Blackduck is the standard tool within ZEISS to monitor dependencies of software projects and scan for potential security issues in those dependencies. You can find more general information about the usage of Blackduck within ZEISS in the wiki: https://wiki.zeiss.com/spaces/FOSS/pages/387680848/Overview+BlackDuck
All ZUi-Web artifacts are automatically scanned by Blackduck. This way, you can add ZUi-Web as dependency to your project in Blackduck and get notified about potential issues coming from ZUi-Web.
You can find the artifacts here:
Before you can see and use these Blackduck artifacts, you will need to request access to Blackduck itself. See the wiki documentation for this.
In the past, you needed to request access to the ZUi-Web artifacts explicitly to be able to see and use them in Blackduck.
This shouldn't be the case anymore and you should be able to find the artifacts in Blackduck without additional configuration needed. However, this might be a subject to change in the future and might not be in our hand as ZUi-Web team.
Matching unmatched components (e.g. ZUi-Web) in Blackduck
Sometimes Blackduck detects ZUi-Web (or other dependencies) as unmatched components or unmatched IDs/files. You can manually map these to the correct ZUi-Web project version:
- Open your Blackduck project and go to the Source tab.
- Apply the filter “Unmatched IDs” (or “Unmatched Files”).
- Identify the relevant unmatched entries (for example ones related to ZUi-Web).
- Click on the “…” menu of the entry and choose Edit adjustment.
- Map it to the appropriate ZUi-Web project version (e.g. the matching
@zeiss/zuiartifact). - After saving, the component will automatically disappear from the Unmatched Components tab.
A short video showing this workflow (using ZUi-Web as an example) plus a short description is available in the FOSS wiki (Requires login with your ZEISS account.)
If you have trouble using ZUi-Web artifacts in your Blackduck project, please use our tech-support channel in Teams.