Handle WebHooks from Sonatype Lifecycle with ease!
1.1K
This project contains an example (working) Web Hook handler for Sonatype Lifecycle that can publish messages to Microsoft Teams Channel(s), Slack Channel(s), or open Jira Issues.
Contents
Create a config.json file formatted like the provided example.config.json.
The config.json will allow you to configure multiple endpoints for a single message from Sonatype IQ. You can configure 1 or several message types.
NOTE: Currently the "applications" key only allows for the value to be "DEFAULT". Currently the "events" array is only configured for "APPLICATION_EVALUATION" for Slack and Microsoft Teams and WAIVER_REQUEST for Jira.
Configuring the Jira API to create issues is dependent on the version of Jira you have in use (Cloud, Data-Center, etc.). This blog will be helpful for more detailed setup steps: https://blog.developer.atlassian.com/creating-a-jira-cloud-issue-in-a-single-rest-call/
echo -n '<YOUR-EMAIL-ADDRESS>:<YOUR-API-TOKEN>' | base64
Want to change the output? Here are the Jira Markdown Docs: https://developer.atlassian.com/cloud/jira/platform/apis/document/nodes/blockquote
On Slack we need to create an app to listen for our Webhooks from Sonatype Lifecycle:
Follow the official Sonatype Documentation to add this handler as a Webhook.

Supported WebHook Events currently are:
This webhook handler is published as a Docker Image to Docker Hub.
An example docker-compose.yml might be:
services:
webhook-teams:
image: sonatype-webhook-handler:latest
environment:
- CONFIG_FILE_PATH=/your/path/to/your/config.json
- IQ_SERVER_URL=[YOUR_IQ_SERVER_URL_HERE]
- PORT=3000
ports:
- '3000:3000'
Then you can just run: docker-compose up -d .
You can run this on any Node 16 or Node 18 environment.
npm install to obtain the required depnedencies.env file as follows:
CONFIG_FILE_PATH=/your/path/to/your/config.json
IQ_SERVER_URL=https://my-iq-server-url # Full URL to your Sonatype Lifecycle Server
PORT=3000 # The port to run this handler on
npm start - the handler is now listening on http://localhost:3000/You can quickly test the handler by accessing one of the test URLs:
Your rules (as defined in your config.json) will be applied to the simulated payloads.

Remember:
It is worth noting that this is NOT SUPPORTED by Sonatype, and is a contribution of ours to the open source community (read: you!)
sonatype-webhook-handlerPhew, that was easier than I thought. Last but not least of all - have fun!
Content type
Image
Digest
sha256:00305c5d2…
Size
95.6 MB
Last updated
about 3 years ago
docker pull sonatypecommunity/sonatype-webhook-handler