First you must configure a user/API token in Black Duck SCA so that the Detect findings are analyzed in Black Duck SCA.
Generating an API token
Log in into your Black Duck SCA instance.
From the user menu located on the top navigation bar, select My Access Tokens. The My Access Tokens page appears.
Click Create New Token. The Create New Token dialog box appears
Type your name in the Name field.
Optional: in the Description field, you can type a description or definition.
Select Read and Write Access.
Click Create. The API token displays in a pop-up window. For security reasons, this is the only time your user API token displays. Please save this token. If the token is lost, you must regenerate it.
Optional: To modify an access token that you created, click the arrow in the same row as the access token name to open a drop-down menu and select Edit, Delete, or Regenerate.
Configure the plugin with your Black Duck SCA url and the API token you just generated.
The following user roles are required for the user that you create in Black Duck SCA:
| Role | Action |
|---|---|
| Project Creator | Creates Black Duck SCA projects |
| Project Code Scanner | Populates project BOMGlobal Code Scanner can also be used to populate Project BOM |
| Global Code Scanner | Populates the project BOM, generates reports, checks for policy violations. |
| Project Manager | Generates reports |
Note: A user with the Global Code Scanner overall role can generate a report, but cannot delete the report. The Project Manager project role is required to delete the report.