OpenText Application Security (Fortify)
Official@fortify · Canada
Great code demands great security, and with Fortify, go beyond 'check the box' application security to achieve that.
Agent Skills by OpenText Application Security (Fortify)
Showing 7 vetted skills indexed across 1 GitHub repositories.
fortify-remediate
Identify and remediate Fortify findings across FoD and SSC with Aviator-guided patches.
fortify-cicd-integration
Generate platform-aware Fortify CI/CD workflow guidance from repository analysis.
fortify-create-app
Automate Fortify application creation on FoD or SSC with fcli commands.
fortify-ssc
Automate Fortify SSC operations on applications, versions, artifacts, and issues via fcli.
fortify-exploitability-analysis
Trace attacker-controlled input to vulnerable code paths and emit Markdown and CycloneDX VEX reports.
fortify-fod
Orchestrate Fortify on Demand workflows for apps, releases, scans, and audits.
fcli-common
Reference Fortify CLI (fcli) usage, installation, and environment configuration for automation workflows.
Frequently Asked Questions About OpenText Application Security (Fortify)
FAQPage SchemaWhat specific security tasks does Fortify enable for development teams?▼
Fortify enables automated vulnerability identification, exploitability path tracing, and guided remediation. It allows teams to manage security artifacts, orchestrate scans across on-demand or on-premise platforms, and generate standardized compliance reports like CycloneDX VEX to ensure secure software delivery.
Which personas benefit most from integrating these security capabilities?▼
Application security engineers, DevSecOps practitioners, and software developers benefit from these capabilities. The platform provides the necessary visibility for security teams to manage risk, while offering developers direct, guided remediation paths to fix identified vulnerabilities within their existing codebases.
What are the primary prerequisites for deploying these security operations?▼
Deployment requires an active Fortify on Demand or Software Security Center instance. Users must configure the environment with appropriate credentials and ensure the command-line interface is installed to facilitate communication between local repositories and the centralized security management platforms.