Skip to content

Retire the legacy Dependency-Track shell uploader - #93

Merged
tonit merged 2 commits into
mainfrom
92-retire-uploader
Sep 25, 2026
Merged

tonit merged 2 commits into
mainfrom
92-retire-uploader

Conversation

@tonit

@tonit tonit commented Sep 25, 2026

Copy link
Copy Markdown
Member

Retires the legacy Dependency-Track uploader and its dedicated tests now that native delivery is the supported SBOM upload path. Removes obsolete CI lint/test entries while preserving installer checks and native delivery demos.

Replaces script instructions with a native migration guide covering preserved project names, explicit creation, child UUIDs and parent hierarchy, credentials, separate polling, failure handling and legacy endpoint differences. The old documentation anchor remains as a migration destination. Updates the CLI/tools inventory and corrects stale manifest comments that equated artifact IDs with receiver project names. Native behavior and unrelated tools are unchanged.

Validation: full baseline Go suite, manifest tests, go vet, 14 CI-detector tests, remaining shell lint and 127 installer checks passed. The documented name/version, autoCreate and child-UUID configurations normalize/plan offline against the released v0.5.0 binary without credentials; native delivery and TLS installed-binary demos pass. Independent review found no blocker; its additional stale-comment finding is fixed. Workflow syntax passes; full actionlint reports only the same two pre-existing ShellCheck diagnostics (SC2129/SC2086) reproduced on unchanged main.

Fixes #92

Copilot AI lite review requested due to automatic review settings September 25, 2026 13:48

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Reviewed changes have no unresolved blocking issues.

Review effort: Lite
Findings: None

What changed in this PR

Retires the legacy Dependency-Track shell uploader and transitions users to native delivery.

Changes:

  • Removes the uploader, tests, and obsolete CI checks.
  • Adds native migration guidance.
  • Clarifies manifest and CLI documentation.
File Summary
tools/​rio-dtrack-upload.sh Removes legacy uploader
tools/​rio-dtrack-upload_test.sh Removes dedicated tests
tools/​README.md Adds migration guidance
internal/​manifest/​manifest.go Corrects artifact ID comments
docs/​manifest.md Clarifies artifact selector semantics
docs/​cli.md Updates migration guidance
.github/​workflows/​ci.yaml Removes obsolete checks

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Retire the legacy Dependency-Track uploader and migrate its documentation

2 participants