Set up an issue tracking integration to export issues captured in Polaris to an external issue tracking platform.
Supported issue tracking integration platforms:
- Azure DevOps
- Jira
- ServiceNow
After you set up an issue tracking integration, you can export DAST, SAST, and SCA issues in your Polaris projects to an external issue tracking platform. You can export a single issue or multiple issues at once. When exporting multiple issues, you can create one ticket for all selected issues (bundled) or create individual tickets for each issue. Polaris creates tickets that include detailed information about the issue, remediation guidance, and helpful links. DAST issues also include evidence of the issue found; for example, the API endpoint. You can select the type of ticket Polaris creates when you set up the integration. See Export an issue to Azure DevOps or Jira for more information.
Additionally, setting up an issue tracking integration allows you to create tickets using issue policies (with the Create and bundle to 1 external issue tracker ticket action). When policy violations are detected in a scan of a project's default branch, Polaris creates a single ticket linked to all of the violating issues. The ticket includes the name of the violated policy, the names of violated rules, and links you can use to view issues that violate different rules in Polaris. See Issue policies for more information.
Ticket links appear on the Issues tab (in the Bug Tracking column) and in the Issue Details panel (under Bug Tracking).
Automatically close tickets and synchronize triage statuses
Optionally, configure Polaris to automatically close (auto-close) tickets in an integrated issue tracking platform when issues are absent or dismissed. For Jira Cloud and ServiceNow, you can also configure two-way synchronization of Polaris triage statuses and external ticket statuses.
Auto-close is available for all issue tracking integrations. When enabled, Polaris automatically closes tickets when the linked issue is dismissed (any reason) or absent in subsequent scans. Auto-close applies to all issue types (SAST, SCA, DAST). This feature helps reduce manual ticket management by automatically synchronizing external tickets with the issues they're linked to in Polaris.
For Jira Cloud and ServiceNow integrations, you can also configure two-way status synchronization. When configured:
- Triage status changes in Polaris automatically update the status of linked Jira or ServiceNow tickets.
- Ticket status changes automatically update the triage status of linked Polaris issues.
- Optionally, fix-by dates in Polaris and ticket due dates are kept in sync.
Please note:
- Bundled tickets created from policy violations or bulk export of several issues to one ticket are not supported for two-way synchronization. This feature only works for individually exported issues with a 1:1 link between a Polaris issue and an external ticket. Bundled tickets can still participate in one-way auto-close, which is triggered when all issues linked to the ticket are dismissed or absent in Polaris.
- Polaris does not reopen tickets that were automatically closed. When a previously absent issue is re-detected, the original ticket remains closed. If the issue is flagged by a policy, the policy creates a new ticket automatically. Otherwise, you must manually export or link a new ticket.
- By default, auto-close is only enabled on the project's default branch.
- If an issue tracking instance's API token expires, triage status changes in Polaris are still saved, but are not reflected in the issue tracker until the token is renewed. The error is logged in the issue's triage history and shown in the integration's configuration.
- Ticket statuses that have no configured mapping in Polaris do not trigger a triage status change in Polaris.
- Issue counts in portfolio summary views, dashboards, and reports reflect triage status changes triggered by two-way synchronization, but these counts can take up to 60 minutes to update.
For Jira Cloud two-way synchronization, also note:
- If a Jira workflow blocks a status transition, Polaris reverts the triage status to its previous value and logs the error in the issue's triage history.
- Triage status changes triggered by Jira sync do not require approval, even if triage approval workflows are configured.
For ServiceNow two-way synchronization, also note:
- If the ServiceNow incident workflow requires mandatory custom fields, issue export and status synchronization fail. Polaris does not change the triage status or incident ticket status and logs the error in the issue's triage history.
To use these features, create integration options that define the status mappings and auto-close behavior, then enable those options at the project level. See Create integration options for Azure DevOps, Create integration options for Jira, or Create integration options for ServiceNow for more information.
Edit links between issues and tickets
After you set up an issue tracking integration, you can update the links between issues in Polaris and tickets in the issue tracking instance.
Polaris issue tracking link updates allow you to:
- Link issues to an external ticket that already exists.
- Change the ticket that issues are linked to.
- Delete links to tickets.
Please note:
- Like other triage actions, ticket links are shared across branches in a project. If the same issue is detected on multiple branches and you link it to a ticket on one branch, that ticket link applies to the issue across all branches.
- When you manually link an issue to a ticket (or change the ticket an issue is linked to), the ticket you specify must:
- Exist in the issue tracking instance you connected your Polaris project to.
- Match the ticket type configured in your Polaris project's issue tracking integration. For example, if a Polaris project's issue tracking integration is configured to create tasks in Azure DevOps or Jira, you cannot create links to epics.
- When you change links manually (including creating, updating, or deleting links), the ticket's description does not change. Changing or removing ticket links in Polaris does not alter, update, or close the tickets in the connected issue tracking instance.
- Similarly, modifying or deleting a ticket in a connected issue tracking instance will not affect issues in Polaris.
- All link updates (including creating, updating, or deleting links) are tracked as triage events, and appear in the issue's triage history. See View issue history for more information.
You can edit ticket links using the Bug Tracking ID field in the triage panel. See Ways to triage issues in Polaris for more information.
Set up an issue tracking integration
- Ensure you meet the prerequisites for the integration, which vary from platform to platform:
- Set up the connection between Polaris and the issue tracking platform:
- (Optional) Create integration options to configure auto-close and, for Jira Cloud or ServiceNow, two-way synchronization:
- Connect a project in Polaris to an issue tracking instance: