About Fortify Code Security for Visual Studio Code Application security is most effective when it meets developers where they already are — inside the IDE, alongside the code they’re writing. Surfacing vulnerabilities at the moment of authoring is faster, cheaper, and far less disruptive than catching them later in the pipeline or in production. Fortify Code Security for Visual Studio Code is built around that idea. The extension brings the full power of OpenText Fortify Application Security Testing directly into VS Code and into the agentic coding workflow, so secure coding feedback shows up alongside the rest of a developer’s workflow rather than in a separate tool they have to switch into. What you can do with the extension? From inside VS Code, the extension supports the full early-remediation workflow across both OpenText Core Application Security (Fortify on Demand) and Application Security Center: Run SAST, SCA, and DAST scans : Submit scans through Fortify on Demand, ScanCentral SAST, or run local SAST scans with Fortify Static Code Analyzer, plus SCA and DAST scans through FoD or ScanCentral DAST. All powered by the Fortify CLI (fcli). Review and audit findings : Browse, filter, and triage vulnerabilities by severity, category, and status; view data flow traces; set analysis tags; and sync audit decisions back to FoD or SSC in real time. Navigate directly to vulnerable code : Jump from a finding straight to the affected line in the editor. Get AI-powered remediation with Fortify Aviator : Receive contextual explanations, root-cause analysis, and step-by-step fix recommendations tailored to your code, with the option to apply AI-suggested fixes directly in the editor. Work with AI coding assistants through bundled Fortify Agent Skills : The extension ships with a set of domain-specific skills (fortify-fod, fortify-ssc, fortify-remediate, fortify-cicd-integration, fcli-common) that teach AI assistants like GitHub Copilot, Claude Code, Gemini CLI, Cursor, and others how to run scans, query findings, and autonomously remediate vulnerabilities on your behalf. Connect via the optional fcli MCP server : For assistants that support the Model Context Protocol, the extension can start and manage a local fcli MCP server, exposing Fortify capabilities as typed MCP tools for deeper, programmatic AI agent integration. The result is a tighter feedback loop between scanning, auditing, and fixing — and one consistent experience whether developers are working manually, through an AI coding assistant, or both. About the 26.2 Release The Release Notes for this version focus primarily on documenting known issues and workarounds, particularly around fcli session creation, ScanCentral client auto-update behavior, and certain auditing flows for custom tags. Teams planning to install or upgrade should review them before rolling out to make sure none of the documented behaviors affect their workflow. For the full list, see the Release Notes . Documentation Full setup instructions, configuration guidance, and usage walkthroughs are available in the User Guide . Get Started Install or upgrade from the Visual Studio Marketplace: Fortify Code Security for Visual Studio Code Whether your team is already running Fortify in the pipeline or just starting to bring static analysis closer to the developer, 26.2 is a good moment to put security feedback, along with AI-assisted remediation, right where the code gets written. Contact Customer Support OpenText Fortify https://portal.microfocus.com/ +1 (800) 509-1800