Changes for page Jenkins Shared Library

Last modified by Boris Folgmann on 2025/11/03 09:41

From version 3.2
edited by Achim Mahnke
on 2025/10/01 10:24
Change comment: There is no comment for this version
To version 6.10
edited by Boris Folgmann
on 2025/11/03 09:14
Change comment: There is no comment for this version

Summary

Details

Page properties
Author
... ... @@ -1,1 +1,1 @@
1 -xwiki:XWiki.achimmahnket-systemscom
1 +xwiki:XWiki.borisfolgmannt-systemscom
Content
... ... @@ -26,9 +26,9 @@
26 26  1. Checking out the source code from git.
27 27  1. If a pom.xml is found your favorite JDK is selected, by default jdk11. Then a maven build is done.
28 28  1. If there's no pom.xml but a package.json is found a nodejs build is done.
29 -1. If there is no pom.xml or package.json but a go.mod file, a go test tool run is done.
29 +1. If there is no pom.xml or package.json but a go.mod file, a go build is done.
30 30  1. Then the following stages are executed in parallel
31 -11. Analysis: For maven projects the Java source code is checked by checkstyle, pmd and spotbugs. Furthermore the job output will be checked for any warnings generated by maven, javac or javadoc. If Python modules (.py files) exist in the git repository they will be analyzed using pylint and flake8. If pylint or flake8 are not available on the Jenkins agent the steps will be skipped. Python files that are generated or downloaded into the workspace will not be checked. The results will be displayed on the classical Jenkins build page after the build. If a go.mod f
31 +11. Analysis: For maven projects the Java source code is checked by checkstyle, pmd and spotbugs. Furthermore the job output will be checked for any warnings generated by maven, javac or javadoc. If Python modules (.py files) exist in the git repository they will be analyzed using pylint and flake8. If pylint or flake8 are not available on the Jenkins agent the steps will be skipped. Python files that are generated or downloaded into the workspace will not be checked. The results will be displayed on the classical Jenkins build page after the build. For Go projects, the Go test tool is used to run all tests and produce a coverage output file for SonarQube. Additionally, the gotestsum tool is used to produce a report which is picked up by Jenkins.</dd>
32 32  11. Security: If it's not a feature or bugfix branch a dependency check is done which checks if e.g. libraries are used which have known vulnerabilities. The results will be displayed in Jenkins after the build.
33 33  11. Docker: this will also work for projects which are neither maven or nodejs. A Dockerfile is enough to trigger this part of the pipeline.
34 34  111. If a Dockerfile is found a docker image is built.
... ... @@ -126,8 +126,14 @@
126 126  )))|(((
127 127  'npm install && npm run build ~-~-prod'
128 128  )))|(((
129 -npm command to execute for building Node.JS projects.
129 +npm command to execute for building Node.JS projects.
130 130  )))
131 +|= |go|'go'|Golang version to use.
132 +Refers to a symbolic name of a go tool configuration in Jenkins.
133 +|= |goBuildCommand|(((
134 +'go build -o app cmd/server/main.go'
135 +)))|go build run. Should be overridden for your project.
136 +|= |goTestCommand|'gotestsum ~-~-format pkgname ~-~-junitfile report.xml ~-~- -failfast -race -coverprofile=coverage.out -tags=test ./...'|Runs gotestsum tool which in turn calls 'go test' for all packages in the project. Should be overridden for your project. The gotestsum tool is available out-of-the-box and produces a report file which is picked up by Jenkins automatically.
131 131  |=(% rowspan="10" %)(((
132 132  Docker build
133 133  )))|(((
... ... @@ -306,9 +306,11 @@
306 306  |(((
307 307  helmRegistry
308 308  )))|(((
309 -Nexus registry of your DOaaS instance
315 +Helm registry of your DOaaS instance, which is usally 'https:~/~/registry-CUSTOMER.devops.t-systems.net/chartrepo/PROJECTKEY'
310 310  )))|(((
311 -Name of registry to which the packaged Helm chart is uploaded.
317 +Helm registry to which the packaged Helm chart is uploaded.
318 +
319 +
312 312  )))
313 313  |(((
314 314  helmRegistryCredentialsId
... ... @@ -347,7 +347,7 @@
347 347  )))|(((
348 348  Id of the Jenkins Credentials for signers private keyfile.
349 349  )))
350 -|=(% colspan="1" rowspan="12" %)(((
358 +|=(% colspan="1" rowspan="13" %)(((
351 351  Static Source Code Analysis
352 352  )))|(((
353 353  checkstyleConfig
... ... @@ -380,10 +380,13 @@
380 380  )))|(((
381 381  Defines which named dependency-check tool should be used.
382 382  )))
391 +|dependencyCheckMvnArgs|'-DassemblyAnalyzerEnabled=false'|Additional arguments which are be passed to dependency-check for maven projects.(((
392 +See [[Dependency Check Maven Configuration>>https://jeremylong.github.io/DependencyCheck/dependency-check-maven/configuration.html]] for more information.
393 +)))
383 383  |(((
384 384  dependencyCheckArgs
385 385  )))|(((
386 -'~-~-disableAssembly ~-~-nvdValidForHours 720'
397 +'~-~-disableAssembly'
387 387  )))|(((
388 388  Addtional arguments which are be passed to dependency-check. See [[Dependency>>url:https://jeremylong.github.io/DependencyCheck/dependency-check-cli/arguments.html||shape="rect"]][[ Check CLI Arguments>>url:https://jeremylong.github.io/DependencyCheck/dependency-check-cli/arguments.html||shape="rect"]] for more information.
389 389  )))
... ... @@ -445,6 +445,23 @@
445 445  |sonarQualityGate| |Sets the desired quality gate to use for the scan result in SonarQube.
446 446  If not specified, the quality gate is not changed.
447 447  As a default, SonarQube will use the quality gate "Sonar way" for new scan results.
459 +|=(% colspan="1" %)Dependency Check|skipDependencyCheck|false|Set to true to skip the dependency-check.
460 +|=(% colspan="1" %) |dependencyCheckTool|'dependency-check'|Defines which named dependency-check tool should be used.
461 +|=(% colspan="1" %) |dependencyCheckMvnArgs|'-DassemblyAnalyzerEnabled=false'|Additional arguments which are be passed to dependency-check for maven projects.(((
462 +See [[Dependency Check Maven Configuration>>https://jeremylong.github.io/DependencyCheck/dependency-check-maven/configuration.html]] for more information.
463 +)))
464 +|=(% colspan="1" %) |dependencyCheckArgs|'~-~-disableAssembly'|Addtional arguments which are be passed to dependency-check. See [[Dependency>>url:https://jeremylong.github.io/DependencyCheck/dependency-check-cli/arguments.html||shape="rect"]][[ Check CLI Arguments>>url:https://jeremylong.github.io/DependencyCheck/dependency-check-cli/arguments.html||shape="rect"]] for more information.
465 +|=(% colspan="1" %) |dependencyCheckNvdApiKeyCredentialsId|'dependency-check-nvdapikey'|If you have your own NVD API Key, set it as a credential of type text in Jenkins. Then specify the credential id using this argument. It will be automatically passed to dependency-check. There will be no error if no credential is found. Just the NVD download will be slower. Please note, on DevOps-as-a-Service a shared NVD API Key is automatically supplied for the default credential id.
466 +|=(% colspan="1" rowspan="2" %)Dependency Track|depTrackCredentialsId|'PROJECTKEY-deptrack-projectcreator'|(((
467 +Id of the Jenkins Credential which has to be used to authenticate to Dependency Track for publishing the SBOM.
468 +)))
469 +|depTrackClassifier|'application'|The component type (e.g. application, library, firmware, ...) that should be set in the SBOM file.
470 +Will be later shown as classifier for the project in Dependency Track.
471 +See [[CycloneDX Metadata Component Type>>https://cyclonedx.org/docs/1.6/json/#metadata_component_type]] for supported values.
472 +|=(% colspan="1" rowspan="2" %)Trivy|trivySeverity|'High'|String which sets the minimum severity of Trivy findings that has to be reached to mark the Trivy Results stage as unstable.
473 +Possible values are: "None", "Unknown", "Negligible", "Low", "Medium", "High", "Critical".
474 +|trivyBuildResult|'SUCCESS'|String which sets the overall build result when the result of the Trivy scan reaches trivyServerity.
475 +Possible values are: "SUCCESS", "UNSTABLE" or "FAILURE"
448 448  |=(% rowspan="7" %)(((
449 449  Deployment
450 450  )))|(((