ppkarwasz commented on code in PR #8707: URL: https://github.com/apache/hadoop/pull/8707#discussion_r3904542045
########## pom.xml: ########## @@ -866,6 +885,27 @@ xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/x <outputFormat>xml</outputFormat> </configuration> </plugin> + <plugin> + <!-- Post-processes the CycloneDX SBOM into a 1.7 document that + marks dependencies shaded into the jar by maven-shade-plugin. + See dev-support/sbom/sbom.groovy. --> + <groupId>org.codehaus.gmavenplus</groupId> + <artifactId>gmavenplus-plugin</artifactId> + <executions> + <execution> + <id>sbom-postprocess</id> + <phase>verify</phase> + <goals> + <goal>execute</goal> + </goals> + <configuration> + <scripts> + <script>${maven.multiModuleProjectDirectory}/dev-support/sbom/sbom.groovy</script> Review Comment: This **will** happen upstream (CycloneDX/cyclonedx-maven-plugin#696), but we are uncertain about the details. Hadoop is **not** the project that contains the most shaded content, but is certainly most commonly used shaded dependency. Having one version of Hadoop release an SBOM with the wrong mechanism beats hundreds of projects populating Maven Central with imperfect SBOMs. This is a proposal on how to improve HADOOP's SBOM **now** (@steveloughran was talking about an alternative XSLT-based solution), so other projects can start experimenting consuming SBOMs for HADOOP's **libraries**. SBOMs for normal (non-shading) libraries are much less interesting and don't require reusing the upstream SBOM. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
