Sonatype for Bamboo Data Center

Sonatype for Bamboo Data Center

Sonatype for Bamboo Data Center integrates with Atlassian Bamboo to run policy evaluations in the build workspace. It provides instant analysis of open-source components used in every Bamboo build and generates alerts for policy violations related to quality, license, or security. This allows development teams to address open-source policy violations earlier in the development cycle and avoid unplanned rework.

The Sonatype for Bamboo Data Center integration is available on the Atlassian Marketplace.

Note
Sonatype for Bamboo Data Center plugin is verified by Sonatype to work on the Bamboo Data Center.

Main Features

  1. Perform a Lifecycle policy evaluation on files in the build workspace.
  2. Display scan results within Bamboo build workspace.
  3. Provide a link to a comprehensive Lifecycle policy evaluation report indicating violation details and remediation recommendations.

Release Notes

clm-bamboo-plugin

Changelog

Version 4.5.1 (July 08, 2026)

Version 4.5.0 (June 04, 2026)

Version 4.4.2 (May 07, 2026)

Version 4.4.1 (April 21, 2026)

Version 4.4.0 (April 08, 2026)

Version 4.3.1 (March 06, 2026)

Version 4.3.0 (February 09, 2026)

Version 4.2.3 (December 05, 2025)

Version 4.2.2 (November 21, 2025)

Version 3.4.0 (November 21, 2025)

Version 2.44.0 (November 21, 2025)

Version 3.3.3 (November 12, 2025)

Version 4.2.1 (November 07, 2025)

Version 3.3.2 (October 27, 2025)

Version 4.2.0 (October 10, 2025)

Version 2.43.4 (October 7, 2025)

Version 4.1.1 (September 12, 2025)

Version 4.1.0 (August 15, 2025)

Version 3.3.1 (August 15, 2025)

Version 4.0.1 (July 10, 2025)

Version 4.0.0 (June 16, 2025)

Version 3.3.0 (May 09, 2025)

Version 3.2.0 (April 04, 2025)

Version 3.1.5 (March 05, 2025)

Version 3.1.4 (February 05, 2025)

Version 3.1.3 (January 17, 2025)

Version 3.1.2 (January 09, 2025)

Version 3.1.1 (December 18, 2024)

Version 3.1.0 (December 12, 2024)

Version 3.0.4 (November 15, 2024)

Version 3.0.3 (November 08, 2024)

Version 3.0.2 (October 28, 2024)

Version 3.0.1 (October 11, 2024)

Version 3.0.0 (October 01, 2024)

Version 2.43.3 (September 04, 2024)

Version 2.43.2 (August 20, 2024)

Version 2.43.1 (August 12, 2024)

Version 2.43.0 (July 10, 2024)

Version 2.42.6 (June 26, 2024)

Version 2.42.5 (June 4, 2024)

Version 2.42.4 (May 14, 2024)

Version 2.42.3 (April 9, 2024)

Version 2.42.2 (March 11, 2024)

Version 2.42.0 (March 5, 2024)

Version 2.41.1 (January 22, 2024)

Version 2.41.0 (December 8, 2023)

Version 2.40.0 (November 1, 2023)

Version 2.39.0 (October 16, 2023)

Version 2.38.0 (September 7, 2023)

Version 2.37.0 (August 25, 2023)

Version 2.36.0 (July 20, 2023)

Version 2.35.0 (June 30, 2023)

Version 2.34.0 (June 16, 2023)

Version 2.33.0 (June 9, 2023)

Version 2.32.0 (May 15, 2023)

Version 2.31.0 (April 20, 2023)

Version 2.30.0 (April 6, 2023)

Version 2.29.0 (March 21, 2023)

Version 2.28.0 (March 17, 2023)

Version 2.21.1 (March 17, 2023)

Compatibility

Plugin Version IQ Server Version Bamboo Version Java Runtime
4.3.0-01 and higher 70 and higher 12.x JDK 21
4.0.0-01 to 4.2.3-01 70 and higher 11.x JDK 17
3.0.0-01 to 3.3.2-01 70 and higher 10.0.0 to 10.2.7 JDK 17
2.42.0-01 to 2.43.4-02 70 and higher 8.2.0 to 9.6.6 JDK 11, JDK 17
2.42.0-01 70 and higher 8.2.0 to 9.6.0 JDK 11
2.0 to 2.41.1-01 70 and higher 6.8 to 9.0 JDK 8, JDK 11 (Bamboo 8+)
1.14 to 2.0 70 and higher 5.10 to 7.2 JDK 8
1.13 69 and higher 5.10 to 7.2 JDK 8
1.9 to 1.12.1 50 and higher 5.10 to 7.2 JDK 8
1.8 1.45 and higher 5.10 to 7.2 JDK 8
1.1 to 1.7 All versions 5.10 to 7.2 JDK 8

Requirements

Installation and Configuration

Go to the Installation and Configuration page for steps to install and set up Sonatype for Bamboo Data Center.

Variables and credentials

Starting from version 3.1.0, you can configure variables and credentials at the global, project, or plan level from the Bamboo administration page.

To add a variable, click on the Global variables option on the left-hand navigation menu, and enter a variable name and value.

To add a credential, click on the Shared credentials option on the left-hand navigation menu, and enter the a Credential name, Username, and Password.

The Credential name field is the value that will be used by the Sonatype for Bamboo Data Center plugin; make sure it's one of the supported values listed below. The Username field can be set to match the Credential Name.

Sonatype for Bamboo Data Center currently supports the following credentials:

NEXUS_CONTAINER_IMAGE_REGISTRY_USER
NEXUS_CONTAINER_IMAGE_REGISTRY_PASSWORD
NEXUS_CONTAINER_SCANNING_REGISTRY_USER
NEXUS_CONTAINER_SCANNING_REGISTRY_PASSWORD

Add Sonatype Lifecycle analysis task

  1. Navigate to a Bamboo Project > Plan > Stage > and then Job, select the Tasks tab, and then click on the Add task button.
  1. A modal displays a list of available Task types. Lifecycle Policy Evaluation is listed in the Tests type, or you can use search to locate it.
  1. Enter the required information:

Tip
Details of the application evaluation are provided in the job/build-specific log.

  1. Click the Save button. Lifecycle Policy Evaluation task now appears in the list as Final tasks.

Evaluate Policies and View Results

Your application will be evaluated as a task during Bamboo job execution. The Job Summary page shows the results of the evaluation.

The summary results give a breakdown and count of violations for each of the 3 threat level categories:

The overall evaluation status is indicated by Passed, Failed, Passed with Warnings.

Click on Full Report to view a detailed report in the IQ Server.

Reachability Analysis

See Reachability Analysis with Bamboo for how to enable Reachability in builds, covering required permissions and plugin version (3.2.0+), the parameters, using includes to narrow artifacts, and the entry point strategy with tips for scoping via namespaces.

Centralized CI configuration

To centrally manage supported CI evaluation settings for Bamboo Data Center builds through the Lifecycle organization and application hierarchy, see the CI Configuration REST API.