Sonatype for Bamboo Data Center
Sonatype for Bamboo Data Center
Sonatype for Bamboo Data Center integrates with Atlassian Bamboo to run policy evaluations in the build workspace. It provides instant analysis of open-source components used in every Bamboo build and generates alerts for policy violations related to quality, license, or security. This allows development teams to address open-source policy violations earlier in the development cycle and avoid unplanned rework.
The Sonatype for Bamboo Data Center integration is available on the Atlassian Marketplace.
Note
Sonatype for Bamboo Data Center plugin is verified by Sonatype to work on the Bamboo Data Center.
Main Features
- Perform a Lifecycle policy evaluation on files in the build workspace.
- Display scan results within Bamboo build workspace.
- Provide a link to a comprehensive Lifecycle policy evaluation report indicating violation details and remediation recommendations.
Release Notes
clm-bamboo-plugin
Changelog
Version 4.5.1 (July 08, 2026)
- Maintenance release
Version 4.5.0 (June 04, 2026)
- Added support for .NET reachability analysis
- Added support for reachability analysis evidence
Version 4.4.2 (May 07, 2026)
- Maintenance release
Version 4.4.1 (April 21, 2026)
- Maintenance release
Version 4.4.0 (April 08, 2026)
- Added support for API-based CI configuration
- Added support for Sonatype Container Scanner
Version 4.3.1 (March 06, 2026)
- Maintenance release
Version 4.3.0 (February 09, 2026)
- Added support for JavaScript reachability analysis
- Added support for Bamboo Data Center version 12
Version 4.2.3 (December 05, 2025)
- Fixed an edge case where scans failed for npm projects
Version 4.2.2 (November 21, 2025)
- Maintenance release
Version 3.4.0 (November 21, 2025)
- Maintenance release
Version 2.44.0 (November 21, 2025)
- Maintenance release
Version 3.3.3 (November 12, 2025)
- Fixed an issue preventing Lifecycle evaluations from running on remote agents in Bamboo 10.2.x
Version 4.2.1 (November 07, 2025)
- Maintenance release
Version 3.3.2 (October 27, 2025)
- Fixed an issue preventing Lifecycle evaluations from running in Bamboo 10.2.7
Version 4.2.0 (October 10, 2025)
- Added support for analyzing Java 25 bytecode
Version 2.43.4 (October 7, 2025)
- Maintenance release
Version 4.1.1 (September 12, 2025)
- Fixed an issue preventing Lifecycle evaluations from running in Bamboo 11.0.4
Version 4.1.0 (August 15, 2025)
- Added support for analyzing Java 23 and Java 24 bytecode
Version 3.3.1 (August 15, 2025)
- Fixed an issue preventing Lifecycle evaluations from running in Bamboo 10.2.x
Version 4.0.1 (July 10, 2025)
- Maintenance release
Version 4.0.0 (June 16, 2025)
- Added support for Bamboo Data Center version 11
Version 3.3.0 (May 09, 2025)
- Added support for the auto waivers feature
Version 3.2.0 (April 04, 2025)
- Added support for Java Reachability Analysis
Version 3.1.5 (March 05, 2025)
- Added both Priorities and Report URLs to Scan Results Summaries
Version 3.1.4 (February 05, 2025)
- Added branch name collection when a scan runs in a Git repository context
Version 3.1.3 (January 17, 2025)
- Fixed an issue that prevented scanning due to missing classes in the plugin’s dependencies
Version 3.1.2 (January 09, 2025)
- Maintenance release
Version 3.1.1 (December 18, 2024)
- Fixed a NullPointerException that occurred when reading credentials
Version 3.1.0 (December 12, 2024)
- Added support for variables and credentials in Bamboo Data Center, applicable at global, project, and plan levels
- Fixed issue that caused an error (
ClassNotFoundException: org.yaml.snakeyaml.error.YAMLException) during the scanning of YAML files
Version 3.0.4 (November 15, 2024)
- Updated internal dependencies to address a security vulnerability
Version 3.0.3 (November 08, 2024)
- Maintenance release
Version 3.0.2 (October 28, 2024)
- Fixed intermittent issue related to Java 17 and 21 bytecode scanning
Version 3.0.1 (October 11, 2024)
- Maintenance release
Version 3.0.0 (October 01, 2024)
- Added support for Bamboo Data Center version 10
Version 2.43.3 (September 04, 2024)
- Maintenance release
Version 2.43.2 (August 20, 2024)
- Updated internal dependencies to ensure compatibility with Lifecycle 181
Version 2.43.1 (August 12, 2024)
- Updated internal dependencies to ensure compatibility with Lifecycle 180
- Added support for analyzing Java 21 and Java 22 bytecode
Version 2.43.0 (July 10, 2024)
- Updated internal dependencies to ensure compatibility with Lifecycle 179
Version 2.42.6 (June 26, 2024)
- Updated internal dependencies to ensure compatibility with Lifecycle 178
Version 2.42.5 (June 4, 2024)
- Updated internal dependencies to ensure compatibility with Lifecycle 177
- Fixed issue ClassNotFoundException:javax.management.MalformedObjectNameException
Version 2.42.4 (May 14, 2024)
- Updated internal dependencies to ensure compatibility with Lifecycle 176
Version 2.42.3 (April 9, 2024)
- Updated internal dependencies to ensure compatibility with Lifecycle 175
Version 2.42.2 (March 11, 2024)
- Updated internal dependencies to ensure compatibility with Lifecycle 174
Version 2.42.0 (March 5, 2024)
- Sonatype for Bamboo is now certified for Bamboo Data Center
Version 2.41.1 (January 22, 2024)
- Updated internal dependencies to ensure compatibility with Lifecycle 171
Version 2.41.0 (December 8, 2023)
- Updated internal dependencies to ensure compatibility with Lifecycle 170
Version 2.40.0 (November 1, 2023)
- Updated internal dependencies to ensure compatibility with Lifecycle 169
Version 2.39.0 (October 16, 2023)
- Updated internal dependencies to ensure compatibility with Lifecycle 168
Version 2.38.0 (September 7, 2023)
- Updated internal dependencies to ensure compatibility with Lifecycle 167
Version 2.37.0 (August 25, 2023)
- Updated internal dependencies to ensure compatibility with Lifecycle 166
Version 2.36.0 (July 20, 2023)
- Updated internal dependencies to ensure compatibility with Lifecycle 165
Version 2.35.0 (June 30, 2023)
- Updated internal dependencies to ensure compatibility with Lifecycle 164
Version 2.34.0 (June 16, 2023)
- Updated internal dependencies to ensure compatibility with Lifecycle 163
Version 2.33.0 (June 9, 2023)
- Updated internal dependencies to ensure compatibility with Lifecycle 162
Version 2.32.0 (May 15, 2023)
- Updated internal dependencies to ensure compatibility with Lifecycle 161
Version 2.31.0 (April 20, 2023)
- Updated internal dependencies to ensure compatibility with Lifecycle 160
Version 2.30.0 (April 6, 2023)
- Updated internal dependencies to ensure compatibility with Lifecycle 159
Version 2.29.0 (March 21, 2023)
- Updated internal dependencies to ensure compatibility with Lifecycle 158
Version 2.28.0 (March 17, 2023)
- Updated internal dependencies to ensure compatibility with Lifecycle 156
Version 2.21.1 (March 17, 2023)
- Seamlessly fortifying Bamboo CI/CD pipelines with Shift-left security
Compatibility
| Plugin Version | IQ Server Version | Bamboo Version | Java Runtime |
|---|---|---|---|
| 4.3.0-01 and higher | 70 and higher | 12.x | JDK 21 |
| 4.0.0-01 to 4.2.3-01 | 70 and higher | 11.x | JDK 17 |
| 3.0.0-01 to 3.3.2-01 | 70 and higher | 10.0.0 to 10.2.7 | JDK 17 |
| 2.42.0-01 to 2.43.4-02 | 70 and higher | 8.2.0 to 9.6.6 | JDK 11, JDK 17 |
| 2.42.0-01 | 70 and higher | 8.2.0 to 9.6.0 | JDK 11 |
| 2.0 to 2.41.1-01 | 70 and higher | 6.8 to 9.0 | JDK 8, JDK 11 (Bamboo 8+) |
| 1.14 to 2.0 | 70 and higher | 5.10 to 7.2 | JDK 8 |
| 1.13 | 69 and higher | 5.10 to 7.2 | JDK 8 |
| 1.9 to 1.12.1 | 50 and higher | 5.10 to 7.2 | JDK 8 |
| 1.8 | 1.45 and higher | 5.10 to 7.2 | JDK 8 |
| 1.1 to 1.7 | All versions | 5.10 to 7.2 | JDK 8 |
Requirements
- Install and start IQ Server.
- Create an organization and at least one application in IQ Server.
- Evaluate the application at least once (see Manual Application Evaluation.)
Installation and Configuration
Go to the Installation and Configuration page for steps to install and set up Sonatype for Bamboo Data Center.
Variables and credentials
Starting from version 3.1.0, you can configure variables and credentials at the global, project, or plan level from the Bamboo administration page.
To add a variable, click on the Global variables option on the left-hand navigation menu, and enter a variable name and value.
To add a credential, click on the Shared credentials option on the left-hand navigation menu, and enter the a Credential name, Username, and Password.
The Credential name field is the value that will be used by the Sonatype for Bamboo Data Center plugin; make sure it's one of the supported values listed below. The Username field can be set to match the Credential Name.
Sonatype for Bamboo Data Center currently supports the following credentials:
NEXUS_CONTAINER_IMAGE_REGISTRY_USER
NEXUS_CONTAINER_IMAGE_REGISTRY_PASSWORD
NEXUS_CONTAINER_SCANNING_REGISTRY_USER
NEXUS_CONTAINER_SCANNING_REGISTRY_PASSWORD
Add Sonatype Lifecycle analysis task
- Navigate to a Bamboo Project > Plan > Stage > and then Job, select the Tasks tab, and then click on the Add task button.
- A modal displays a list of available Task types. Lifecycle Policy Evaluation is listed in the Tests type, or you can use search to locate it.
- Enter the required information:
- Task Description: a brief explanation of what the task does.
- Disable this task: an option to disable the entire Lifecycle Policy Evaluation process, ensuring it is skipped during plan execution.
- Add condition to task: an option to configure the task to execute only when a specified condition is met.
- Fail build when IQ Server is unable to evaluate: check this option to fail the build when an IQ evaluation cannot be performed. This may occur if the IQ Server is inaccessible. If left unchecked, the build will continue even without a policy evaluation.
Tip
Details of the application evaluation are provided in the job/build-specific log.
- Fail build when there are scanning errors: check this option if you want to fail the build when there are scanning errors. This could occur if for example there are malformed files.
- Organization (optional): the list of Organizations retrieved from the IQ Server. An organization ID can also be specified directly. If an organization is selected and automatic application creation is enabled, a new application will automatically be created under the selected organization, if it does not already exist on the IQ Server.
- Application: the list of Applications corresponds to the account used during Sonatype for Bamboo Data Center configuration. Remember, this is the Application containing the policies that components in the build will be evaluated against. An application can also be specified that is not in the list. If automatic application creation is enabled, an application with the specified ID will automatically be created if it does not already exist on the IQ Server.
- Stage: this corresponds to the stage you wish the policy evaluation of the application/project to be run against. Additionally, this will correspond to the stage location when viewing report information via the IQ Server. For example, if you chose the Build stage, summary and dashboard violation results will be displayed accordingly.
- Scan Targets: the scan targets setting allows you to control which files should be examined with an Apache Ant styled pattern. The pattern is relative to the project workspace root directory and inherits the global configuration.
- Advanced Options - Module Excludes: if you are using the Sonatype CLM for Maven plugin, module files are created, and can contribute to results found during an evaluation.
- Java Reachability - Enable Java reachability analysis: Perform an analysis in Java or JVM language binaries to detect method signatures that contain components with potentially exploitable security vulnerabilities. You can customize the analysis by selecting the algorithm for reachability, specifying scan targets (which default to the predefined targets if left empty), choosing an entrypoint identification strategy, and defining the relevant namespaces.
- Click the Save button. Lifecycle Policy Evaluation task now appears in the list as Final tasks.
Evaluate Policies and View Results
Your application will be evaluated as a task during Bamboo job execution. The Job Summary page shows the results of the evaluation.
The summary results give a breakdown and count of violations for each of the 3 threat level categories:
- Critical (threat level 8-10)
- Severe (threat level 4-7)
- Moderate (threat level 2-3)
The overall evaluation status is indicated by Passed, Failed, Passed with Warnings.
Click on Full Report to view a detailed report in the IQ Server.
Reachability Analysis
See Reachability Analysis with Bamboo for how to enable Reachability in builds, covering required permissions and plugin version (3.2.0+), the parameters, using includes to narrow artifacts, and the entry point strategy with tips for scoping via namespaces.
Centralized CI configuration
To centrally manage supported CI evaluation settings for Bamboo Data Center builds through the Lifecycle organization and application hierarchy, see the CI Configuration REST API.