HawkScan and Jira
StackHawk’s official Jira Cloud integration.
The StackHawk Jira integration lets you identify and track scanner findings within your Atlassian Jira Cloud workspace. The integration consists of a Jira App that has to be first installed into your Jira workspace to support communication with StackHawk.
- HawkScan findings can send and associate scanner findings to a Jira Workspace as a new or existing Jira Issue.
- You must have a StackHawk account.
You must have login permissions to the Jira workspace you wish to add the integration to.
You must have sufficient Administration permissions to install add-ons to your jira workspace.
Your Jira Project must have a defined “Bug” issue type, which is not present for all Jira Project workspaces by default. See Adding the bug issue type to your Jira project for more details.
With this integration you authorize StackHawk with the following Jira scopes:
- Read access to the connected Jira workspace
- Write access to the connected Jira workspace
The StackHawk for Jira app will first need to be installed from the Atlassian marketplace, before it can be connected to a StackHawk organization.
- Log into the StackHawk web app
- Visit the Jira Integration page in StackHawk
- Click Enable Jira
- Click the View In Marketplace button. This will open in a new tab in Jira Marketplace. There the
- In the new tab, click Install to install the app in your Jira workspace and go through installation process. Once completed, you can press Get Started to authorize the add-on with your Jira workspace.
Once the StackHawk application have been installed in Jira, a one-time verification token from StackHawk needs to be manually copied into Jira to authorize the new application.
- After installing the app from the Marketplace, go to the Jira page in StackHawk.
- Copy the UUID key. Note: this key is time-sensitive, and will expire after one hour.
- In Jira, go to
Apps > Manage Your Apps > StackHawk for Jira > Get Started.
- Paste the UUID key into the StackHawk Integration Token field.
You can verify the Jira app installation at any time after configuring a integration token.
- Go to the Jira page in StackHawk.
- You should see a
Connected to: <your workspace URL>, which indicates the integration has been linked to that Jira Workspace.
With the Jira App installation verified, you can send a finding to Jira new create a Jira Issue and associated it with a StackHawk scanner finding.
- Go to a finding detail in StackHawk
Scans > Scan Details > Findings
- Click on the checkbox for a given Path, Status, Method
- Click on
Actions -> Send to Jira
- Fill out the Jira ticket details. Findings can be promoted with either a new Jira issue, or linked to an existing Jira issue.
Creating a new issue: Select the project you want the created ticket to be associated with. The created issue will be made with the Bug issue type. The created issue will have details about those findings. Click Create Issue, and the Jira issue will be created and associated with the scan findings.
Linking an existing issue: Select the issue from the query search you want associated with your Jira ticket. The linked issue will receive a comment with the details of the vulnerability findings. Click Link Issue, and the Jira issue will be created and associated with the scan findings.
Similar to sending to Jira, you can clear the status of a finding or change it to another status by selecting the Path, Status, and Method and selecting a different action.
A Jira project has defined issue types for created issues. Jira Classic Software Projects will have the “Bug” issue type defined by default, however Jira Next-gen Software Projects and Jira Core Projects will not include this issue type by default. To send created issues to your Jira Project you will have to add a Bug issue type to your Jira Project:
- In your Jira project workspace, go to
Settings -> Issues
Issue types -> Add issue type
- Add a standard Issue Type named “Bug”, and give it a description.
The created Bug issue type will be used for Jira Issues created from the StackHawk platform.
The Jira integration can be disconnected from the authorized StackHawk organization from the Jira Integration page.
- Go to the Jira Integration page in StackHawk.
- In Jira, go to
Apps -> Manage Your Apps -> StackHawk for Jira
At this time, a StackHawk organization can only be one-to-one mapped to a Jira workspace.
Only Jira Cloud workspaces are supported; Jira Server workspaces are not yet supported.
Created Jira Issues will be the Bug issue type; this is currently not configurable.
Clearing the status of a finding will not remove or close a created or linked Jira issue.
Have any suggestions, feature requests, or feedback to share? drop us a line at firstname.lastname@example.org