dongjoon-hyun opened a new pull request, #1969: URL: https://github.com/apache/zookeeper/pull/1969
This PR aims to publish SBOM artifacts along with the other Apache projects. - https://cwiki.apache.org/confluence/display/COMDEV/SBOM Here is an article to give some context. - https://www.activestate.com/blog/why-the-us-government-is-mandating-software-bill-of-materials-sbom/ Software Bill of Materials (SBOM) are additional artifacts containing the aggregate of all direct and transitive dependencies of a project. The US Government (based on NIST recommendations) currently accepts only the three most popular SBOM standards as valid, namely: [CycloneDX](https://cyclonedx.org/), [Software Identification (SWID) tag](https://csrc.nist.gov/projects/Software-Identification-SWID), [Software Package Data Exchange® (SPDX)](https://spdx.dev/). We can use one of the Maven plugin, [CycloneDX maven plugin](https://github.com/CycloneDX/cyclonedx-maven-plugin), a lightweight software bill of materials (SBOM) standard designed for use in application security contexts and supply chain component analysis. https://maven.apache.org/plugins/index.html#misc **The expected results** ``` $ mvn install -DskipTests ... $ ls -al ~/.m2/repository/org/apache/zookeeper/zookeeper/3.9.0-SNAPSHOT/ total 16768 drwxr-xr-x 12 dongjoon staff 384 Jan 10 14:59 . drwxr-xr-x 8 dongjoon staff 256 Jan 10 14:59 .. -rw-r--r-- 1 dongjoon staff 436 Jan 10 14:59 _remote.repositories -rw-r--r-- 1 dongjoon staff 1945 Jan 10 14:59 maven-metadata-local.xml -rw-r--r-- 1 dongjoon staff 70780 Jan 10 14:59 zookeeper-3.9.0-SNAPSHOT-cyclonedx.json -rw-r--r-- 1 dongjoon staff 61959 Jan 10 14:59 zookeeper-3.9.0-SNAPSHOT-cyclonedx.xml -rw-r--r-- 1 dongjoon staff 3291660 Jan 10 14:59 zookeeper-3.9.0-SNAPSHOT-javadoc.jar -rw-r--r-- 1 dongjoon staff 1365393 Jan 10 14:59 zookeeper-3.9.0-SNAPSHOT-osgi.jar -rw-r--r-- 1 dongjoon staff 883895 Jan 10 14:59 zookeeper-3.9.0-SNAPSHOT-sources.jar -rw-r--r-- 1 dongjoon staff 1533401 Jan 10 14:59 zookeeper-3.9.0-SNAPSHOT-tests.jar -rw-r--r-- 1 dongjoon staff 1341057 Jan 10 14:59 zookeeper-3.9.0-SNAPSHOT.jar -rw-r--r-- 1 dongjoon staff 11456 Jan 10 14:55 zookeeper-3.9.0-SNAPSHOT.pom ``` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
