I'm wondering if anyone has integrated their Bamboo deployment with HP Fortify static code analyzer? If yes do you have any suggestions, best practices or sites with helpful information? We are a Java development shop and have a little PL/SQL too. We build our Java code with Maven. Thank you in advanced for any help you can offer.
Hi @Chris Flynn,
It looks like the fortify code analyser can be accessed via command line. This means that you can just use a script task to invoke this tool and achieve what you want.
Their documentation explains how to achieve this. A basic command sequence can be like this.
sourceanalyzer -b <build ID> <sourcecode>sourceanalyzer -b <build ID> -scan -f <test>.fprfortifyclient.bat -url SSCServerUrl -authtoken XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX uploadFPR -file BuildID.fpr -project "MyProject" -version "MyProject v1.0.0"Hope that helps.
Thank you for the help. Since we use Maven to build our applications we are able to take advantage of the HP Fortify Maven Plugin. The only thing missing is the ability to fail the build due to the scan results. However, looking at the new HP Fortify Bamboo plugin it appears the plugin has resolved this problem. So we should be all set now.
Thanks again for the help.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Chris,
I am new to Fortify and trying to integrate with Bamboo, so my question is very basic, during the setup process, I have Fortify SCA and Applications installed on a Windows machine and my Bamboo is running on RHEL7 server with more than 1000 plans, so wondering do i need to installed SCA on Bamboo or do I need to install a seperate Bamboo on SCA windows server ?
I have installed Fortify SCA plugin, but it needs sce executable? confused ???
Thanks,
Sri
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
This might be a good question for the expert, but I think you would want to install a Bamboo Remote Agent on the Fortify Windows Machine. The Bamboo Fortify Plugin needs to know the location of your Fortify installation on the Windows machine, since it uses that installation to run Fortify scans. It should be a pretty straightforward configuration.
By using the Fortify Plugin for Bamboo it also sets a requirement for that plan that the agent it uses has to have the "Fortify" capability so it should automatically find that Windows machine Agent (assuming the Fortify installation is auto discovered during the remote agent installation.
This link has good information to start the Bamboo Remote Agent as a Windows Service:
https://confluence.atlassian.com/bamboo/additional-remote-agent-options-436044733.html#
This is the basic instructions for a remote agent:
https://confluence.atlassian.com/bamboo/bamboo-remote-agent-installation-guide-289276832.html
Let me know if you have any other questions or if I was not clear on some point. Good luck!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks Chris, I did install Bamboo Agent on the Windows machine and created a Bamboo plan but looks like i have some failures related to Fortify scan -clean
Thanks again for a quick respoonse
Sridhar Mudhagouni
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
@Sridhar Mudhagouni I'm sure you have this covered already, but make sure your Windows build server and the Bamboo server can communicate over the needed ports.
https://confluence.atlassian.com/bamkb/troubleshooting-remote-agents-216957427.html
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Sridhar,
I went through a similar process recently and although documentation of the "Fortify App for Bamboo" plugin states it creates a Bamboo local server capability (and SCA needs to be installed on the Bamboo server), this seems to be no longer true and it actually can be used with Bamboo remote agents.
Rgds,
F
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Glad you figured it out :)
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Chris Flynn, I haven't used HP Fortify static code analyzer before. Does HP Fortify static code analyzer provide a CLI tool for running?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
HP Fortify has a Maven Plugin that we used for the integration. We still have not taken on the challenge of failing the Bamboo build if HP Fortify finds any defects, but hopefully this new HP Fortify Bamboo Plugin will help with that functionality.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
@Chris Flynn Does HP Fortify generate any kind of reports when having any defects?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Minh Tran, You should watch the little video that comes with the plugin, it is pretty informative.
The HP Fortify scan does produce a FPR file with the scan results.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Ok cool. So in that case, you can base on the scan results file to generate a JUnit Report xml file then you can use JUnit Report Parser task to parse it
You can check it out it here:
https://confluence.atlassian.com/bamboo/junit-parser-289277056.html
https://confluence.atlassian.com/bamboo/junit-parsing-in-bamboo-289277357.html
With this way, you can configure Bamboo to fail when there is a defect
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Minh Tran -- just to follow up, I don't think the FPR file produced by the Fortify scan is in the JUnit xml format. Thank you for the help though.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
 
 
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.