# dti4q

> CLI to upload BOM files to Dependency-Track (https://dependencytrack.org/) tool using CI/CD pipelines

Latest version **1.0.0** (published 2021-10-20) · MIT license · 0 weekly downloads

## Install

```sh
npm install dti4q
pnpm add dti4q
yarn add dti4q
bun add dti4q
```

Provides the command `dti4q`.

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.0.0 |
| Published | 2021-10-20 |
| First published | 2021-10-20 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 1 |
| Unpacked size | 363.6 KB |
| Known vulnerabilities | 0 (+23 in 1 direct dependencies) |
| Install scripts | no |
| Author | Miguel A. Mateo-Casali |
| Maintainers | mimaca1 |
| Keywords | cli, dependency track, devsecops |

## Links

- npm: https://www.npmjs.com/package/dti4q
- npm.io page: https://npm.io/package/dti4q

## Dependencies (1)

- [axios](https://npm.io/package/axios.md) ^0.23.0

## Alternatives

- [@salesforce/cli](https://npm.io/package/@salesforce/cli.md) — 389.7K weekly downloads
- [@mintlify/cli](https://npm.io/package/@mintlify/cli.md) — 208.9K weekly downloads
- [@grafana/e2e-selectors](https://npm.io/package/@grafana/e2e-selectors.md) — 128.7K weekly downloads
- [mintlify](https://npm.io/package/mintlify.md) — 112.0K weekly downloads
- [@intlayer/cli](https://npm.io/package/@intlayer/cli.md) — 22.8K weekly downloads

## Recent versions

- 1.0.0 (latest) — 2021-10-20

## README

# Dependencytrack
CLI to Dependecy Track

## Installation

Install it using npm
```
npm install @i4q/dtrack-cli -g
```

## Usage

Execute the following command:
```
dtrack-cli --server https://yourDependencyTrackServer.com/ 
            --bom-path bom.xml
           --api-key PUT_YOUR_KEY_HERE 
           --project-name "Project Name"
           --project-version latest 
           --auto-create true
```

## Gitlab CI/CD example
### package.json projects (NodeJS, Angular, React...)

```yaml
dependency-check:
  stage: XXX
  image: node:12.17
  before_script:
    - npm install -g @cyclonedx/bom
    - npm install -g @i4q/dtrack-cli -g
  script:
    - npm install
    - cyclonedx-bom -o bom.xml
    - dtrack-cli --server ${DTRACK_HOST_URL} --bom-path bom.xml --api-key ${DTRACK_API_KEY} --project-name ${NAME} --project-version ${VERSION} --auto-create true
  allow_failure: true
  only:
    - tags
```
### PyPi projects

```yaml
dependency-check:
  stage: XXX
  image: python:3.6
  before_script:
    - apt update -y
    - apt install curl gnupg -y
    - curl -sL https://deb.nodesource.com/setup_12.x  | bash -
    - apt install nodejs -y
    - npm install -g @i4q/dtrack-cli
    - node -v
    - pip install cyclonedx-bom
  script:
    - cyclonedx-py -i requirements.txt -o bom.xml
    - dtrack-cli --server ${DTRACK_HOST_URL} --bom-path bom.xml --api-key ${DTRACK_API_KEY} --project-name ${NAME} --project-version ${VERSION} --auto-create true
  allow_failure: true
  only:
    - tags
```

### Maven projects

```yaml
dependency-check-java:
  stage: sonar
  image: maven:3.6-openjdk-11
  before_script:
    - apt update -y
    - apt install curl gnupg -y
    - curl -sL https://deb.nodesource.com/setup_12.x  | bash -
    - apt install nodejs -y
    - npm install -g @i4q/dtrack-cli
  script:
    - mvn clean install
    - mvn org.cyclonedx:cyclonedx-maven-plugin:makeBom
    - dtrack-cli --server ${DTRACK_HOST_URL} --bom-path target/bom.xml --api-key ${DTRACK_API_KEY} --project-name ${NAME} --project-version ${VERSION} --auto-create true
  allow_failure: true
  only:
    - tags
```

---
_Source: https://npm.io/package/dti4q · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
