Issue tracking integrations

Black Duck Polaris Platform

Set up an issue tracking integration to export issues captured in Polaris to an external issue tracking platform.

Supported issue tracking integration platforms:

  • Azure DevOps
  • Jira
  • ServiceNow

After you set up an issue tracking integration, you can export DAST, SAST, and SCA issues in your Polaris projects to an external issue tracking platform. You can export a single issue or multiple issues at once. When exporting multiple issues, you can create one ticket for all selected issues (bundled) or create individual tickets for each issue. Polaris creates tickets that include detailed information about the issue, remediation guidance, and helpful links. DAST issues also include evidence of the issue found; for example, the API endpoint. You can select the type of ticket Polaris creates when you set up the integration. See Export an issue to Azure DevOps or Jira for more information.

Additionally, setting up an issue tracking integration allows you to create tickets using issue policies (with the Create and bundle to 1 external issue tracker ticket action). When policy violations are detected in a scan of a project's default branch, Polaris creates a single ticket linked to all of the violating issues. The ticket includes the name of the violated policy, the names of violated rules, and links you can use to view issues that violate different rules in Polaris. See Issue policies for more information.

Ticket links appear on the Issues tab (in the Bug Tracking column) and in the Issue Details panel (under Bug Tracking).

Note: You can add multiple instances of issue tracking integrations to your organization, but each Polaris project can only be connected to one instance.

Automatically close tickets and synchronize triage statuses

Optionally, configure Polaris to automatically close (auto-close) tickets in an integrated issue tracking platform when issues are absent or dismissed. For Jira Cloud and ServiceNow, you can also configure two-way synchronization of Polaris triage statuses and external ticket statuses.

Auto-close is available for all issue tracking integrations. When enabled, Polaris automatically closes tickets when the linked issue is dismissed (any reason) or absent in subsequent scans. Auto-close applies to all issue types (SAST, SCA, DAST). This feature helps reduce manual ticket management by automatically synchronizing external tickets with the issues they're linked to in Polaris.

For Jira Cloud and ServiceNow integrations, you can also configure two-way status synchronization. When configured:

  • Triage status changes in Polaris automatically update the status of linked Jira or ServiceNow tickets.
  • Ticket status changes automatically update the triage status of linked Polaris issues.
  • Optionally, fix-by dates in Polaris and ticket due dates are kept in sync.

Please note:

  • Bundled tickets created from policy violations or bulk export of several issues to one ticket are not supported for two-way synchronization. This feature only works for individually exported issues with a 1:1 link between a Polaris issue and an external ticket. Bundled tickets can still participate in one-way auto-close, which is triggered when all issues linked to the ticket are dismissed or absent in Polaris.
  • Polaris does not reopen tickets that were automatically closed. When a previously absent issue is re-detected, the original ticket remains closed. If the issue is flagged by a policy, the policy creates a new ticket automatically. Otherwise, you must manually export or link a new ticket.
  • By default, auto-close is only enabled on the project's default branch.
  • If an issue tracking instance's API token expires, triage status changes in Polaris are still saved, but are not reflected in the issue tracker until the token is renewed. The error is logged in the issue's triage history and shown in the integration's configuration.
  • Ticket statuses that have no configured mapping in Polaris do not trigger a triage status change in Polaris.
  • Issue counts in portfolio summary views, dashboards, and reports reflect triage status changes triggered by two-way synchronization, but these counts can take up to 60 minutes to update.

For Jira Cloud two-way synchronization, also note:

  • If a Jira workflow blocks a status transition, Polaris reverts the triage status to its previous value and logs the error in the issue's triage history.
  • Triage status changes triggered by Jira sync do not require approval, even if triage approval workflows are configured.
Important: Two-way synchronization is supported for Jira Cloud only. Jira Data Center is not supported.

For ServiceNow two-way synchronization, also note:

  • If the ServiceNow incident workflow requires mandatory custom fields, issue export and status synchronization fail. Polaris does not change the triage status or incident ticket status and logs the error in the issue's triage history.

To use these features, create integration options that define the status mappings and auto-close behavior, then enable those options at the project level. See Create integration options for Azure DevOps, Create integration options for Jira, or Create integration options for ServiceNow for more information.

Set up an issue tracking integration

To set up an issue tracking integration, follow these steps:
  1. Ensure you meet the prerequisites for the integration, which vary from platform to platform:
  2. Set up the connection between Polaris and the issue tracking platform:
  3. (Optional) Create integration options to configure auto-close and, for Jira Cloud or ServiceNow, two-way synchronization:
  4. Connect a project in Polaris to an issue tracking instance: