Skip to main content

Integrating Invicti Standard with Redmine

This document is for:
Invicti Standard

Redmine is an issue tracking system that is part of a larger, flexible project management web application. It is free and open source, cross-platform and cross-database. Redmine is written using the Ruby on Rails framework.

This document explains how to configure Invicti Standard to send a detected vulnerability to Redmine, including both manual configuration and wizard-based setup.

Redmine Fields

This table lists and explains the Redmine fields in the Send to Actions tab.

Button/Section/FieldDescription
AddClick to add an integration.
DeleteClick to delete the integration and clear all fields.
Configure Send ToClick to configure the integration using the Settings Wizard instead of doing it manually.
Create Sample IssueOnce all relevant fields have been configured, click to create a sample issue.
ActionThis section contains general fields about the Send To Action
Display NameThis is the name of the configuration that will be shown in menus.
MandatoryThis section contains fields that must be completed.
URLThis is the Redmine instance URL.
API Access KeyThis is the API Access Key for authentication.
Project IDThis is the project identifier of the issue.
Priority IDThis is the priority identifier.
VulnerabilityThis section contains fields with vulnerability details.
Body TemplateThis is the template file that is used to create description fields.
Title FormatThis is the string format that is used to create the vulnerability title.
OptionalThis section contains optional fields.
Tracker IDThis is the tracker identifier.
Status IDThis is the status identifier.
Category IDThis is the category identifier.
Assignee IDThis is the assignee identifier.
Due DaysThis is the number of days between the date the issue was created to the date it's due.
Is PrivateThis indicates whether the issue is accessible only to the assignee.
Custom FieldsThese are the custom fields that are defined for the project. Click the ellipsis () to open the Custom Fields Editor dialog. In the Edit Custom Field Value field, enter the value and click OK.

How to Integrate Invicti Standard with Redmine

Follow these steps to configure the Redmine integration manually in Invicti Standard:

  1. Open Invicti Standard.
  2. From the Home tab on the ribbon, click Options. The Options dialog is displayed.
  3. Click Send To Actions.
Invicti Standard Options dialog showing Send To Actions configuration menu
  1. From the Add dropdown, select Redmine. The Redmine fields are displayed.
Redmine integration configuration form showing all mandatory and optional fields
  1. In the Mandatory section, complete the connection details:

    • URL
    • API Access Key
    • Project
    • Priority ID
  2. In the Vulnerability section, you can change the default Body Template and Title Format.

note

Body templates are stored in %userprofile%\Documents\Invicti\Resources\Send To Templates. If you use your own custom templates, store them in this location.

  1. In the Optional section you can specify:

    • Tracker ID
    • Status ID
    • Category ID
    • Assignee ID
    • Due Days
    • Is Private
    • Custom Fields
  2. To set custom field values, in the Custom Fields field, click the ellipsis button.

  3. In the Edit Custom Field Value field, enter the relevant value.

Redmine custom fields editor dialog for configuring custom field values
  1. Click OK.
  2. Click Create Sample Issue to confirm that Invicti Standard can connect to the configured system. The Send To Action Test confirmation dialog is displayed.
Redmine test connection dialog showing Create Sample Issue confirmation and results
  1. In the Send To Action Test dialog, click the Issue number link to open the issue in Redmine in the default browser.
Redmine test connection dialog showing Create Sample Issue confirmation and results

How to Integrate Invicti Standard with Redmine Using the Wizard

Configuration Alternative

Instead of configuring the settings manually, the configuration wizard can help you with the settings.

  1. Open Invicti Standard.
  2. From the Home tab on the ribbon, click Options. The Options dialog is displayed.
  3. Click Send To Actions.
  4. From the Add dropdown, select Redmine. The Redmine fields are displayed.
Redmine integration form showing Configure Send To button to launch the configuration wizard
  1. Click Configure Send To to launch the wizard. The Send To Configuration dialog is displayed.
Redmine configuration wizard welcome screen with Next button to proceed
  1. Click Next. The Authentication step is displayed.
Redmine wizard authentication step showing URL and API Access Key fields with Test Credentials button
  1. Complete the URL and API Access Key fields, and click Test Credentials.
  2. When the confirmation message, Your credentials are confirmed, is displayed, click Next. The Project step is displayed.
Redmine wizard project selection step showing available projects list
  1. Select a project, and click Next. The Priority step is displayed.
Redmine wizard priority selection step showing available priority levels
  1. Select a priority, and click Next. The Tracker step is displayed.
Redmine wizard tracker selection step showing available tracker types
  1. If required, select a tracker, and click Next. The Status step is displayed.
Redmine wizard status selection step showing available status options
  1. If required, select a status, and click Next. The Category step is displayed.
Redmine wizard category selection step showing available issue categories
  1. If required, select a category, and click Next. The Assignee step is displayed.
Redmine wizard assignee selection step showing available team members
  1. If required, select an assignee, and click Next. The Optional Fields step is displayed.
Redmine wizard optional fields step showing Due Days and Is Private settings
  1. If required, complete the Due Days and Is Private fields, and click Next. The Summary step is displayed.
Redmine wizard summary step showing review of all configured settings with Finish button
  1. Review your settings, and click Finish. The Settings are applied automatically. You are returned to the Send To Actions fields.
  2. To set custom field values, in the Custom Fields field, click the ellipsis button.
  3. In the Edit Custom Field Value field, enter the relevant value.
Redmine custom fields configuration after wizard completion showing custom field editor
  1. Click OK.
  2. Click Create Sample Issue to confirm that Invicti Standard can connect to the configured system. A Send To Action Test confirmation dialog is displayed.
Redmine wizard final test showing sample issue creation confirmation
  1. In the Send To Action Test dialog, click the Issue number link to open the issue in Redmine in the default browser.

How to Export Reported Vulnerabilities to Projects in Redmine

Prerequisites

Please ensure that you have first configured Redmine integration (see How to Integrate Invicti Standard with Redmine).

  1. Open Invicti Standard.
  2. From the ribbon, select the File tab. Local Scans are displayed. Double-click the relevant scan to display its results.
Invicti Standard scan results view showing vulnerabilities ready for export to Redmine
  1. In the Issues panel, right click the vulnerability you want to export and select Send to Redmine. (Alternatively, from the ribbon, click the Vulnerability tab, then Send To Redmine.) A confirmation message and link is displayed at the bottom of the screen.
Invicti Standard Issues panel showing right-click context menu with Send to Redmine option
  1. Click the Redmine Send To Action is executed for the selected vulnerability link to view the newly-created issue in Redmine.
  2. The vulnerability is automatically exported to Redmine. You can view it in Redmine's Issues tab.
Redmine Issues tab displaying the exported vulnerability as a new issue with complete details

Need help?

Invicti Support team is ready to provide you with technical help. Go to Help Center

Was this page useful?