about how to obtain a
Fortify license file, contact Customer Support.
l
Up-to-date Fortify Software Security Content
Fortify Security Assistant uses a knowledge base of rules to enforce secure coding standards
applicable to the codebase for static analysis. Fortify Software Security Content consists of Fortify
Secure Coding Rulepacks, which describe general secure coding idioms for popular languages and
public APIs.
To update Fortify Software Security Content, do one of the following:
l
Download the Fortify security content directly from the Fortify Rulepack update server or from
an OpenText™ Fortify Software Security Center server.
Important! To download security content from a Fortify Software Security Center URL or
the Fortify Rulepack update server that uses HTTPS, you must import a self- or locally-
signed certificate into the Java Runtime Environment (JRE) certificate store.
l
Load Fortify security content from a copy on your local system.
OpenText™ Fortify Security Assistant Plugin for Eclipse (24.2.0)
Page 7 of 20