DataDog / datadog-ci

Use Datadog from your CI.
https://datadoghq.com
Apache License 2.0
129 stars 55 forks source link

Propagating CycloneDx information #1453

Closed marcwieserdev closed 1 month ago

marcwieserdev commented 2 months ago

What and why?

The goal of this PR is to proagate new information coming from CycloneDX sboms, such as libraries package manager, is a library direct or not, files and dependencies between components.

How?

This is done by updating the CycloneDX SBOM to SCARequest payload. Please note it will be more convenient to review it commit by commit as they have been split by propagation type + 1 refacto at first to prepare file propagation

Review checklist

datadog-datadog-prod-us1[bot] commented 2 months ago

Datadog Report

Branch report: marc.wieser/Propagating_CycloneDX_Information Commit report: b67e88f Test service: datadog-ci-tests

:white_check_mark: 0 Failed, 152 Passed, 0 Skipped, 1m 14.97s Total duration (2m 18.86s time saved)