ppkarwasz commented on code in PR #8707:
URL: https://github.com/apache/hadoop/pull/8707#discussion_r3904542045


##########
pom.xml:
##########
@@ -866,6 +885,27 @@ xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 
https://maven.apache.org/x
               <outputFormat>xml</outputFormat>
             </configuration>
           </plugin>
+          <plugin>
+            <!-- Post-processes the CycloneDX SBOM into a 1.7 document that
+                 marks dependencies shaded into the jar by maven-shade-plugin.
+                 See dev-support/sbom/sbom.groovy. -->
+            <groupId>org.codehaus.gmavenplus</groupId>
+            <artifactId>gmavenplus-plugin</artifactId>
+            <executions>
+              <execution>
+                <id>sbom-postprocess</id>
+                <phase>verify</phase>
+                <goals>
+                  <goal>execute</goal>
+                </goals>
+                <configuration>
+                  <scripts>
+                    
<script>${maven.multiModuleProjectDirectory}/dev-support/sbom/sbom.groovy</script>

Review Comment:
   This **will** happen upstream (CycloneDX/cyclonedx-maven-plugin#696), but we 
are uncertain about the details.
   
   Hadoop is **not** the project that contains the most shaded content, but is 
certainly most commonly used shaded dependency. Having one version of Hadoop 
release an SBOM with the wrong mechanism beats hundreds of projects populating 
Maven Central with imperfect SBOMs.
   
   This is a proposal on how to improve HADOOP's SBOM **now** (@steveloughran 
was talking about an alternative XSLT-based solution), so other projects can 
start experimenting consuming SBOMs for HADOOP's **libraries**.
   
   SBOMs for normal (non-shading) libraries are much less interesting and don't 
require reusing the upstream SBOM.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to