Track and Fix Findings

Create Tickets from Advisories

Generate remediation tickets directly from security advisories to track vulnerability fixes in your workflow.

Use Mondoo ticketing to track the work of fixing advisories in your existing workflow. When a Mondoo space has a ticketing integration, you can create a ticket from an advisory. Creating a ticket can:

  • Directly create a new issue, ticket, work item, or incident in Jira, GitHub, GitLab, Azure DevOps, Zendesk, or ServiceNow, or send it to your own endpoint through a webhook
  • Send an email message to the recipient of your choice, such as a listener for your external issue tracking, ticketing, or project management software

For an overview of ticketing, read Track and Fix Findings with Ticketing.

Only team members with Editor or Owner access can perform this task.

  1. In the Mondoo App, navigate to a space that is set up to use ticketing.

  2. In the side navigation bar, under Findings, select Security, then select the Advisories filter.

  3. Select the advisory you want to track to open its finding page.

    You can create a ticket from a vulnerability (CVE) the same way: select the Vulnerabilities filter instead, then open the CVE.

  4. Near the top-right corner, select ACTIONS > Create ticket.

    The ACTIONS menu on an advisory's finding page in the Mondoo App, with the Create ticket option

  5. In the Create Ticket dialog, define the ticket:

    • In Select Integration, choose where Mondoo creates or sends the ticket.

    • Provide the fields the selected integration needs. They depend on the ticket system:

      Ticket systemFields in the Create Ticket dialog
      JiraJira Project and Issue Type
      GitHub IssuesRepository Owner and Repository Name
      GitLab IssuesGitLab Project Path, such as group/project
      Azure DevOpsAzure DevOps Project
      ZendeskPriority and Type
      ServiceNowImpact, Urgency, and Priority (default: 3 - Low, 3 - Low, 5 - Planning)
      EmailRecipient
      WebhookNo extra fields. Mondoo sends the ticket to the webhook URL.
    • Optionally set a Title and add Notes. Leave the title empty to let Mondoo generate one from the finding.

    The bottom of the dialog confirms how many findings the ticket covers.

    The Create Ticket dialog in the Mondoo App for a GitHub Issues integration, with repository owner, repository name, title, and notes fields

  6. Select CREATE TICKET.

    Mondoo creates a new ticket in the space and then creates a corresponding issue or ticket in your ticket system, or sends email to the selected recipient.

Create one ticket for several findings

To track several advisories or vulnerabilities in a single ticket, go to Findings > Security, select the checkbox beside each finding, and then select Create Ticket in the toolbar that appears. The Create Ticket dialog works the same way as for a single advisory.

Learn more

On this page