Retire the legacy Dependency-Track shell uploader - #93
Merged
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
Reviewed changes have no unresolved blocking issues.
Review effort: Lite
Findings: None
What changed in this PR
Retires the legacy Dependency-Track shell uploader and transitions users to native delivery.
Changes:
- Removes the uploader, tests, and obsolete CI checks.
- Adds native migration guidance.
- Clarifies manifest and CLI documentation.
| File | Summary |
|---|---|
tools/rio-dtrack-upload.sh |
Removes legacy uploader |
tools/rio-dtrack-upload_test.sh |
Removes dedicated tests |
tools/README.md |
Adds migration guidance |
internal/manifest/manifest.go |
Corrects artifact ID comments |
docs/manifest.md |
Clarifies artifact selector semantics |
docs/cli.md |
Updates migration guidance |
.github/workflows/ci.yaml |
Removes obsolete checks |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This was referenced Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Retires the legacy Dependency-Track uploader and its dedicated tests now that native delivery is the supported SBOM upload path. Removes obsolete CI lint/test entries while preserving installer checks and native delivery demos.
Replaces script instructions with a native migration guide covering preserved project names, explicit creation, child UUIDs and parent hierarchy, credentials, separate polling, failure handling and legacy endpoint differences. The old documentation anchor remains as a migration destination. Updates the CLI/tools inventory and corrects stale manifest comments that equated artifact IDs with receiver project names. Native behavior and unrelated tools are unchanged.
Validation: full baseline Go suite, manifest tests, go vet, 14 CI-detector tests, remaining shell lint and 127 installer checks passed. The documented name/version, autoCreate and child-UUID configurations normalize/plan offline against the released v0.5.0 binary without credentials; native delivery and TLS installed-binary demos pass. Independent review found no blocker; its additional stale-comment finding is fixed. Workflow syntax passes; full actionlint reports only the same two pre-existing ShellCheck diagnostics (SC2129/SC2086) reproduced on unchanged main.
Fixes #92