dongjoon-hyun opened a new pull request, #1969:
URL: https://github.com/apache/zookeeper/pull/1969

   This PR aims to publish SBOM artifacts along with the other Apache projects.
   
   - https://cwiki.apache.org/confluence/display/COMDEV/SBOM
   
   Here is an article to give some context.
   - 
https://www.activestate.com/blog/why-the-us-government-is-mandating-software-bill-of-materials-sbom/
   
   Software Bill of Materials (SBOM) are additional artifacts containing the 
aggregate of all direct and transitive dependencies of a project. The US 
Government (based on NIST recommendations) currently accepts only the three 
most popular SBOM standards as valid, namely: 
[CycloneDX](https://cyclonedx.org/), [Software Identification (SWID) 
tag](https://csrc.nist.gov/projects/Software-Identification-SWID), [Software 
Package Data Exchange® (SPDX)](https://spdx.dev/).
   
   We can use one of the Maven plugin, [CycloneDX maven 
plugin](https://github.com/CycloneDX/cyclonedx-maven-plugin), a lightweight 
software bill of materials (SBOM) standard designed for use in application 
security contexts and supply chain component analysis.
   
   https://maven.apache.org/plugins/index.html#misc
   
   **The expected results**
   ```
   $ mvn install -DskipTests
   ...
   
   $ ls -al ~/.m2/repository/org/apache/zookeeper/zookeeper/3.9.0-SNAPSHOT/
   total 16768
   drwxr-xr-x  12 dongjoon  staff      384 Jan 10 14:59 .
   drwxr-xr-x   8 dongjoon  staff      256 Jan 10 14:59 ..
   -rw-r--r--   1 dongjoon  staff      436 Jan 10 14:59 _remote.repositories
   -rw-r--r--   1 dongjoon  staff     1945 Jan 10 14:59 maven-metadata-local.xml
   -rw-r--r--   1 dongjoon  staff    70780 Jan 10 14:59 
zookeeper-3.9.0-SNAPSHOT-cyclonedx.json
   -rw-r--r--   1 dongjoon  staff    61959 Jan 10 14:59 
zookeeper-3.9.0-SNAPSHOT-cyclonedx.xml
   -rw-r--r--   1 dongjoon  staff  3291660 Jan 10 14:59 
zookeeper-3.9.0-SNAPSHOT-javadoc.jar
   -rw-r--r--   1 dongjoon  staff  1365393 Jan 10 14:59 
zookeeper-3.9.0-SNAPSHOT-osgi.jar
   -rw-r--r--   1 dongjoon  staff   883895 Jan 10 14:59 
zookeeper-3.9.0-SNAPSHOT-sources.jar
   -rw-r--r--   1 dongjoon  staff  1533401 Jan 10 14:59 
zookeeper-3.9.0-SNAPSHOT-tests.jar
   -rw-r--r--   1 dongjoon  staff  1341057 Jan 10 14:59 
zookeeper-3.9.0-SNAPSHOT.jar
   -rw-r--r--   1 dongjoon  staff    11456 Jan 10 14:55 
zookeeper-3.9.0-SNAPSHOT.pom
   ```


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to