Skip to content

The CxAST Eclipse plugin enables you to import results from a CxAST scan directly into your IDE. You can view the vulnerabilities that were identified in your source code and navigate directly to the vulnerable code in the editor.

License

Notifications You must be signed in to change notification settings

Checkmarx/ast-eclipse-plugin

Repository files navigation


Contributors Forks Stargazers Issues Install Apache License


Logo

CHECKMARX ONE ECLIPSE PLUGIN

The Checkmarx One Eclipse plugin enables you to import results from a Checkmarx One scan directly into your IDE.
Explore the docs »
Marketplace »

Table of Contents
  1. Overview
  2. Getting Started
  3. Usage
  4. Contribution
  5. License
  6. Contact

Overview

Checkmarx continues to spearhead the shift-left approach to AppSec by bringing our powerful AppSec tools into your IDE. This empowers developers to identify vulnerabilities and remediate them as they code. The Checkmarx Eclipse plugin integrates seamlessly into your IDE, enabling you to access the full functionality of your Checkmarx One account (SAST, SCA, IaC Security) directly from your IDE.

You can run new scans, or import results from scans run in your Checkmarx One account. Checkmarx provides detailed info about each vulnerability, including remediation recommendations and examples of effective remediation. The plugin enables you to navigate from a vulnerability to the relevant source code, so that you can easily zero-in on the problematic code and start working on remediation.

Main Features

  • Access the full power of Checkmarx One (SAST, SCA, and IaC Security) directly from your IDE
  • Run a new scan from your IDE even before committing the code, or import scan results from your Checkmarx One account
  • Provides actionable results including remediation recommendations. Navigate from results panel directly to the highlighted vulnerable code in the editor and get right down to work on the remediation.
  • Group and filter results
  • Triage results (by adjusting the severity and state and adding comments) directly from the Visual Studio console
  • Links to Codebashing lessons

Getting Started

Prerequisites

  • An eclipse installation, version 2019-03 (4.11) or above.

Supported platforms: Windows, Mac, Linux/GTK

In order to use this integration for running an end-to-end flow of scanning a project and viewing results, the API Key must have at a minimum the out-of-the-box composite role ast-scanner as well as the IAM role default-roles.

Setting Up

  1. Verify that all prerequisites are in place.

  2. Install the Checkmarx One plugin and configure the settings as described here.

Usage

To see how you can use our tool, please refer to the Documentation

How To Videos

  • Installing and Setting up the Plugin GIF - How to install and set up the plugin

  • Running a Scan from the IDE Running a Scan from the IDE

  • Loading and Viewing Scan Results Loading and Viewing Scan Results

Contribution

We appreciate feedback and contribution to the ECLIPSE PLUGIN! Before you get started, please see the following:

License

Distributed under the Apache 2.0. See LICENSE for more information.

Contact

Checkmarx - Integrations Team

Project Link: https://github.com/Checkmarx/ast-eclipse-plugin

Find more integrations from our team here

© 2022 Checkmarx Ltd. All Rights Reserved.

About

The CxAST Eclipse plugin enables you to import results from a CxAST scan directly into your IDE. You can view the vulnerabilities that were identified in your source code and navigate directly to the vulnerable code in the editor.

Topics

Resources

License

Stars

Watchers

Forks

Contributors 23

Languages