Skip to main content

Create an agent-based scanning integration for Jira Cloud

Setting up the Veracode Software Composition Analysis agent-based scanning integration for Jira Cloud allows your organization to create Jira issues from within the Veracode Platform.

If you also use Veracode Static Analysis, Veracode recommends you use the Veracode Integration for Jira Cloud, which offers additional features and greater customization. To integrate your agent-based scan findings with Veracode Integration for Jira Cloud, you must link your project to an application profile in the Veracode Platform.

Before you begin:

To set up this integration, you must have the Security Lead role in the Veracode Platform and be an administrator of your Jira instance.

This integration works with both Jira Cloud and Jira Server. For Jira Server, the server must be accessible from outside the internet.

To complete this task:

  1. In the Veracode Platform, select Scans & Analysis > Software Composition Analysis.

  2. Select Agent-Based Scan.

  3. Select Agent-Based Scan Settings > Integrations > Actions > Create Jira Cloud Integration.

  4. Enter a name and server URL for your integration and select Next.

  5. To leave the Veracode Platform and go to your Jira instance, select the application link.

  6. Inside JIRA application link setting, for URL, enter https://sca.analysiscenter.veracode.com.

  7. Select Create New Link.

  8. If you see a warning saying no response was received from the URL you entered, select Continue.

  9. For Application Name, enter SourceClear.

  10. From the Application Type dropdown menu, select Generic Application.

  11. Select Continue.

  12. Select the pencil icon to the right of the newly created application.

  13. Select Incoming authentication and copy the values you see on step 3 into this screen.

  14. Select Save.

  15. Copy these values:

    • Consumer Key
    • Consumer Name
    • Public Key
    • Callback URL
  16. Select Save.

  17. In the Veracode Platform, Select Next.

Results:

When you see the Step 3 window, select the link. To authorize the OAuth application, select Allow. You can now create your first ticket template.