Class BaseFiniteStateRecorder

All Implemented Interfaces:
ExtensionPoint, Describable<Publisher>, BuildStep, SimpleBuildStep
Direct Known Subclasses:
FiniteStateAnalyzeBinaryRecorder, FiniteStateSBOMImportRecorder, FiniteStateThirdPartyImportRecorder

public abstract class BaseFiniteStateRecorder extends Recorder implements SimpleBuildStep
Abstract base class for all Finite State recorders. Contains common functionality shared across different analysis types.

The plugin supports two transports, selected per build step via getPlatform():

  • "legacy" (default) — the legacy platform: download and exec the Java CLT jar. Kept so existing jobs keep working unchanged after upgrading the plugin.
  • "2026" — the 2026 platform release: direct calls to the public v0 REST API, described via configureRequest(FiniteStateScanRequest).

FiniteStateExecutionFramework inspects the selected platform and drives the matching flow. The default is the legacy platform so that a job saved before this field existed (no platform in its persisted XML) deserializes to the legacy behavior — an upgrade never silently retargets a job at the 2026 REST API. See HELIX-422.

  • Field Details

    • DEFAULT_POLL_TIMEOUT_MINUTES

      public static final int DEFAULT_POLL_TIMEOUT_MINUTES
      Default poll timeout (minutes) when waiting for scan completion (FR-7).
      See Also:
    • PLATFORM_LEGACY

      public static final String PLATFORM_LEGACY
      Legacy platform transport (Java CLT jar download-and-exec). Default for backward compatibility.
      See Also:
    • PLATFORM_2026

      public static final String PLATFORM_2026
      2026 platform release transport (direct public v0 REST API).
      See Also:
    • subdomain

      protected String subdomain
    • apiTokenCredentialsId

      protected String apiTokenCredentialsId
    • projectName

      protected String projectName
    • projectVersion

      protected String projectVersion
    • externalizableId

      protected Boolean externalizableId
    • preRelease

      protected Boolean preRelease
    • waitForCompletion

      protected Boolean waitForCompletion
    • pollTimeoutMinutes

      protected Integer pollTimeoutMinutes
    • platform

      protected String platform
  • Constructor Details

    • BaseFiniteStateRecorder

      protected BaseFiniteStateRecorder()
  • Method Details

    • getSubdomain

      public String getSubdomain()
    • getApiTokenCredentialsId

      public String getApiTokenCredentialsId()
    • getProjectName

      public String getProjectName()
    • getProjectVersion

      public String getProjectVersion()
    • getExternalizableId

      public boolean getExternalizableId()
    • getPreRelease

      public boolean getPreRelease()
    • getWaitForCompletion

      public boolean getWaitForCompletion()
    • getPollTimeoutMinutes

      public int getPollTimeoutMinutes()
    • getPlatform

      public String getPlatform()
      Selected transport. Defaults to PLATFORM_LEGACY when unset (including jobs whose persisted config predates this field), so upgrading the plugin never changes an existing job's behavior.
    • isRestApi

      public boolean isRestApi()
      True when this step targets the 2026 platform's public v0 REST API instead of the legacy CLT.
    • setSubdomain

      public void setSubdomain(String subdomain)
    • setApiTokenCredentialsId

      @DataBoundSetter public void setApiTokenCredentialsId(String apiTokenCredentialsId)
      Setter to allow Pipeline usage like: apiTokenCredentialsId: 'my-secret-text-id'
    • setProjectName

      public void setProjectName(String projectName)
    • setProjectVersion

      @DataBoundSetter public void setProjectVersion(String projectVersion)
    • setExternalizableId

      @DataBoundSetter public void setExternalizableId(boolean externalizableId)
    • setPreRelease

      @DataBoundSetter public void setPreRelease(boolean preRelease)
    • setWaitForCompletion

      @DataBoundSetter public void setWaitForCompletion(boolean waitForCompletion)
    • setPollTimeoutMinutes

      @DataBoundSetter public void setPollTimeoutMinutes(int pollTimeoutMinutes)
    • setPlatform

      @DataBoundSetter public void setPlatform(String platform)
    • getFileFromWorkspace

      protected FilePath getFileFromWorkspace(FilePath workspace, String relativeFilePath, TaskListener listener) throws IOException, InterruptedException
      Get file from workspace - common utility method (pipeline and freestyle)
      Throws:
      IOException
      InterruptedException
    • getSecretTextValue

      protected String getSecretTextValue(Run<?,?> run, String credentialId)
      Get secret values from credentials - common utility method (pipeline and freestyle)
    • getCLTPath

      protected FilePath getCLTPath(FilePath workspace, String subdomain, String apiToken, TaskListener listener) throws IOException, InterruptedException
      Get CLT path using the shared CLTManager (legacy platform transport only).
      Throws:
      IOException
      InterruptedException
    • buildCLTEnvironment

      protected String[] buildCLTEnvironment(String apiToken)
      Build the environment variables required by the CLT for authentication and domain routing (legacy platform transport only).
    • parseVersion

      protected String parseVersion(Run<?,?> run, String projectVersion)
      Parse version based on externalizableId setting
    • validateCommonFields

      protected boolean validateCommonFields(TaskListener listener)
      Validate common required fields
    • logCommonInfo

      protected void logCommonInfo(Run<?,?> run, TaskListener listener, String filePath)
      Log common information
    • addConsolidatedResult

      protected void addConsolidatedResult(Run<?,?> run, String analysisType, String projectName, String consoleOutput, String status, String url, String scanIds, String scanStatus)
      Add a successful/structured result (with scan metadata) to the consolidated results action.
    • addConsolidatedResult

      protected void addConsolidatedResult(Run<?,?> run, String analysisType, String projectName, String consoleOutput, String status, String url)
      Add a minimal result (error/validation paths that have no scan metadata yet).
    • configureRequest

      protected abstract void configureRequest(FiniteStateScanRequest request)
      Populate the type-specific portion of the scan request (kind + per-analysis fields), used by the 2026 platform's v0 REST transport. The framework fills the common fields (subdomain, token, project, version, polling, etc.).
    • executeAnalysis

      protected abstract int executeAnalysis(FilePath cltPath, FilePath filePath, String projectName, String projectVersion, String apiToken, FilePath workspace, Launcher launcher, TaskListener listener) throws IOException, InterruptedException
      Execute the analysis via the legacy platform's CLT transport. Invoked by FiniteStateExecutionFramework only when isRestApi() is false.
      Returns:
      CLT process exit code (0 = success, 1 = completed with findings, other = error)
      Throws:
      IOException
      InterruptedException
    • getAnalysisType

      protected abstract String getAnalysisType()
      Get the analysis type name for logging and results
    • getFilePathFieldName

      protected abstract String getFilePathFieldName()
      Get the file path field name for validation
    • getFilePathValue

      protected abstract String getFilePathValue()
      Get the file path value
    • perform

      public void perform(Run<?,?> run, FilePath workspace, EnvVars env, Launcher launcher, TaskListener listener) throws InterruptedException, IOException
      Preferred entry point including environment variables. Marks build as failed on error.
      Specified by:
      perform in interface SimpleBuildStep
      Throws:
      InterruptedException
      IOException