Skip to content

Add Strix scan parser - #16079

Open
ummon-v wants to merge 6 commits into
DefectDojo:devfrom
ummon-v:feature/strix-parser
Open

ummon-v wants to merge 6 commits into
DefectDojo:devfrom
ummon-v:feature/strix-parser

Conversation

@ummon-v

@ummon-v ummon-v commented Sep 24, 2026

Copy link
Copy Markdown

Description

Adds a new parser for Strix, importing the vulnerabilities.json report of a Strix security run under the "Strix Scan" scan type.

  • One Finding per report entry; every field is optional per finding_class (code findings carry PoC/CVSS data, dependency findings carry package metadata), missing fields are left unset
  • Maps title, severity, impact, description (target/confidence/CVSS lines plus the analysis sections), steps to reproduce (PoC), mitigation (remediation steps + fix effort), CWE, CVE, CVSS score and vector, date, file_path/line from code locations, component name/version for dependency findings, and static/dynamic from finding_class
  • Unknown or missing severities default to Info
  • A non-array report raises an error instead of importing 0 findings; a wrapped {"vulnerabilities": [...]} shape is accepted for forward compatibility
  • Deduplication uses unique_id_from_tool, keyed on the report's stable per-finding id (registered in settings.dist.py)

Test results

  • unittests.tools.test_strix_parser: 15 tests covering no/one/many findings, full field mapping, dependency and code-location mapping, severity defaults, CWE extraction, CVSS vector assembly, wrapped report shape, and malformed input rejection
  • unittests.test_parsers meta-test passes (layout and docs checks)
  • Ruff clean (0.16.5)

Documentation

  • New parser page: docs/content/supported_tools/parsers/file/strix.md

Checklist

  • Rebased against the very latest dev
  • Submitted against dev (new feature)
  • Ruff compliant
  • Python 3.13 compliant
  • Documentation added under docs/
  • No model changes (no migrations needed)
  • Unit tests added
  • Labels applied

@github-actions github-actions Bot added settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR docs unittests parser labels Sep 24, 2026
@Maffooch Maffooch added this to the 3.4.0 milestone Sep 24, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs parser settings_changes Needs changes to settings.py based on changes in settings.dist.py included in this PR unittests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants