[ 
https://issues.apache.org/jira/browse/HADOOP-19974?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18109435#comment-18109435
 ] 

ASF GitHub Bot commented on HADOOP-19974:
-----------------------------------------

ppkarwasz commented on PR #8707:
URL: https://github.com/apache/hadoop/pull/8707#issuecomment-5462946957

   For reviewers, here are three real entries taken from the generated BOMs 
(`<description>` and `<externalReferences>` elided for brevity).
   
   **1. External dependency** — `commons-logging` in 
`hadoop-client-runtime/target/bom.xml`. It is on the shade `artifactSet` 
exclude list (left unshaded so downstream users can configure logging), so it 
gets an explicit `isExternal="true"` and keeps its hash:
   
   ```xml
   <component type="library" 
bom-ref="pkg:maven/commons-logging/[email protected]?type=jar" 
isExternal="true">
     <publisher>The Apache Software Foundation</publisher>
     <group>commons-logging</group>
     <name>commons-logging</name>
     <version>1.3.0</version>
     <scope>required</scope>
     <hashes>
       <hash 
alg="SHA-256">66d3c980470b99b0c511dad3dfc0ae7b265ec1fb144e96bc0253a8a175fd34d9</hash>
     </hashes>
     <licenses>
       <license>
         <id>Apache-2.0</id>
         <url>https://www.apache.org/licenses/LICENSE-2.0</url>
       </license>
     </licenses>
     <purl>pkg:maven/commons-logging/[email protected]?type=jar</purl>
   </component>
   ```
   
   **2. Non-relocated embedded dependency** — `httpclient5` in 
`hadoop-tos/target/bom.xml`. `hadoop-tos` shades without relocations, so the 
embedded classes are verbatim copies: the component omits `isExternal` (the 
schema default is `false`), keeps the original's hash, and carries a notes-only 
pedigree:
   
   ```xml
   <component type="library" 
bom-ref="pkg:maven/org.apache.httpcomponents.client5/[email protected]?type=jar">
     <publisher>The Apache Software Foundation</publisher>
     <group>org.apache.httpcomponents.client5</group>
     <name>httpclient5</name>
     <version>5.5</version>
     <scope>required</scope>
     <hashes>
       <hash 
alg="SHA-256">496b4b0e8d5f3a8139a5d2638486d304758bac3a9c39d76989f663cfd9354fc9</hash>
     </hashes>
     <licenses>
       <license>
         <id>Apache-2.0</id>
       </license>
     </licenses>
     
<purl>pkg:maven/org.apache.httpcomponents.client5/[email protected]?type=jar</purl>
     <pedigree>
       <notes>Embedded verbatim into this artifact by maven-shade-plugin, 
without package relocation; the hashes describe the original standalone 
artifact.</notes>
     </pedigree>
   </component>
   ```
   
   **3. Relocated embedded dependency** — `commons-lang3` in 
`hadoop-client-runtime/target/bom.xml`. The embedded copy is a rewritten 
derivative (relocated to `org.apache.hadoop.shaded`), so the component carries 
no hash of its own; the SHA-256 of the original standalone artifact sits on the 
pedigree ancestor, which deliberately shares the component's PURL so 
vulnerability scanners can still match it:
   
   ```xml
   <component type="library" 
bom-ref="pkg:maven/org.apache.commons/[email protected]?type=jar">
     <publisher>The Apache Software Foundation</publisher>
     <group>org.apache.commons</group>
     <name>commons-lang3</name>
     <version>3.20.0</version>
     <scope>optional</scope>
     <licenses>
       <license>
         <id>Apache-2.0</id>
         <url>https://www.apache.org/licenses/LICENSE-2.0</url>
       </license>
     </licenses>
     <purl>pkg:maven/org.apache.commons/[email protected]?type=jar</purl>
     <pedigree>
       <ancestors>
         <component type="library">
           <group>org.apache.commons</group>
           <name>commons-lang3</name>
           <version>3.20.0</version>
           <hashes>
             <hash 
alg="SHA-256">69e5c9fa35da7a51a5fd2099dfe56a2d8d32cf233e2f6d770e796146440263f4</hash>
           </hashes>
           
<purl>pkg:maven/org.apache.commons/[email protected]?type=jar</purl>
         </component>
       </ancestors>
       <notes>Relocated and embedded into this artifact by maven-shade-plugin; 
the ancestor component describes the original standalone artifact.</notes>
     </pedigree>
   </component>
   ```




> Publish CycloneDX 1.7 SBOMs that distinguish shaded dependencies
> ----------------------------------------------------------------
>
>                 Key: HADOOP-19974
>                 URL: https://issues.apache.org/jira/browse/HADOOP-19974
>             Project: Hadoop Common
>          Issue Type: Improvement
>          Components: build
>            Reporter: Piotr Karwasz
>            Priority: Minor
>              Labels: pull-request-available
>
> Hadoop currently generates CycloneDX SBOMs only under the {{dist}} profile 
> (see HADOOP-18590), in XML, at spec version 1.6.
> CycloneDX 1.7 introduces an {{isExternal}} attribute that makes it possible 
> to distinguish dependencies shaded inside a JAR from those merely referenced 
> on the classpath. This distinction is essential for vulnerability management: 
> only the embedded copies actually ship with our artifacts.
> Relocated dependencies are technically derivative libraries, so they 
> additionally receive a {{pedigree}} element pointing to the original 
> artifact, including its SHA-256 checksum. Vulnerability management systems 
> would not be able to match a new PURL minted for the relocated copy against 
> vulnerability databases, and they do not yet consult the pedigree, so both 
> the relocated copy and its ancestor deliberately share the PURL of the 
> original. Dependencies embedded without relocation are verbatim copies of the 
> original, so they keep the original's checksum and need no pedigree.
> Since {{cyclonedx-maven-plugin}} does not yet support {{maven-shade-plugin}} 
> (see 
> [CycloneDX/cyclonedx-maven-plugin#472|https://github.com/CycloneDX/cyclonedx-maven-plugin/issues/472]),
>  this issue post-processes the generated BOM with a Groovy script 
> ({{dev-support/sbom/sbom.groovy}}) in the same {{dist}} profile. The set of 
> shaded dependencies is derived from the effective {{maven-shade-plugin}} 
> configuration, so it cannot drift from the shade {{artifactSet}}, and the 
> result is validated against the CycloneDX 1.7 schema.
> Out of scope for this issue (follow-ups): SBOMs for the binary distribution 
> tarball, and correcting license metadata in the generated documents.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to