ppkarwasz commented on PR #8707:
URL: https://github.com/apache/hadoop/pull/8707#issuecomment-5462946957

   For reviewers, here are three real entries taken from the generated BOMs 
(`<description>` and `<externalReferences>` elided for brevity).
   
   **1. External dependency** — `commons-logging` in 
`hadoop-client-runtime/target/bom.xml`. It is on the shade `artifactSet` 
exclude list (left unshaded so downstream users can configure logging), so it 
gets an explicit `isExternal="true"` and keeps its hash:
   
   ```xml
   <component type="library" 
bom-ref="pkg:maven/commons-logging/[email protected]?type=jar" 
isExternal="true">
     <publisher>The Apache Software Foundation</publisher>
     <group>commons-logging</group>
     <name>commons-logging</name>
     <version>1.3.0</version>
     <scope>required</scope>
     <hashes>
       <hash 
alg="SHA-256">66d3c980470b99b0c511dad3dfc0ae7b265ec1fb144e96bc0253a8a175fd34d9</hash>
     </hashes>
     <licenses>
       <license>
         <id>Apache-2.0</id>
         <url>https://www.apache.org/licenses/LICENSE-2.0</url>
       </license>
     </licenses>
     <purl>pkg:maven/commons-logging/[email protected]?type=jar</purl>
   </component>
   ```
   
   **2. Non-relocated embedded dependency** — `httpclient5` in 
`hadoop-tos/target/bom.xml`. `hadoop-tos` shades without relocations, so the 
embedded classes are verbatim copies: the component omits `isExternal` (the 
schema default is `false`), keeps the original's hash, and carries a notes-only 
pedigree:
   
   ```xml
   <component type="library" 
bom-ref="pkg:maven/org.apache.httpcomponents.client5/[email protected]?type=jar">
     <publisher>The Apache Software Foundation</publisher>
     <group>org.apache.httpcomponents.client5</group>
     <name>httpclient5</name>
     <version>5.5</version>
     <scope>required</scope>
     <hashes>
       <hash 
alg="SHA-256">496b4b0e8d5f3a8139a5d2638486d304758bac3a9c39d76989f663cfd9354fc9</hash>
     </hashes>
     <licenses>
       <license>
         <id>Apache-2.0</id>
       </license>
     </licenses>
     
<purl>pkg:maven/org.apache.httpcomponents.client5/[email protected]?type=jar</purl>
     <pedigree>
       <notes>Embedded verbatim into this artifact by maven-shade-plugin, 
without package relocation; the hashes describe the original standalone 
artifact.</notes>
     </pedigree>
   </component>
   ```
   
   **3. Relocated embedded dependency** — `commons-lang3` in 
`hadoop-client-runtime/target/bom.xml`. The embedded copy is a rewritten 
derivative (relocated to `org.apache.hadoop.shaded`), so the component carries 
no hash of its own; the SHA-256 of the original standalone artifact sits on the 
pedigree ancestor, which deliberately shares the component's PURL so 
vulnerability scanners can still match it:
   
   ```xml
   <component type="library" 
bom-ref="pkg:maven/org.apache.commons/[email protected]?type=jar">
     <publisher>The Apache Software Foundation</publisher>
     <group>org.apache.commons</group>
     <name>commons-lang3</name>
     <version>3.20.0</version>
     <scope>optional</scope>
     <licenses>
       <license>
         <id>Apache-2.0</id>
         <url>https://www.apache.org/licenses/LICENSE-2.0</url>
       </license>
     </licenses>
     <purl>pkg:maven/org.apache.commons/[email protected]?type=jar</purl>
     <pedigree>
       <ancestors>
         <component type="library">
           <group>org.apache.commons</group>
           <name>commons-lang3</name>
           <version>3.20.0</version>
           <hashes>
             <hash 
alg="SHA-256">69e5c9fa35da7a51a5fd2099dfe56a2d8d32cf233e2f6d770e796146440263f4</hash>
           </hashes>
           
<purl>pkg:maven/org.apache.commons/[email protected]?type=jar</purl>
         </component>
       </ancestors>
       <notes>Relocated and embedded into this artifact by maven-shade-plugin; 
the ancestor component describes the original standalone artifact.</notes>
     </pedigree>
   </component>
   ```


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to