For the complete documentation index, see llms.txt. This page is also available as Markdown.

Getting started

This section is your gateway to getting started with OpenText Fortify Software Composition Analysis (Fortify SCA).

Follow these steps after creating an account with Fortify SCA:

  1. Set up an integration If you have a project's dependency file but setting up an integration is not applicable at the moment, you can upload the dependency file manually.

  2. Set up a license use case When you first access the license view, you will see that all repositories are marked as "Unknown" in the risk column. This is because you have not configured any use cases for your repositories yet. Defining a use case helps the tool understand how you organize the code in your repositories, which affects the risk associated with any particular license.

  3. Set up automations The automations engine allows for rules to be triggered based on conditions. For example, a rule can fail a pipeline if it detects a new high-risk vulnerability detected, or an unwanted license.

    By default, Fortify SCA has set up a number of rules to prevent unwanted licenses or dangerous vulnerabilities. Click the toggle button to disable any rule.

Last updated

Was this helpful?