Repository navigation
Conversation
This adds support for Red Hat-flavored, CycloneDX JSON format SBoMs. Signed-off-by: Hank Donnay <hdonnay@redhat.com> Change-Id: I58d33321bf572021e436b9289ee5b0d16a6a6964
This shouldn't matter for correctly written tests. However, poorly written tests will require follow-up fixes. Signed-off-by: Hank Donnay <hdonnay@redhat.com> Change-Id: Ic89dfd66113bd99bf0f65b53df7df1b46a6a6964
This returns SHA256 and SHA1 digests for embedded jars. Signed-off-by: Hank Donnay <hdonnay@redhat.com> Change-Id: Icdd64e6f259ef9eab34b47ac9e5936516a6a6964
This calls into the `java/bom` package when an appropriate file is found. Signed-off-by: Hank Donnay <hdonnay@redhat.com> Change-Id: If6e96e723e5735ed5acbfcbaf9d0d0056a6a6964
crozzy
force-pushed
the
cyclone-dx-java
branch
from
October 9, 2026 18:20
369313b to
ef243e7
Compare
crozzy
commented
Oct 9, 2026
| for _, pkg := range l.Pkgs { | ||
| ir.Packages[pkg.ID] = pkg | ||
| rs := mavenIDs | ||
| if strings.HasPrefix(pkg.PackageDB, "sbom:") { |
Contributor
Author
There was a problem hiding this comment.
This check is here because things can exist in the SBOM file and not have associated CPEs, without this check they would be assigned the Maven Central repository and be available for OSV matching (which is undesirable).
crozzy
commented
Oct 9, 2026
crozzy
force-pushed
the
cyclone-dx-java
branch
from
October 9, 2026 21:39
ef243e7 to
e58f384
Compare
This change has the fs walk discover and use SBoM files. As long as they're earlier in the walk (this should always be the case), the entries there will be authoritative to the claircore examination. This also shook loose bugs in the `Package` object creation that would result in incorrect digests and file paths. Signed-off-by: Hank Donnay <hdonnay@redhat.com> Change-Id: I70b2e9dcebbfc92b82cb354463b700c76a6a6964
SBOM packages were indexed with the Maven Central repository, which is what selects the OSV Java matcher. Attach them to the product CPE repository instead, and leave that Maven Central repository on packages found by scanning jars. Signed-off-by: crozzy <joseph.crosland@gmail.com>
SBOM packages are associated with a redhat-java-cpe-repository during coalescing, but nothing recorded those repositories. Detect one repository per product CPE in a layer SBOM or an embedded jar SBOM. Signed-off-by: crozzy <joseph.crosland@gmail.com>
SBOM components were stored under the purl artifact name. The rest of the Java indexer uses group:artifact, which is the purl namespace and name. Signed-off-by: crozzy <joseph.crosland@gmail.com>
PackageDB depends on whether a jar entry came from a CycloneDX document, pom.properties, a manifest, or the archive name. Store that producer on Info and select the prefix from it. Maven Central is consulted only for a manifest or a filename, so a search hit cannot replace a document or pom.properties. Signed-off-by: crozzy <joseph.crosland@gmail.com>
A Quarkus document has no CPE on the root component. Product identity is a scope-excluded framework, and provides lists say which Maven purls belong to that product. Record every such CPE so the package can be matched against each product repository. Signed-off-by: crozzy <joseph.crosland@gmail.com>
The scanner drops a jar when a layer CycloneDX document already records its path or digest. An SBOM embedded in a jar does not cover jars outside that archive. Signed-off-by: crozzy <joseph.crosland@gmail.com>
crozzy
force-pushed
the
cyclone-dx-java
branch
from
October 9, 2026 21:45
e58f384 to
31fe1f2
Compare
crozzy
commented
Oct 9, 2026
Contributor
Author
There was a problem hiding this comment.
In 2 minds about checking this file in but due to the lack legit testing fixtures I erred on the side of including it.
crozzy
marked this pull request as ready for review
October 9, 2026 22:17
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TODO author review