Repository navigation
Conversation
crozzy
force-pushed
the
cyclone-dx-java-match
branch
from
October 9, 2026 15:01
3e12600 to
bcc3471
Compare
This adds support for Red Hat-flavored, CycloneDX JSON format SBoMs. Signed-off-by: Hank Donnay <hdonnay@redhat.com> Change-Id: I58d33321bf572021e436b9289ee5b0d16a6a6964
This shouldn't matter for correctly written tests. However, poorly written tests will require follow-up fixes. Signed-off-by: Hank Donnay <hdonnay@redhat.com> Change-Id: Ic89dfd66113bd99bf0f65b53df7df1b46a6a6964
This returns SHA256 and SHA1 digests for embedded jars. Signed-off-by: Hank Donnay <hdonnay@redhat.com> Change-Id: Icdd64e6f259ef9eab34b47ac9e5936516a6a6964
This calls into the `java/bom` package when an appropriate file is found. Signed-off-by: Hank Donnay <hdonnay@redhat.com> Change-Id: If6e96e723e5735ed5acbfcbaf9d0d0056a6a6964
crozzy
force-pushed
the
cyclone-dx-java-match
branch
2 times, most recently
from
October 9, 2026 21:39
73bb550 to
8be49b9
Compare
This change has the fs walk discover and use SBoM files. As long as they're earlier in the walk (this should always be the case), the entries there will be authoritative to the claircore examination. This also shook loose bugs in the `Package` object creation that would result in incorrect digests and file paths. Signed-off-by: Hank Donnay <hdonnay@redhat.com> Change-Id: I70b2e9dcebbfc92b82cb354463b700c76a6a6964
SBOM packages were indexed with the Maven Central repository, which is what selects the OSV Java matcher. Attach them to the product CPE repository instead, and leave that Maven Central repository on packages found by scanning jars. Signed-off-by: crozzy <joseph.crosland@gmail.com>
SBOM packages are associated with a redhat-java-cpe-repository during coalescing, but nothing recorded those repositories. Detect one repository per product CPE in a layer SBOM or an embedded jar SBOM. Signed-off-by: crozzy <joseph.crosland@gmail.com>
SBOM components were stored under the purl artifact name. The rest of the Java indexer uses group:artifact, which is the purl namespace and name. Signed-off-by: crozzy <joseph.crosland@gmail.com>
PackageDB depends on whether a jar entry came from a CycloneDX document, pom.properties, a manifest, or the archive name. Store that producer on Info and select the prefix from it. Maven Central is consulted only for a manifest or a filename, so a search hit cannot replace a document or pom.properties. Signed-off-by: crozzy <joseph.crosland@gmail.com>
A Quarkus document has no CPE on the root component. Product identity is a scope-excluded framework, and provides lists say which Maven purls belong to that product. Record every such CPE so the package can be matched against each product repository. Signed-off-by: crozzy <joseph.crosland@gmail.com>
The scanner drops a jar when a layer CycloneDX document already records its path or digest. An SBOM embedded in a jar does not cover jars outside that archive. Signed-off-by: crozzy <joseph.crosland@gmail.com>
RepositoryKey is the key for a Red Hat product CPE attributed to a Java component. Signed-off-by: crozzy <joseph.crosland@gmail.com>
pkg:maven rows are now accepted. The package name is namespace:name, ignoring repository_url and type. FixedInVersion is the PURL version for a fixed row. Maven known_not_affected rows are skipped, and a versioned known_affected Maven PURL is not ingested. TODO: resolve what a version on a known_affected Maven PURL means. TODO: move the feed URL back to the production vex-feed once Maven data is published there. Signed-off-by: crozzy <joseph.crosland@gmail.com>
The matcher selects redhat-java-cpe-repository records. It applies the RHEL CPE check, then compares Maven versions: an installed package is vulnerable when it is strictly older than FixedInVersion, and an empty FixedInVersion matches any installed version. Signed-off-by: crozzy <joseph.crosland@gmail.com>
crozzy
force-pushed
the
cyclone-dx-java-match
branch
from
October 9, 2026 21:45
8be49b9 to
ee6f9ff
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.