eclipse-tractusx / sig-infra

Repository for Tractus-X infrastructure topics and resources.
Apache License 2.0
2 stars 2 forks source link

Having NVD API Key for eclipse-tractusx organization within the secrets #459

Closed ds-mwesener closed 5 months ago

ds-mwesener commented 6 months ago

Is your support request related to a problem? Please describe.

Dependency check takes very long without api key. image

Describe the solution you'd like

Adding an api key either for the project repository or the organization into the secrets. https://nvd.nist.gov/general/news/API-Key-Announcement

Additional context

Please find an example run: https://github.com/eclipse-tractusx/traceability-foss/actions/runs/8353452321/job/22865193054

tomaszbarwicki commented 6 months ago

Hi @ds-mwesener , I think EF can help with that, suggest to create an EF gitlab issue to request API key..

ds-mwesener commented 6 months ago

https://gitlab.eclipse.org/eclipsefdn/helpdesk/-/issues/4457

ds-mwesener commented 6 months ago

Would it be possible to also add a secret to the catena project: https://github.com/catenax-ng/tx-traceability-foss

I know we soon want to fully migrate but as long as this process is not completed it would be a big benefit for us. I already have an API key which could be set at least for tx-traceability-foss.

Thanks in advance: @tomaszbarwicki

tomaszbarwicki commented 6 months ago

@ds-mwesener sure thing can add, is it in vault? what is the key and how do you prefer to name the secret in repo?

FaGru3n commented 5 months ago

Hi @ds-mwesener any update on this, i guess @netomi gave you a little update on https://gitlab.eclipse.org/eclipsefdn/helpdesk/-/issues/4457

ds-mwesener commented 5 months ago

Hi @FaGru3n we have created a story for using the image: https://github.com/eclipse-tractusx/traceability-foss/issues/875 Once this has been prioritized by our product owner we will try to use it that way. Thank you for heads up.