Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add serialNumber and VEX references to generate SBOMs #56

Merged
merged 2 commits into from
Nov 6, 2023

Conversation

ppkarwasz
Copy link
Contributor

The cyclonedx-maven-plugin has still some limitations that prevent it from publishing a reproducible serialNumber
(CycloneDX/cyclonedx-maven-plugin#420) and adding a reference to a VEX document (CycloneDX/cyclonedx-maven-plugin#419 and CycloneDX/cyclonedx-maven-plugin#421).

This PR provides a temporary workaround that will allow us to produce an CycloneDX (only the XML version), enhanced with these two elements.

The proposed URL for the VDR file is compatible with the CycloneDX/transparency-exchange-api#12 modification to the CycloneDX BOM Exchange API Standard.

This is part of the apache/logging-log4j2#1707 effort.

The `cyclonedx-maven-plugin` has still some limitations that prevent it
from publishing a reproducible `serialNumber`
(CycloneDX/cyclonedx-maven-plugin#420) and adding a reference to a VEX
document (CycloneDX/cyclonedx-maven-plugin#419 and
CycloneDX/cyclonedx-maven-plugin#421).

This PR provides a temporary workaround that will allow us to produce an
CycloneDX (only the XML version), enhanced with these two elements.
@vy vy merged commit 954f7f2 into apache:main Nov 6, 2023
5 checks passed
@vy vy added the enhancement label Nov 6, 2023
@vy vy added this to the 10.3.0 milestone Nov 6, 2023
@ppkarwasz ppkarwasz deleted the sbom-transform branch November 6, 2023 09:20
vy added a commit that referenced this pull request Nov 6, 2023
* Add `serialNumber` and VEX references to generate SBOMs

The `cyclonedx-maven-plugin` has still some limitations that prevent it
from publishing a reproducible `serialNumber`
(CycloneDX/cyclonedx-maven-plugin#420) and adding a reference to a VEX
document (CycloneDX/cyclonedx-maven-plugin#419 and
CycloneDX/cyclonedx-maven-plugin#421).

This PR provides a temporary workaround that will allow us to produce an
CycloneDX (only the XML version), enhanced with these two elements.

---------

Co-authored-by: Volkan Yazıcı <volkan@yazi.ci>
vy added a commit that referenced this pull request Nov 6, 2023
vy added a commit that referenced this pull request Nov 6, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants