DependencyTrack / DependencyTrack/dependency-track
Pipeline Documentation
- Dominant language
- Java
- Stars
- 4.2k
- Forks
- 811
- Avg merge
- 8h 39m
- Merged PRs (30d)
- 237
Description
I am having difficulty getting ingestion of BOM and XML as part of a Jenkins pipeline and would like to request a bit of documentation on how they can be implemented.
The [Continious Delivery](https://docs.dependencytrack.org/usage/cicd/) page mentions pipelines but contains no examples.
I found [this excellent tip](https://github.com/jeremylong/DependencyCheck/issues/852) for usage of archiveArtifacts in DependencyCheck. I have used it for both dependency-check plugin *and* for cyclonedx-maven-plugin. ie, maybe the info should appear in a couple of different bits of documentation!
I found this [dependency-check plugin pull request](https://github.com/jenkinsci/dependency-track-plugin/pull/1) that contains useful information... but also raises questions. For instance...
- can one specify "synchronous publishing mode" in a pipeline?
I have also been trying to get cyclonedx-node-module working in a pipeline using the NodeJS jenkins plugin. I have not yet succeeded!
Contributor guide
Research direction
Start with the Continuous Delivery page at https://docs.dependencytrack.org/usage/cicd/ and the linked archiveArtifacts tip and Jenkins plugin pull request. Check which BOM/XML ingestion workflows and synchronous publishing options are currently supported, including the reported NodeJS plugin difficulty. Done means tested pipeline examples and documented limitations; confirm the scope with maintainers given the long inactivity.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- node.js
- Domain
- ci-cd, documentation
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 43/100