Skip to main content
Version: 3.14

Integrate Dependency-Track

This documentation guide provides comprehensive instructions for installing and integrating Dependency-Track with the KubeRocketCI.

note

For details on how KubeRocketCI pipelines generate SBOMs with cdxgen and upload them to Dependency-Track, refer to Security Scanning Pipelines.

Prerequisites​

Installation​

To install Dependency-Track use KubeRocketCI addons approach.

Configuration​

  1. Open Administration -> Access Management -> Teams. Click Create Team -> Automation and click Create.

  2. Click + in Permissions and add:

    BOM_UPLOAD
    PROJECT_CREATION_UPLOAD
    VIEW_PORTFOLIO
  3. Click + in API keys to create token:

    Dependency-Track settings

  4. Provision secrets using a manifest, Portal, or with the externalSecrets operator:

Go to the Portal open Configuration -> SECURITY -> DEPENDENCYTRACK. Click + ADD INTEGRATION fill fields Quick Link URL, URL and Token click the save button.

Dependency-Track update manual secret

The ci-dependency-track secret is used by the security pipelines to upload SBOMs.

Configure the KubeRocketCI Portal​

The KubeRocketCI Portal and the krci sca CLI commands read Dependency-Track with a separate, read-only API key. The pipeline key above is not enough: Dependency-Track requires VIEW_VULNERABILITY to list findings and VIEW_POLICY_VIOLATION to list policy violations, and answers 403 without them.

  1. Open Administration -> Access Management -> Teams. Click Create Team, name it krci-portal, and click Create.

  2. Click + in Permissions and add:

    VIEW_PORTFOLIO
    VIEW_VULNERABILITY
    VIEW_POLICY_VIOLATION
  3. Click + in API keys to create an API key for the team.

  4. Set the Dependency-Track URL in the krci-portal values:

    krci-portal:
    configEnv:
    DEPENDENCY_TRACK_URL: https://dependency-track.example.com
    # Optional: browser-facing URL, when it differs from DEPENDENCY_TRACK_URL
    DEPENDENCY_TRACK_WEB_URL: https://dependency-track.example.com
  5. Add the API key to the Portal secret as DEPENDENCY_TRACK_API_KEY (see Create the portal-secret Kubernetes Secret). With the External Secrets Operator, store it under the Portal eso.secretPath. Restart the Portal to apply the key.

  6. Verify the integration: krci sca list lists the Dependency-Track projects, and krci sca findings <codebase> lists the findings of a codebase after its first security scan.