Viewing Scanned Application Details
In this panel details such as, the scanner types used with a break-up of the number of vulnerabilities found by each scanner and the associated risk rating are displayed. In this example, there are a total of 907 vulnerabilities found and categorized based on the scanners that detected them.
- Click on the number of vulnerabilities for any scanner type to view the specifics.
- You can filter the vulnerabilities based on OWASP and SANS categorization.
- Click View All to view details of all vulnerabilities detected.Click Supply Chain Threats to view application specific supply chain threats. Click Outbreak Alerts to view the application specific FortiGuard outbreak alerts.
- Modify Risk Rating - You can modify the risk rating settings for the application on this page, click Set Rating Factors.
- Plugins - You can enable and configure JIRA and FortiDAST scan target with FortiDevSec, click Plugins. See Plugins.
- Scan History - You can view the scan history of the application such as the type of scanners used for various scans, the scan duration, total number of vulnerabilities found, and the associated risk.
Hover over to view CI/CD and build related information.
Scan details are listed in the panel on the right side.
The displayed application related data includes the number of files and lines of code scanned, scanner types used, the App ID and organization ID, and the time when the application was added and last scanned. Click Scanner Config to download the fdevsec.yaml file.
- Modify App ID - You can modify the application ID, the new ID is displayed in this Details panel instantly. Ensure that you update the modified application ID in any existing fdevsec.yaml file.
- Deactivating/Deleting the Application - You can deactivate an application wherein no modification is allowed to the application vulnerability findings, but you are allowed to view them. You can delete an application (that is not being scanned) from the dashboard only after deactivating it.