Merge pull request #51551 from COBI-98

Closes gh-51551

* gh-51551:
  Polish "Add SBOM manifest attributes to repackaged Maven wars"
  Add SBOM manifest attributes to repackaged Maven wars
This commit is contained in:
Andy Wilkinson
2026-09-09 15:31:48 +01:00
6 changed files with 100 additions and 5 deletions
@@ -67,6 +67,16 @@ class WarIntegrationTests extends AbstractArchiveIntegrationTests {
.hasAttribute("Not-Used", "Foo")));
}
@TestTemplate
void sbomManifestAttributesAreAddedToRepackagedWar(MavenBuild mavenBuild) {
mavenBuild.project("war-sbom").execute((project) -> {
File repackaged = new File(project, "target/war-sbom-0.0.1.BUILD-SNAPSHOT.war");
assertThat(jar(repackaged)).hasEntryWithName("WEB-INF/classes/META-INF/sbom/application.cdx.json")
.manifest((manifest) -> manifest.hasAttribute("Sbom-Format", "CycloneDX")
.hasAttribute("Sbom-Location", "WEB-INF/classes/META-INF/sbom/application.cdx.json"));
});
}
@TestTemplate
void jarDependencyWithCustomFinalNameBuiltInSameReactorIsPackagedUsingArtifactIdAndVersion(MavenBuild mavenBuild) {
mavenBuild.project("war-reactor")
@@ -0,0 +1,48 @@
<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<groupId>org.springframework.boot.maven.it</groupId>
<artifactId>war-sbom</artifactId>
<version>0.0.1.BUILD-SNAPSHOT</version>
<packaging>war</packaging>
<properties>
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
<maven.compiler.source>@java.version@</maven.compiler.source>
<maven.compiler.target>@java.version@</maven.compiler.target>
</properties>
<build>
<plugins>
<plugin>
<groupId>@project.groupId@</groupId>
<artifactId>@project.artifactId@</artifactId>
<version>@project.version@</version>
<executions>
<execution>
<goals>
<goal>repackage</goal>
</goals>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-war-plugin</artifactId>
<version>@maven-war-plugin.version@</version>
</plugin>
</plugins>
</build>
<dependencies>
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-context</artifactId>
<version>@spring-framework.version@</version>
</dependency>
<dependency>
<groupId>jakarta.servlet</groupId>
<artifactId>jakarta.servlet-api</artifactId>
<version>@jakarta-servlet.version@</version>
<scope>provided</scope>
</dependency>
</dependencies>
</project>
@@ -0,0 +1,24 @@
/*
* Copyright 2012-present the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* https://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.test;
public class SampleApplication {
public static void main(String[] args) {
}
}
@@ -55,6 +55,7 @@ import org.springframework.util.StringUtils;
* @author Stephane Nicoll
* @author Madhura Bhave
* @author Scott Frederick
* @author Cobi Eun
* @since 2.3.0
*/
public abstract class Packager {
@@ -422,7 +423,8 @@ public abstract class Packager {
}
private boolean isCycloneDxBom(JarEntry entry) {
if (!entry.getName().startsWith("META-INF/sbom/")) {
if (!entry.getName().startsWith("META-INF/sbom/")
&& !entry.getName().startsWith(getLayout().getClassesLocation() + "META-INF/sbom/")) {
return false;
}
return entry.getName().endsWith(".cdx.json") || entry.getName().endsWith("/bom.json");
@@ -687,16 +687,26 @@ abstract class AbstractPackagerTests<P extends Packager> {
}
@Test
void sbomManifestEntriesAreWritten() throws IOException {
this.testJarFile.addClass("com/example/Application.class", ClassWithMainMethod.class);
this.testJarFile.addFile("META-INF/sbom/application.cdx.json", new ByteArrayInputStream(new byte[0]));
void sbomManifestEntriesAreWrittenForJar() throws IOException {
sbomManifestEntriesAreWritten(new Layouts.Jar(), "");
}
@Test
void sbomManifestEntriesAreWrittenForWar() throws IOException {
sbomManifestEntriesAreWritten(new Layouts.War(), "WEB-INF/classes/");
}
private void sbomManifestEntriesAreWritten(Layout layout, String prefix) throws IOException {
this.testJarFile.addClass(prefix + "com/example/Application.class", ClassWithMainMethod.class);
this.testJarFile.addFile(prefix + "META-INF/sbom/application.cdx.json", new ByteArrayInputStream(new byte[0]));
P packager = createPackager(this.testJarFile.getFile());
packager.setLayout(layout);
execute(packager, NO_LIBRARIES);
Manifest manifest = getPackagedManifest();
assertThat(manifest).isNotNull();
assertThat(manifest.getMainAttributes().getValue("Sbom-Format")).isEqualTo("CycloneDX");
assertThat(manifest.getMainAttributes().getValue("Sbom-Location"))
.isEqualTo("META-INF/sbom/application.cdx.json");
.isEqualTo(prefix + "META-INF/sbom/application.cdx.json");
}
private File createLibraryJar() throws IOException {