OWASP Dependency Track Python API client
This is a generated library based on the official OWASP Dependency Track OpenAPI spec using openapi-python-client including some sanity patches.
Usage
pip install owasp-dependency-track-client
Create the client
from owasp_dt import Client
client = Client(
base_url="http://localhost:8080/api",
# base_url="http://localhost:8080/api/v2", # For v2 API
headers={
"X-Api-Key": "YOUR API KEY"
},
verify_ssl=False,
)
Call endpoints:
from owasp_dt.api.project import get_projects
projects = get_projects.sync(client=client)
assert len(projects) > 0
OWASP Dependency Track CLI
Looking for a CLI? Check out https://github.com/mreiche/owasp-dependency-track-cli
Development
Update the library
- Install the requirements:
pip install -e ".[test]oruv sync --extra test - Start an OWASP DT instance locally (see Start the test environment): https://docs.dependencytrack.org/getting-started/deploy-docker/
- Run
regenerate-api-client.sh - Check if bugs are still in effect
- Publish this library with the API version tag
Start the test environment
cd test
podman|docker compose up
- Preconfigured user:
admin:admin2 - Preconfigured API key: see
test/test.env
Clean database init
- Prepare
test/docker-compose.yml
init-keys:
volumes:
# Comment out init dir
# - './init:/init:ro'
apiserver:
environment:
# Comment in proxy env variables
HTTP_PROXY: "http://localhost"
HTTPS_PROXY: "http://localhost"
postgres:
volumes:
# Comment out init.sql
# - "./init/init.sql:/docker-entrypoint-initdb.d/init.sql"
-
Delete the volumes first
podman volume rm test_postgres-data podman volume rm test_apiserver-data
-
Start the stack
-
Perform login and change password to
admin2 -
Create an Administrators API key and update
test/test.env -
Dump the data
podman exec test_postgres_1 bash -c "pg_dump -U \$POSTGRES_USER -d \$POSTGRES_DB > /tmp/init.sql" podman cp test_postgres_1:/tmp/init.sql "$(pwd)/test/init/init.sql"
-
Remove all data from tables
dex_workflow_rundex_workflow_history*
-
Save the KEK key
podman cp test_apiserver_1:/data/.dependency-track/keys/secret-management-kek.json "$(pwd)/test/init/secret-management-kek.json"
-
Revert changes in
test/docker-compose.yml -
Restart the stack
Release files for owasp-dependency-track-client 5.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| owasp_dependency_track_client-5.1.1.tar.gz | 196.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| owasp_dependency_track_client-5.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 808.2 kB
Release files / owasp_dependency_track_client-5.1.1.tar.gz
| Download URL | owasp_dependency_track_client-5.1.1.tar.gz |
|---|---|
| Size | 196.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
cb0920e739551a7ec4cb1721c8835068bfa7c28e751fc596c48a00f297771b90
|
|
BLAKE2b-256 checksum How to use checksums |
ac8180f8b677d7724adffb76b307965f699c837cb6ce73a9f90bf71d50f34dd8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.15
|
Release files / owasp_dependency_track_client-5.1.1-py3-none-any.whl
| Download URL | owasp_dependency_track_client-5.1.1-py3-none-any.whl |
|---|---|
| Size | 611.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8259373ef126ac96d71f479189193c2d69ebcac0a222f7dd6785658d8d4398e1
|
|
BLAKE2b-256 checksum How to use checksums |
852abc9224104b2d02551ac23dc2f6fae27509ba93b23e96b6642984662ea6d3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.15
|