<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Blackduck scanning on Databricks Workflow in Get Started Discussions</title>
    <link>https://community.databricks.com/t5/get-started-discussions/blackduck-scanning-on-databricks-workflow/m-p/129794#M10613</link>
    <description>&lt;P&gt;Does anyone know if its compatible scan in blackduck your json based files from Workflows?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At least, when its come to the notebook its compatible as blackduck detects python based files but i am wondering why can workflow be scanned as well.&lt;/P&gt;</description>
    <pubDate>Tue, 26 Aug 2025 10:19:50 GMT</pubDate>
    <dc:creator>fjrodriguez</dc:creator>
    <dc:date>2025-08-26T10:19:50Z</dc:date>
    <item>
      <title>Blackduck scanning on Databricks Workflow</title>
      <link>https://community.databricks.com/t5/get-started-discussions/blackduck-scanning-on-databricks-workflow/m-p/129794#M10613</link>
      <description>&lt;P&gt;Does anyone know if its compatible scan in blackduck your json based files from Workflows?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At least, when its come to the notebook its compatible as blackduck detects python based files but i am wondering why can workflow be scanned as well.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Aug 2025 10:19:50 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/blackduck-scanning-on-databricks-workflow/m-p/129794#M10613</guid>
      <dc:creator>fjrodriguez</dc:creator>
      <dc:date>2025-08-26T10:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Blackduck scanning on Databricks Workflow</title>
      <link>https://community.databricks.com/t5/get-started-discussions/blackduck-scanning-on-databricks-workflow/m-p/132514#M10726</link>
      <description>&lt;DIV class="prose text-pretty dark:prose-invert inline leading-relaxed break-words min-w-0 [word-break:break-word] prose-strong:font-medium"&gt;
&lt;P&gt;Hi &lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/176268"&gt;@fjrodriguez&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Have you found your answer already? I hope I understand your question correctly. I think Databricks Asset Bundles (or Terraform) can be a useful tool to be added here, if you haven't looked at it already.&lt;/P&gt;
&lt;UL class="marker:text-quiet list-disc"&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;&lt;STRONG&gt;Yes, you can and should scan both Python and JSON files&lt;/STRONG&gt; (e.g., Databricks Workflow configs) with BlackDuck to detect vulnerabilities and exposed secrets such as API tokens.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;&lt;STRONG&gt;Databricks Asset Bundles&lt;/STRONG&gt; let you manage all related Python scripts and JSON configuration files together in a Git repository. This structure makes it easy to apply automated BlackDuck scans across your entire Databricks project using CI/CD pipelines, ensuring all assets are checked for security issues before deployment.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;This approach helps you maintain security and compliance across your Databricks workflows.&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A href="https://wdcnet.com.br/wp-content/uploads/2025/01/Black-Duck-Secrets-Scanning.pdf" target="_blank"&gt;https://wdcnet.com.br/wp-content/uploads/2025/01/Black-Duck-Secrets-Scanning.pdf&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://www.blackduck.com/blog/finding-hard-coded-secrets-before-you-suffer-a-breach.html" target="_blank"&gt;https://www.blackduck.com/blog/finding-hard-coded-secrets-before-you-suffer-a-breach.html&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.databricks.com/t5/technical-blog/ci-cd-integration-with-databricks-workflows/ba-p/81821" target="_blank"&gt;https://community.databricks.com/t5/technical-blog/ci-cd-integration-with-databricks-workflows/ba-p/81821&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://docs.databricks.com/aws/en/dev-tools/ci-cd/" target="_blank"&gt;https://docs.databricks.com/aws/en/dev-tools/ci-cd/&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://documentation.blackduck.com/category/cicd_integrations" target="_blank"&gt;https://documentation.blackduck.com/category/cicd_integrations&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 19 Sep 2025 02:32:27 GMT</pubDate>
      <guid>https://community.databricks.com/t5/get-started-discussions/blackduck-scanning-on-databricks-workflow/m-p/132514#M10726</guid>
      <dc:creator>koji_kawamura</dc:creator>
      <dc:date>2025-09-19T02:32:27Z</dc:date>
    </item>
  </channel>
</rss>

