DependencyTrack / DependencyTrack/dependency-track

Pipeline Documentation

Open
#253 9 comments 0 reactions 0 assignees View on GitHub
documentation good first issue hacktoberfest size/S
Dominant language
Java
Stars
4.2k
Forks
811
Avg merge
8h 39m
Merged PRs (30d)
237

Description

I am having difficulty getting ingestion of BOM and XML as part of a Jenkins pipeline and would like to request a bit of documentation on how they can be implemented.

The [Continious Delivery](https://docs.dependencytrack.org/usage/cicd/) page mentions pipelines but contains no examples.

I found [this excellent tip](https://github.com/jeremylong/DependencyCheck/issues/852) for usage of archiveArtifacts in DependencyCheck. I have used it for both dependency-check plugin *and* for cyclonedx-maven-plugin. ie, maybe the info should appear in a couple of different bits of documentation!

I found this [dependency-check plugin pull request](https://github.com/jenkinsci/dependency-track-plugin/pull/1) that contains useful information... but also raises questions. For instance...

- can one specify "synchronous publishing mode" in a pipeline?

I have also been trying to get cyclonedx-node-module working in a pipeline using the NodeJS jenkins plugin. I have not yet succeeded!

Contributor guide

Open the contributing guide

Research direction

Start with the Continuous Delivery page at https://docs.dependencytrack.org/usage/cicd/ and the linked archiveArtifacts tip and Jenkins plugin pull request. Check which BOM/XML ingestion workflows and synchronous publishing options are currently supported, including the reported NodeJS plugin difficulty. Done means tested pipeline examples and documented limitations; confirm the scope with maintainers given the long inactivity.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js
Domain
ci-cd, documentation
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
43/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.