OWASP Dependency Track Python API client
This is a generated library based on the official OWASP Dependency Track OpenAPI spec using openapi-python-client including some sanity patches.
Usage
pip install owasp-dependency-track-client
Create the client
from owasp_dt import Client
client = Client(
base_url="http://localhost:8080/api",
# base_url="http://localhost:8080/api/v2", # For v2 API
headers={
"X-Api-Key": "YOUR API KEY"
},
verify_ssl=False,
)
Call endpoints:
from owasp_dt.api.project import get_projects
projects = get_projects.sync(client=client)
assert len(projects) > 0
OWASP Dependency Track CLI
Looking for a CLI? Check out https://github.com/mreiche/owasp-dependency-track-cli
Development
Update the library
- Install the requirements:
pip install -e ".[test]oruv sync --extra test - Start an OWASP DT instance locally (see Start the test environment): https://docs.dependencytrack.org/getting-started/deploy-docker/
- Run
regenerate-api-client.sh - Check if bugs are still in effect
- Publish this library with the API version tag
Start the test environment
cd test
podman|docker compose up
- Preconfigured user:
admin:admin2 - Preconfigured API key: see
test/test.env
Clean database init
- Prepare
test/docker-compose.yml
init-keys:
volumes:
# Comment out init dir
# - './init:/init:ro'
apiserver:
environment:
# Comment in proxy env variables
HTTP_PROXY: "http://localhost"
HTTPS_PROXY: "http://localhost"
postgres:
volumes:
# Comment out init.sql
# - "./init/init.sql:/docker-entrypoint-initdb.d/init.sql"
-
Delete the volumes first
podman volume rm test_postgres-data podman volume rm test_apiserver-data
-
Start the stack
-
Perform login and change password to
admin2 -
Create an Administrators API key and update
test/test.env -
Dump the data
podman exec test_postgres_1 bash -c "pg_dump -U \$POSTGRES_USER -d \$POSTGRES_DB > /tmp/init.sql" podman cp test_postgres_1:/tmp/init.sql "$(pwd)/test/init/init.sql"
-
Remove all data from tables
dex_workflow_rundex_workflow_history*
-
Save the KEK key
podman cp test_apiserver_1:/data/.dependency-track/keys/secret-management-kek.json "$(pwd)/test/init/secret-management-kek.json"
-
Revert changes in
test/docker-compose.yml -
Restart the stack
Metadata
Release files for owasp-dependency-track-client 5.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| owasp_dependency_track_client-5.1.0.tar.gz | 195.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| owasp_dependency_track_client-5.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 806.2 kB
Release files / owasp_dependency_track_client-5.1.0.tar.gz
| Download URL | owasp_dependency_track_client-5.1.0.tar.gz |
|---|---|
| Size | 195.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
84799b797031d188af7a44fb7cf62db0807b2345b838527f65d674b4b7bc3c74
|
|
BLAKE2b-256 checksum How to use checksums |
f8652c3f534c3624c101cc4b557ce72a8ebaad5cf6a361dfcd46f549e1f2e9df
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.15
|
Release files / owasp_dependency_track_client-5.1.0-py3-none-any.whl
| Download URL | owasp_dependency_track_client-5.1.0-py3-none-any.whl |
|---|---|
| Size | 610.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f439b1edaa49b0160c5d3427b2d03eb3c8bb3a7aa40d63ac7e969aadb2701ceb
|
|
BLAKE2b-256 checksum How to use checksums |
4dd85981fd0366d314211716a60370084c83cbb3aeeb07ee656e86acc5a52c7e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.15
|