DevOps Vulnerability Integrations
Organization-wide view of risk exposure for application vulnerabilities
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2026-09-09 | 0 | - |
About
DevOps Vulnerability Integrations is an additional feature set that is available for ITSM Pro customers. You need to install this application separately besides installing DevOps Change Velocity. It helps you to connect your security tools to DevOps Change Velocity. It enables you to retrieve application vulnerabilities found during Dynamic Application Security Testing (DAST) or Static Application Security Testing (SAST) or Software Composition Analysis (SCA) scanning. These vulnerabilities are generally identified by third-party systems such as Veracode or other application vulnerability scanners that are available as out-of-the-box integrations for you to use.
Customers can use this extensible security framework to connect to any security tool that is not supported in the base system of their own. This will allow an organization-wide view of risk exposure for application vulnerabilities. They will have a complete track of application vulnerabilities right from the beginning of the development cycle. Code delivery becomes more reliable even with rapid iterations and, if incidents do arise, they can be resolved more quickly.
Key Features
- A new security integration framework and data model has been added specifically for application security tools. It is an extensible framework that also allows you to create custom integrations with any application security tools.
- Connect Checkmarx which is integrated with your CI/CD pipelines to DevOps Change Velocity to retrieve security scan results. This helps you determine how vulnerable your code is. Checkmarx scans that are configured on GitHub Actions, Jenkins, and Azure DevOps pipelines are supported in the base system. You can view the security scan results in the related list of a Change Request in your ServiceNow instance or in the Pipeline UI. You can use security results in defining change policies and conditions for change automation.