Skip to content

Cyclone dx java - indexing - #2052

Open
crozzy wants to merge 11 commits into
quay:mainfrom
crozzy:cyclone-dx-java
Open

crozzy wants to merge 11 commits into
quay:mainfrom
crozzy:cyclone-dx-java

Conversation

@crozzy

@crozzy crozzy commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

TODO author review

This adds support for Red Hat-flavored, CycloneDX JSON format SBoMs.

Signed-off-by: Hank Donnay <hdonnay@redhat.com>
Change-Id: I58d33321bf572021e436b9289ee5b0d16a6a6964
This shouldn't matter for correctly written tests. However, poorly
written tests will require follow-up fixes.

Signed-off-by: Hank Donnay <hdonnay@redhat.com>
Change-Id: Ic89dfd66113bd99bf0f65b53df7df1b46a6a6964
This returns SHA256 and SHA1 digests for embedded jars.

Signed-off-by: Hank Donnay <hdonnay@redhat.com>
Change-Id: Icdd64e6f259ef9eab34b47ac9e5936516a6a6964
This calls into the `java/bom` package when an appropriate file is
found.

Signed-off-by: Hank Donnay <hdonnay@redhat.com>
Change-Id: If6e96e723e5735ed5acbfcbaf9d0d0056a6a6964
Comment thread java/coalescer.go
for _, pkg := range l.Pkgs {
ir.Packages[pkg.ID] = pkg
rs := mavenIDs
if strings.HasPrefix(pkg.PackageDB, "sbom:") {

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This check is here because things can exist in the SBOM file and not have associated CPEs, without this check they would be assigned the Maven Central repository and be available for OSV matching (which is undesirable).

Comment thread java/packagescanner.go Outdated
hdonnay and others added 7 commits October 9, 2026 14:44
This change has the fs walk discover and use SBoM files. As long as
they're earlier in the walk (this should always be the case), the
entries there will be authoritative to the claircore examination.

This also shook loose bugs in the `Package` object creation that would
result in incorrect digests and file paths.

Signed-off-by: Hank Donnay <hdonnay@redhat.com>
Change-Id: I70b2e9dcebbfc92b82cb354463b700c76a6a6964
SBOM packages were indexed with the Maven Central repository, which is
what selects the OSV Java matcher. Attach them to the product CPE
repository instead, and leave that Maven Central repository on packages
found by scanning jars.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
SBOM packages are associated with a redhat-java-cpe-repository during
coalescing, but nothing recorded those repositories. Detect one
repository per product CPE in a layer SBOM or an embedded jar SBOM.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
SBOM components were stored under the purl artifact name. The rest of
the Java indexer uses group:artifact, which is the purl namespace and name.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
PackageDB depends on whether a jar entry came from a CycloneDX document,
pom.properties, a manifest, or the archive name. Store that producer on
Info and select the prefix from it. Maven Central is consulted only for
a manifest or a filename, so a search hit cannot replace a document or
pom.properties.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
A Quarkus document has no CPE on the root component. Product identity
is a scope-excluded framework, and provides lists say which Maven
purls belong to that product. Record every such CPE so the package
can be matched against each product repository.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
The scanner drops a jar when a layer CycloneDX document already records
its path or digest. An SBOM embedded in a jar does not cover jars
outside that archive.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
@crozzy crozzy changed the title Cyclone dx java Cyclone dx java - indexing Oct 9, 2026

@crozzy crozzy Oct 9, 2026 •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In 2 minds about checking this file in but due to the lack legit testing fixtures I erred on the side of including it.

@crozzy
crozzy marked this pull request as ready for review October 9, 2026 22:17
@crozzy
crozzy requested review from a team as code owners October 9, 2026 22:17
@crozzy
crozzy requested review from BradLugo, dcaravel, hdonnay and jvdm and removed request for hdonnay October 9, 2026 22:17

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants