Add SBOM manifest attributes to repackaged Maven wars

Packager#isCycloneDxBom only recognized CycloneDX SBOMs beneath
META-INF/sbom/. In a war, the CycloneDX Maven plugin's output is
packaged beneath WEB-INF/classes/META-INF/sbom/, so repackaging did
not add the SBOM manifest attributes.

Also check beneath Layout#getClassesLocation(), which findMainMethod
already uses to locate application classes. Continue to support the
root location used by jars.

Signed-off-by: COBI-98 <tkdgus968@naver.com>

See gh-51551
This commit is contained in:
COBI-98
2026-09-09 14:44:33 +01:00
committed by Andy Wilkinson
parent d34a479879
commit bfd05e38b5
6 changed files with 101 additions and 1 deletions
@@ -67,6 +67,16 @@ class WarIntegrationTests extends AbstractArchiveIntegrationTests {
.hasAttribute("Not-Used", "Foo")));
}
@TestTemplate
void sbomManifestAttributesAreAddedToRepackagedWar(MavenBuild mavenBuild) {
mavenBuild.project("war-sbom").execute((project) -> {
File repackaged = new File(project, "target/war-sbom-0.0.1.BUILD-SNAPSHOT.war");
assertThat(jar(repackaged)).hasEntryWithName("WEB-INF/classes/META-INF/sbom/application.cdx.json")
.manifest((manifest) -> manifest.hasAttribute("Sbom-Format", "CycloneDX")
.hasAttribute("Sbom-Location", "WEB-INF/classes/META-INF/sbom/application.cdx.json"));
});
}
@TestTemplate
void jarDependencyWithCustomFinalNameBuiltInSameReactorIsPackagedUsingArtifactIdAndVersion(MavenBuild mavenBuild) {
mavenBuild.project("war-reactor")
@@ -0,0 +1,48 @@
<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<groupId>org.springframework.boot.maven.it</groupId>
<artifactId>war-sbom</artifactId>
<version>0.0.1.BUILD-SNAPSHOT</version>
<packaging>war</packaging>
<properties>
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
<maven.compiler.source>@java.version@</maven.compiler.source>
<maven.compiler.target>@java.version@</maven.compiler.target>
</properties>
<build>
<plugins>
<plugin>
<groupId>@project.groupId@</groupId>
<artifactId>@project.artifactId@</artifactId>
<version>@project.version@</version>
<executions>
<execution>
<goals>
<goal>repackage</goal>
</goals>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-war-plugin</artifactId>
<version>@maven-war-plugin.version@</version>
</plugin>
</plugins>
</build>
<dependencies>
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-context</artifactId>
<version>@spring-framework.version@</version>
</dependency>
<dependency>
<groupId>jakarta.servlet</groupId>
<artifactId>jakarta.servlet-api</artifactId>
<version>@jakarta-servlet.version@</version>
<scope>provided</scope>
</dependency>
</dependencies>
</project>
@@ -0,0 +1,24 @@
/*
* Copyright 2012-present the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* https://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.test;
public class SampleApplication {
public static void main(String[] args) {
}
}
@@ -55,6 +55,7 @@ import org.springframework.util.StringUtils;
* @author Stephane Nicoll
* @author Madhura Bhave
* @author Scott Frederick
* @author Cobi Eun
* @since 2.3.0
*/
public abstract class Packager {
@@ -422,7 +423,8 @@ public abstract class Packager {
}
private boolean isCycloneDxBom(JarEntry entry) {
if (!entry.getName().startsWith("META-INF/sbom/")) {
if (!entry.getName().startsWith("META-INF/sbom/")
&& !entry.getName().startsWith(getLayout().getClassesLocation() + "META-INF/sbom/")) {
return false;
}
return entry.getName().endsWith(".cdx.json") || entry.getName().endsWith("/bom.json");
@@ -699,6 +699,21 @@ abstract class AbstractPackagerTests<P extends Packager> {
.isEqualTo("META-INF/sbom/application.cdx.json");
}
@Test
void sbomManifestEntriesAreWrittenForWar() throws IOException {
this.testJarFile.addClass("WEB-INF/classes/com/example/Application.class", ClassWithMainMethod.class);
this.testJarFile.addFile("WEB-INF/classes/META-INF/sbom/application.cdx.json",
new ByteArrayInputStream(new byte[0]));
P packager = createPackager(this.testJarFile.getFile());
packager.setLayout(new Layouts.War());
execute(packager, NO_LIBRARIES);
Manifest manifest = getPackagedManifest();
assertThat(manifest).isNotNull();
assertThat(manifest.getMainAttributes().getValue("Sbom-Format")).isEqualTo("CycloneDX");
assertThat(manifest.getMainAttributes().getValue("Sbom-Location"))
.isEqualTo("WEB-INF/classes/META-INF/sbom/application.cdx.json");
}
private File createLibraryJar() throws IOException {
TestJarFile library = new TestJarFile(this.tempDir);
library.addClass("com/example/library/Library.class", ClassWithoutMainMethod.class);