ppkarwasz commented on PR #8707: URL: https://github.com/apache/hadoop/pull/8707#issuecomment-5462946957
For reviewers, here are three real entries taken from the generated BOMs (`<description>` and `<externalReferences>` elided for brevity). **1. External dependency** — `commons-logging` in `hadoop-client-runtime/target/bom.xml`. It is on the shade `artifactSet` exclude list (left unshaded so downstream users can configure logging), so it gets an explicit `isExternal="true"` and keeps its hash: ```xml <component type="library" bom-ref="pkg:maven/commons-logging/[email protected]?type=jar" isExternal="true"> <publisher>The Apache Software Foundation</publisher> <group>commons-logging</group> <name>commons-logging</name> <version>1.3.0</version> <scope>required</scope> <hashes> <hash alg="SHA-256">66d3c980470b99b0c511dad3dfc0ae7b265ec1fb144e96bc0253a8a175fd34d9</hash> </hashes> <licenses> <license> <id>Apache-2.0</id> <url>https://www.apache.org/licenses/LICENSE-2.0</url> </license> </licenses> <purl>pkg:maven/commons-logging/[email protected]?type=jar</purl> </component> ``` **2. Non-relocated embedded dependency** — `httpclient5` in `hadoop-tos/target/bom.xml`. `hadoop-tos` shades without relocations, so the embedded classes are verbatim copies: the component omits `isExternal` (the schema default is `false`), keeps the original's hash, and carries a notes-only pedigree: ```xml <component type="library" bom-ref="pkg:maven/org.apache.httpcomponents.client5/[email protected]?type=jar"> <publisher>The Apache Software Foundation</publisher> <group>org.apache.httpcomponents.client5</group> <name>httpclient5</name> <version>5.5</version> <scope>required</scope> <hashes> <hash alg="SHA-256">496b4b0e8d5f3a8139a5d2638486d304758bac3a9c39d76989f663cfd9354fc9</hash> </hashes> <licenses> <license> <id>Apache-2.0</id> </license> </licenses> <purl>pkg:maven/org.apache.httpcomponents.client5/[email protected]?type=jar</purl> <pedigree> <notes>Embedded verbatim into this artifact by maven-shade-plugin, without package relocation; the hashes describe the original standalone artifact.</notes> </pedigree> </component> ``` **3. Relocated embedded dependency** — `commons-lang3` in `hadoop-client-runtime/target/bom.xml`. The embedded copy is a rewritten derivative (relocated to `org.apache.hadoop.shaded`), so the component carries no hash of its own; the SHA-256 of the original standalone artifact sits on the pedigree ancestor, which deliberately shares the component's PURL so vulnerability scanners can still match it: ```xml <component type="library" bom-ref="pkg:maven/org.apache.commons/[email protected]?type=jar"> <publisher>The Apache Software Foundation</publisher> <group>org.apache.commons</group> <name>commons-lang3</name> <version>3.20.0</version> <scope>optional</scope> <licenses> <license> <id>Apache-2.0</id> <url>https://www.apache.org/licenses/LICENSE-2.0</url> </license> </licenses> <purl>pkg:maven/org.apache.commons/[email protected]?type=jar</purl> <pedigree> <ancestors> <component type="library"> <group>org.apache.commons</group> <name>commons-lang3</name> <version>3.20.0</version> <hashes> <hash alg="SHA-256">69e5c9fa35da7a51a5fd2099dfe56a2d8d32cf233e2f6d770e796146440263f4</hash> </hashes> <purl>pkg:maven/org.apache.commons/[email protected]?type=jar</purl> </component> </ancestors> <notes>Relocated and embedded into this artifact by maven-shade-plugin; the ancestor component describes the original standalone artifact.</notes> </pedigree> </component> ``` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
