- Checkmarx Documentation
- Checkmarx One
- Checkmarx One User Guide
- Managing Projects
Managing Projects
A Checkmarx One project defines the source to be scanned, used scanners, scan tags, and groups assignment. Normally, a Checkmarx One project should correspond to a software development project, or to part of one. Any time a scan is run, the scan results remain associated with the project.
For Continuous Integration development methodology, if a new branch is created for each iteration, update the code location within the existing project (rather than creating a new project) so that all the results will reside within a single project.
For every Project that exists in Checkmarx One, the following actions are available:
Viewing the Projects Tab
The Workspace > Projects screen, enables you to manage and monitor all of your Checkmarx One Projects.
The expandable Filters & Groups section enables you to group the projects list by Risk Level and displays the applied table filters.
Below that, the Projects pane shows a list of the projects in your account. Hover over the Results button on the desired Project row and select the desired scanner to see detailed scan results, or you can click on the Overview icon to open the project page.
The following table describes the information shown for each project and the actions that can be taken.
Item | Description | Possible Values |
---|---|---|
Selection Box | Select multiple checkboxes enabling you to bulk delete the selected Projects. The Delete Projects button appears on top of the table. | |
Project Name | The name of the Project. |
|
Risk Level | The risk level of the Project, based on the vulnerabilities that were identified. | High, Medium, Low, No Risk |
Vulnerability Counters | The number of vulnerabilities identified for each severity level is shown. NoteCheckmarx uses the newest available CVSS scoring system. If a vulnerability has a CVSS v3.1 score, that score is used; if it only has a CVSS 2.0 score in NVD, that score is used. The vast majority of vulnerabilities have CVSS 3.1 scores, and all unique Cx Vulnerabilities are ranked using the CVSS 3.1 system. | |
Last Scan | Shows how much time has passed since the Project was last scanned. | |
Tags | Shows tags in key or key:value pairs that were applied to this Project. | |
Groups | Shows the groups that are assigned to the project. | |
Scan Origin | Shows how the most recent scan of the Project was triggered. | webapp, Push Webhook, etc. |
Source | Shows how the source code was accessed for the most recent scan. | Zip, GitHub, etc. |
Actions Buttons - hover over the desired Project to reveal the action buttons. | ||
Results | Hovering over the Results link will display the severity of each scanner for the last successfully completed scan. Clicking on a specific scanner will open the last scan results in the Results Viewer. | SCA, IaC Security, SAST |
Copy ID | Hover over the desired Project and click on the Copy ID icon in a Project’s row to copy the ID of that Project to your clipboard. | |
Overview | Opens the Project page showing detailed information about the Project. | |
Scan | Initiates a new scan for the Project. | |
Context Menu | ||
Assign to Applications | Assign the Project to one or more Applications. See Managing Applications | |
Project Settings | Edit the Project settings. See Configuring Projects | |
Optimization Service Order | Order Optimization service from the Checkmarx AppSec experts for this Project. | |
Generate Project Report | Generate a Project report. See Project Reports | |
Delete Project | Delete the Project and its associated scans. See Deleting Projects |