Al Sutton<p><a href="https://snapp.social/tags/devops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>devops</span></a> rabbit hole for the weekend; Setting up a dependency analyser for monorepo. Turns out that with the right tools it’s not that difficult, and only costs the price of hosting some docker containers.</p><p>The parts of the puzzle are;</p><p><a href="https://github.com/CycloneDX/cyclonedx-gradle-plugin" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/CycloneDX/cyclonedx</span><span class="invisible">-gradle-plugin</span></a></p><p><a href="https://github.com/marketplace/actions/upload-bom-to-dependency-track" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/marketplace/actions</span><span class="invisible">/upload-bom-to-dependency-track</span></a></p><p><a href="https://docs.dependencytrack.org/getting-started/deploy-docker/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">docs.dependencytrack.org/getti</span><span class="invisible">ng-started/deploy-docker/</span></a></p><p><a href="https://snapp.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://snapp.social/tags/AndroidDev" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AndroidDev</span></a> <a href="https://snapp.social/tags/Kotlin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Kotlin</span></a> <a href="https://snapp.social/tags/java" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>java</span></a> <a href="https://snapp.social/tags/owasp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>owasp</span></a></p>