Skip to content

chore: Generate SBOM files with CycloneDX and SPDX maven plugins - #2893

Merged
lprimak merged 2 commits into
apache:mainfrom
lprimak:add-sbom-generation
Sep 19, 2026
Merged

lprimak merged 2 commits into
apache:mainfrom
lprimak:add-sbom-generation

Conversation

@lprimak

@lprimak lprimak commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Following this checklist to help us incorporate your contribution quickly and easily:

  • Make sure there is a GitHub issue filed
    for the change (usually before you start working on it). Trivial changes like typos do not
    require a GitHub issue. Your pull request should address just this issue, without pulling in other changes.
  • Format the pull request title like [#XXX] - Fixes bug in SessionManager,
    where you replace #XXX with the appropriate GitHub issue. Best practice
    is to use the GitHub issue title in the pull request title and in the first line of the commit message.
  • Write a pull request description that is detailed enough to understand what the pull request does, how, and why.
  • add fixes #XXX if merging the PR should close a related issue.
  • Run mvn verify to make sure basic checks pass. A more thorough check will be performed on your pull request automatically.
  • Committers: Make sure a milestone is set on the PR
  • Committers: Use "Squash and Merge" to combine all commits into one when merging a PR when appropriate.

Trivial changes like typos do not require a GitHub issue (javadoc, comments...).
In this case, just format the pull request title like [DOC] - Add javadoc in SessionManager.

If this is your first contribution, you have to read the Contribution Guidelines

If your pull request is about ~20 lines of code you don't need to sign an Individual Contributor License Agreement
if you are unsure please ask on the developers list.

To make clear that you license your contribution under the Apache License Version 2.0, January 2004
you have to acknowledge this by using the following check-box.

@steinarb steinarb left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(I guess this was explained when I was curious about where the BOM went.

But from googling the concepts I see that both CycloneDN and SPDX are stuff I should look into privately...?)

Anyway: LGTM

@lprimak

lprimak commented Sep 19, 2026

Copy link
Copy Markdown
Contributor Author

Thanks Steinar.
SBOM files are part of the EU CRA requirements and can help figure out the vulnerabilities of the software.

Sounds similar to maven BOM but they are not. Maven BOM is no longer necessary in 3.x because it was only used for Jakarta classifier which is no longer used in 3.x

@lprimak
lprimak merged commit bd3ecdd into apache:main Sep 19, 2026
19 checks passed
@lprimak
lprimak deleted the add-sbom-generation branch September 19, 2026 18:46
@steinarb

steinarb commented Sep 20, 2026 via email

Copy link
Copy Markdown
Contributor

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants