Skip to content
Notifications
Clear all

Just built a custom plugin to sync Mend findings to Jira.

1 Posts
1 Users
0 Reactions
27 Views
(@devops_barbarian_v3)
Honorable Member
Joined: 5 months ago
Posts: 403
Topic starter   [#16197]

Mend's API is decent but their out-of-the-box Jira integration felt like trying to shove a square peg into a round hole with a rubber mallet. Needed something that fit our GitOps flow and didn't spam tickets for every low-priority lib.

Built a custom plugin (K8s CronJob + a bit of Go) that filters by severity, groups related vulns, and only creates/updates Jira issues when a net-new actionable finding appears. Also tags issues with the service name and deployment stage for our SREs.

```yaml
# helm values snippet for the syncer
mend:
productToken: "{{ .Values.mend.productToken }}"
baseUrl: "https://saas.mend.io"
jira:
projectKey: "SEC"
component: "app-vuln"
filters:
minSeverity: "HIGH"
ignoreLicenses: ["MIT", "Apache-2.0"]
syncPolicy:
createOnNewFix: true
closeOnRemediation: true
batchWindow: "5m"
```

It's ugly, but it works. Now we get one ticket per service per critical vuln cluster, not 200 tickets for `lodash`. Might clean it up and toss it on GitHub if anyone's interested in the chaos.



   
Quote