[
https://issues.apache.org/jira/browse/HADOOP-19974?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18109435#comment-18109435
]
ASF GitHub Bot commented on HADOOP-19974:
-----------------------------------------
ppkarwasz commented on PR #8707:
URL: https://github.com/apache/hadoop/pull/8707#issuecomment-5462946957
For reviewers, here are three real entries taken from the generated BOMs
(`<description>` and `<externalReferences>` elided for brevity).
**1. External dependency** — `commons-logging` in
`hadoop-client-runtime/target/bom.xml`. It is on the shade `artifactSet`
exclude list (left unshaded so downstream users can configure logging), so it
gets an explicit `isExternal="true"` and keeps its hash:
```xml
<component type="library"
bom-ref="pkg:maven/commons-logging/[email protected]?type=jar"
isExternal="true">
<publisher>The Apache Software Foundation</publisher>
<group>commons-logging</group>
<name>commons-logging</name>
<version>1.3.0</version>
<scope>required</scope>
<hashes>
<hash
alg="SHA-256">66d3c980470b99b0c511dad3dfc0ae7b265ec1fb144e96bc0253a8a175fd34d9</hash>
</hashes>
<licenses>
<license>
<id>Apache-2.0</id>
<url>https://www.apache.org/licenses/LICENSE-2.0</url>
</license>
</licenses>
<purl>pkg:maven/commons-logging/[email protected]?type=jar</purl>
</component>
```
**2. Non-relocated embedded dependency** — `httpclient5` in
`hadoop-tos/target/bom.xml`. `hadoop-tos` shades without relocations, so the
embedded classes are verbatim copies: the component omits `isExternal` (the
schema default is `false`), keeps the original's hash, and carries a notes-only
pedigree:
```xml
<component type="library"
bom-ref="pkg:maven/org.apache.httpcomponents.client5/[email protected]?type=jar">
<publisher>The Apache Software Foundation</publisher>
<group>org.apache.httpcomponents.client5</group>
<name>httpclient5</name>
<version>5.5</version>
<scope>required</scope>
<hashes>
<hash
alg="SHA-256">496b4b0e8d5f3a8139a5d2638486d304758bac3a9c39d76989f663cfd9354fc9</hash>
</hashes>
<licenses>
<license>
<id>Apache-2.0</id>
</license>
</licenses>
<purl>pkg:maven/org.apache.httpcomponents.client5/[email protected]?type=jar</purl>
<pedigree>
<notes>Embedded verbatim into this artifact by maven-shade-plugin,
without package relocation; the hashes describe the original standalone
artifact.</notes>
</pedigree>
</component>
```
**3. Relocated embedded dependency** — `commons-lang3` in
`hadoop-client-runtime/target/bom.xml`. The embedded copy is a rewritten
derivative (relocated to `org.apache.hadoop.shaded`), so the component carries
no hash of its own; the SHA-256 of the original standalone artifact sits on the
pedigree ancestor, which deliberately shares the component's PURL so
vulnerability scanners can still match it:
```xml
<component type="library"
bom-ref="pkg:maven/org.apache.commons/[email protected]?type=jar">
<publisher>The Apache Software Foundation</publisher>
<group>org.apache.commons</group>
<name>commons-lang3</name>
<version>3.20.0</version>
<scope>optional</scope>
<licenses>
<license>
<id>Apache-2.0</id>
<url>https://www.apache.org/licenses/LICENSE-2.0</url>
</license>
</licenses>
<purl>pkg:maven/org.apache.commons/[email protected]?type=jar</purl>
<pedigree>
<ancestors>
<component type="library">
<group>org.apache.commons</group>
<name>commons-lang3</name>
<version>3.20.0</version>
<hashes>
<hash
alg="SHA-256">69e5c9fa35da7a51a5fd2099dfe56a2d8d32cf233e2f6d770e796146440263f4</hash>
</hashes>
<purl>pkg:maven/org.apache.commons/[email protected]?type=jar</purl>
</component>
</ancestors>
<notes>Relocated and embedded into this artifact by maven-shade-plugin;
the ancestor component describes the original standalone artifact.</notes>
</pedigree>
</component>
```
> Publish CycloneDX 1.7 SBOMs that distinguish shaded dependencies
> ----------------------------------------------------------------
>
> Key: HADOOP-19974
> URL: https://issues.apache.org/jira/browse/HADOOP-19974
> Project: Hadoop Common
> Issue Type: Improvement
> Components: build
> Reporter: Piotr Karwasz
> Priority: Minor
> Labels: pull-request-available
>
> Hadoop currently generates CycloneDX SBOMs only under the {{dist}} profile
> (see HADOOP-18590), in XML, at spec version 1.6.
> CycloneDX 1.7 introduces an {{isExternal}} attribute that makes it possible
> to distinguish dependencies shaded inside a JAR from those merely referenced
> on the classpath. This distinction is essential for vulnerability management:
> only the embedded copies actually ship with our artifacts.
> Relocated dependencies are technically derivative libraries, so they
> additionally receive a {{pedigree}} element pointing to the original
> artifact, including its SHA-256 checksum. Vulnerability management systems
> would not be able to match a new PURL minted for the relocated copy against
> vulnerability databases, and they do not yet consult the pedigree, so both
> the relocated copy and its ancestor deliberately share the PURL of the
> original. Dependencies embedded without relocation are verbatim copies of the
> original, so they keep the original's checksum and need no pedigree.
> Since {{cyclonedx-maven-plugin}} does not yet support {{maven-shade-plugin}}
> (see
> [CycloneDX/cyclonedx-maven-plugin#472|https://github.com/CycloneDX/cyclonedx-maven-plugin/issues/472]),
> this issue post-processes the generated BOM with a Groovy script
> ({{dev-support/sbom/sbom.groovy}}) in the same {{dist}} profile. The set of
> shaded dependencies is derived from the effective {{maven-shade-plugin}}
> configuration, so it cannot drift from the shade {{artifactSet}}, and the
> result is validated against the CycloneDX 1.7 schema.
> Out of scope for this issue (follow-ups): SBOMs for the binary distribution
> tarball, and correcting license metadata in the generated documents.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]