Skip to content

Cyclone dx java - matching - #2057

Draft
crozzy wants to merge 14 commits into
quay:mainfrom
crozzy:cyclone-dx-java-match
Draft

crozzy wants to merge 14 commits into
quay:mainfrom
crozzy:cyclone-dx-java-match

Conversation

@crozzy

@crozzy crozzy commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@crozzy
crozzy force-pushed the cyclone-dx-java-match branch from 3e12600 to bcc3471 Compare October 9, 2026 15:01
This adds support for Red Hat-flavored, CycloneDX JSON format SBoMs.

Signed-off-by: Hank Donnay <hdonnay@redhat.com>
Change-Id: I58d33321bf572021e436b9289ee5b0d16a6a6964
This shouldn't matter for correctly written tests. However, poorly
written tests will require follow-up fixes.

Signed-off-by: Hank Donnay <hdonnay@redhat.com>
Change-Id: Ic89dfd66113bd99bf0f65b53df7df1b46a6a6964
This returns SHA256 and SHA1 digests for embedded jars.

Signed-off-by: Hank Donnay <hdonnay@redhat.com>
Change-Id: Icdd64e6f259ef9eab34b47ac9e5936516a6a6964
This calls into the `java/bom` package when an appropriate file is
found.

Signed-off-by: Hank Donnay <hdonnay@redhat.com>
Change-Id: If6e96e723e5735ed5acbfcbaf9d0d0056a6a6964
@crozzy
crozzy force-pushed the cyclone-dx-java-match branch 2 times, most recently from 73bb550 to 8be49b9 Compare October 9, 2026 21:39
hdonnay and others added 10 commits October 9, 2026 14:44
This change has the fs walk discover and use SBoM files. As long as
they're earlier in the walk (this should always be the case), the
entries there will be authoritative to the claircore examination.

This also shook loose bugs in the `Package` object creation that would
result in incorrect digests and file paths.

Signed-off-by: Hank Donnay <hdonnay@redhat.com>
Change-Id: I70b2e9dcebbfc92b82cb354463b700c76a6a6964
SBOM packages were indexed with the Maven Central repository, which is
what selects the OSV Java matcher. Attach them to the product CPE
repository instead, and leave that Maven Central repository on packages
found by scanning jars.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
SBOM packages are associated with a redhat-java-cpe-repository during
coalescing, but nothing recorded those repositories. Detect one
repository per product CPE in a layer SBOM or an embedded jar SBOM.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
SBOM components were stored under the purl artifact name. The rest of
the Java indexer uses group:artifact, which is the purl namespace and name.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
PackageDB depends on whether a jar entry came from a CycloneDX document,
pom.properties, a manifest, or the archive name. Store that producer on
Info and select the prefix from it. Maven Central is consulted only for
a manifest or a filename, so a search hit cannot replace a document or
pom.properties.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
A Quarkus document has no CPE on the root component. Product identity
is a scope-excluded framework, and provides lists say which Maven
purls belong to that product. Record every such CPE so the package
can be matched against each product repository.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
The scanner drops a jar when a layer CycloneDX document already records
its path or digest. An SBOM embedded in a jar does not cover jars
outside that archive.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
RepositoryKey is the key for a Red Hat product CPE attributed to a Java component.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
pkg:maven rows are now accepted. The package name is namespace:name,
ignoring repository_url and type. FixedInVersion is the PURL version
for a fixed row. Maven known_not_affected rows are skipped, and a
versioned known_affected Maven PURL is not ingested.

TODO: resolve what a version on a known_affected Maven PURL means.
TODO: move the feed URL back to the production vex-feed once Maven data is published there.
Signed-off-by: crozzy <joseph.crosland@gmail.com>
The matcher selects redhat-java-cpe-repository records. It applies the
RHEL CPE check, then compares Maven versions: an installed package is
vulnerable when it is strictly older than FixedInVersion, and an empty
FixedInVersion matches any installed version.

Signed-off-by: crozzy <joseph.crosland@gmail.com>
@crozzy
crozzy force-pushed the cyclone-dx-java-match branch from 8be49b9 to ee6f9ff Compare October 9, 2026 21:45
@crozzy crozzy changed the title Cyclone dx java match Cyclone dx java - matching Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants