[
https://issues.apache.org/jira/browse/HADOOP-19974?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18110290#comment-18110290
]
ASF GitHub Bot commented on HADOOP-19974:
-----------------------------------------
ppkarwasz commented on code in PR #8707:
URL: https://github.com/apache/hadoop/pull/8707#discussion_r3904542045
##########
pom.xml:
##########
@@ -866,6 +885,27 @@ xsi:schemaLocation="http://maven.apache.org/POM/4.0.0
https://maven.apache.org/x
<outputFormat>xml</outputFormat>
</configuration>
</plugin>
+ <plugin>
+ <!
> Publish CycloneDX 1.7 SBOMs that distinguish shaded dependencies
> ----------------------------------------------------------------
>
> Key: HADOOP-19974
> URL: https://issues.apache.org/jira/browse/HADOOP-19974
> Project: Hadoop Common
> Issue Type: Improvement
> Components: build
> Reporter: Piotr Karwasz
> Priority: Minor
> Labels: pull-request-available
>
> Hadoop currently generates CycloneDX SBOMs only under the {{dist}} profile
> (see HADOOP-18590), in XML, at spec version 1.6.
> CycloneDX 1.7 introduces an {{isExternal}} attribute that makes it possible
> to distinguish dependencies shaded inside a JAR from those merely referenced
> on the classpath. This distinction is essential for vulnerability management:
> only the embedded copies actually ship with our artifacts.
> Relocated dependencies are technically derivative libraries, so they
> additionally receive a {{pedigree}} element pointing to the original
> artifact, including its SHA-256 checksum. Vulnerability management systems
> would not be able to match a new PURL minted for the relocated copy against
> vulnerability databases, and they do not yet consult the pedigree, so both
> the relocated copy and its ancestor deliberately share the PURL of the
> original. Dependencies embedded without relocation are verbatim copies of the
> original, so they keep the original's checksum and need no pedigree.
> Since {{cyclonedx-maven-plugin}} does not yet support {{maven-shade-plugin}}
> (see
> [CycloneDX/cyclonedx-maven-plugin#472|https://github.com/CycloneDX/cyclonedx-maven-plugin/issues/472]),
> this issue post-processes the generated BOM with a Groovy script
> ({{dev-support/sbom/sbom.groovy}}) in the same {{dist}} profile. The set of
> shaded dependencies is derived from the effective {{maven-shade-plugin}}
> configuration, so it cannot drift from the shade {{artifactSet}}, and the
> result is validated against the CycloneDX 1.7 schema.
> Out of scope for this issue (follow-ups): SBOMs for the binary distribution
> tarball, and correcting license metadata in the generated documents.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]