-
Improvement
-
Resolution: Fixed
-
Minor
-
None
Dependency-Track plugin should display links from the Jenkins job to the relevent Dependency-Track Server project.
Such links would ease process: allow instant navigation from Jenkins to the place where one has to perform auditing and management!
- The links should be provided independent of whether or not "synchronous publishing mode" is enabled.
- The links should be provided for pipeline jobs and old-style maven/freestyle jobs.
- Possibly, the enhancement could be extended via incorporation of badges, should Dependency-Track issue 252 be implemented.
I am using the plugin in synchronous mode (as advised in the best practice documentation) and the resulting "Dependency-Track" Results are certainly handsome looking. However, there are no links for the listed CVEs, etc, (links which are provided by the Dependency-Check plugin). Maybe that could be the subject of a separate enhancement issue... but if one could just click a link to DT server then all the info would be available there anyway.
The above observations are based on usage of:
- Dependency-Track Server v3.4.0
- Jenkins v2.150.1
- cyclonedx-maven-plugin v1.3.1 (and cyclonedx-node-module as well)
- dependency-track-plugin v2.0.2
This issue was originally logged as Dependency-Track issue #254 and is re-logged here as this is the correct place for it.