Fortify Software Security Center
The Fortify Software Security Center (SSC) connector integrates with a Micro Focus / OpenText Fortify SSC server over its REST API. It syncs applications (projects) and application versions (project versions) as assets, and the static and dynamic code findings recorded against those project versions, splitting each finding into a finding instance and a reusable finding definition. Application versions are additionally enriched with the project's configured custom attributes, performance indicators, and variables.
Fortify Static Code Analyzer
The Fortify Static Code Analyzer (SCA) connector ingests Fortify Project Results (FPR) archives produced by Micro Focus / OpenText Fortify SCA scans. Each FPR is a ZIP archive containing `audit.fvdl` (scan results) and an optional `audit.xml` (audit/suppression data). The connector parses these files to produce code projects, static code findings, and reusable static code finding definitions.
Fortify WebInspect
The Fortify WebInspect connector ingests dynamic application security testing (DAST) report files produced by Micro Focus / OpenText Fortify WebInspect. It parses the scanned issues into sites (the scanned web applications), dynamic code findings, and reusable dynamic code finding definitions.


