sourceconditiontarget

✔

✔

✗

Description

The stash/tag resource queries the tags of a repository hosted on Bitbucket Server - the product formerly called Stash and now Bitbucket Data Center. It is the usual way to track releases of an internally hosted dependency.

source

Returns the tag matching versionfilter.

condition

Tests that tag exists in the repository.

target

Not supported - a target fails with target not supported for the plugin Stash Tags. Say so on the issue tracker if you would use one.

Note
An scm is accepted but ignored, logging scm not supported, ignored. The lookup always goes to the Bitbucket Server API.

Parameters

NameTypeDescriptionRequired
ownerstring

“owner” defines the repository owner.

compatible:

  • source
  • condition

remark:

  • “owner” is required.
passwordstring

“password” defines the credential used to authenticate with the Bitbucket Server API.

remark:

  • it must be combined with “username”.
  • the Bitbucket Server client does not read “password” yet: set the credential in “token” together with “username” for a basic authentication.
  • a password is sensitive information. Do not set it directly in the manifest, use an environment variable or a SOPS file instead.
  • the value can be set to {{ requiredEnv "BITBUCKET_PASSWORD"}} to read it from the environment variable BITBUCKET_PASSWORD, or to {{ .bitbucket.password }} to read it from a SOPS file.
  • more information about SOPS on https://github.com/getsops/sops
repositorystring

“repository” defines the repository name.

compatible:

  • source
  • condition

remark:

  • “repository” is required.
tagstring

“tag” defines the tag name to check.

compatible:

  • condition
tokenstring

“token” defines the credential used to authenticate with the Bitbucket Server API.

remark:

  • without “username”, the token is sent as a bearer token.
  • a token is sensitive information. Do not set it directly in the manifest, use an environment variable or a SOPS file instead.
  • the value can be set to {{ requiredEnv "BITBUCKET_TOKEN"}} to read the token from the environment variable BITBUCKET_TOKEN, or to {{ .bitbucket.token }} to read it from a SOPS file.
  • more information about SOPS on https://github.com/getsops/sops
urlstring

“url” defines the Bitbucket Server url.

remark:

  • “url” is required.
  • “https://” is added when the url has no scheme.

example:

  • url: bitbucket.example.com
usernamestring

“username” defines the username used to authenticate with the Bitbucket Server API.

remark:

  • when set, “token” is sent as the password of a basic authentication.
versionfilterobject

“versionfilter” defines the version pattern and its kind, such as “regex”, “semver” or “latest”.

compatible:

  • source

default: latest

    kindstring

“kind” defines the versioning scheme used to select a version.

default: latest

remark:

  • accepted values are “latest”, “semver”, “regex”, “regex/semver”, “time”, “regex/time”, “lex” and “pep440”.
  • “latest” returns the last version of the list.
  • “lex” sorts the versions lexicographically and returns the last one.
  • “pep440” follows https://peps.python.org/pep-0440/

example:

  • kind: semver
    patternstring

“pattern” defines the version pattern, according to “kind”.

default:

  • latest: “latest”
  • semver and pep440: “*”
  • regex: “.*”
  • time and regex/time: “2006-01-02”

remark:

  • for “latest”, “latest” returns the last version, any other value must match a version exactly.
  • for “semver” and “regex/semver”, it is a semantic versioning constraint.
  • for “pep440”, it is a pep440 version specifier.
  • for “regex”, it is a regular expression.
  • for “time” and “regex/time”, it is a Go date layout.
  • ignored by “lex”.

example:

  • pattern: ~1.2
  • pattern: “>=1.0.0 <2.0.0”
  • pattern: ^v\d+.\d+.\d+$
    regexstring

“regex” defines the regular expression extracting the version from each entry.

remark:

  • only used by the kinds “regex/semver” and “regex/time”.
  • the value of the first capture group is used as the version.

example:

  • regex: ^v(\d+.\d+.\d+)$
    replaceallobject

“replaceall” applies a regular expression replacement to each version before filtering.

remark:

  • only used by the kinds “regex”, “regex/semver” and “regex/time”.
  • the replacement runs before “pattern” or “regex” is evaluated.

example:

replaceall:
  pattern: "_"
  replacement: "."

turns “curl-8_15_0” into “curl-8.15.0”.

    strictboolean

“strict” enforces strict semantic versioning rules when parsing versions.

default: false

remark:

  • only used by the kinds “semver” and “regex/semver”.

url, owner and repository are mandatory.

url

The Bitbucket Server instance, e.g. https://stash.example.com. This is a self-hosted product, so there is no default.

owner

The project key or user the repository belongs to.

tag

Condition only - the tag being checked.

versionfilter

Source only. kind: semver is the usual choice for release tags. See the "Version Filtering" page.

Authentication

Credentials are either a token or a username and password pair, both sensitive, so read them from the environment or a SOPS file:

spec:
  url: https://stash.example.com
  token: '{{ requiredEnv "BITBUCKET_TOKEN" }}'
  owner: PROJECTKEY
  repository: myrepo

password must be combined with username. Reading a public repository needs no credential at all.

Example

# updatecli.yaml
sources:
  latestTag:
    name: Get the latest release tag
    kind: stash/tag
    spec:
      url: https://stash.example.com
      token: '{{ requiredEnv "BITBUCKET_TOKEN" }}'
      owner: PROJECTKEY
      repository: myrepo
      versionfilter:
        kind: semver