refactor(build): read the SBOM with the CycloneDX model instead of JsonSlurper - #247
Open
adityamparikh wants to merge 2 commits into
Open
adityamparikh wants to merge 2 commits into
adityamparikh wants to merge 2 commits into
Conversation
Add generateIpClearanceLicenseReport, which writes build/generated/license/ip-clearance-licenses.xml: the "all items depended upon by the project are covered by approved licenses" row of the Incubator IP-clearance status document, listing group:artifact and license for every bundled dependency as reported by the CycloneDX SBOM. A dependency missing from the SBOM fails the task, the same completeness gate the binary LICENSE uses. Add the generateLicenseDocs aggregate (LICENSE, NOTICE and the IP-clearance row) and make check depend on it, so a plain ./gradlew build leaves all three in build/generated/license/. CI uploads that directory as the solr-mcp-license-docs artifact. Extract the SBOM license lookup into a shared SbomLicenses helper used by both license tasks. Document the row on the Licensing & Notices page, in AGENTS.md and in buildSrc/README.md, including a table of the generated files with the Gradle task that produces each. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
…onSlurper Parse the SBOM with cyclonedx-core-java's JsonParser into its typed Bom, Component and License model instead of walking untyped maps from Groovy's JsonSlurper. This removes the unchecked casts and the Groovy dependency from the license lookup. The library is pinned to the version the org.cyclonedx.bom plugin, which writes the SBOM, already uses. The generated LICENSE and IP-clearance row are byte-identical. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
adityamparikh
marked this pull request as ready for review
October 5, 2026 01:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Reads the CycloneDX SBOM with
cyclonedx-core-java's ownJsonParserand its typedBom/Component/Licensemodel, instead of walking untyped maps parsed by Groovy'sJsonSlurper.SbomLicensesgoes from 79 to 67 lines. The four@Suppress("UNCHECKED_CAST")blocks and theas? Map<String, Any?>casts are gone, and the Groovy dependency leaves the license lookup.buildSrcdependency:org.cyclonedx:cyclonedx-core-java:10.2.1(Apache-2.0), pinned to the version theorg.cyclonedx.bomplugin 2.4.1 — which writes the SBOM — already depends on, so reader and writer share one model. It isbuildSrc-only and does not appear in the binaryLICENSE.Behaviour
Unchanged. The lookup keys, the SPDX-id-first label rule, the
https://spdx.org/licenses/<id>.htmlURL fallback and the expression handling are the same.Testing
./gradlew build(JDK 25, clean tree, includingrat) — 421 tests, 0 failed, 0 skipped.LICENSEandip-clearance-licenses.xmlare byte-identical to the output of theJsonSlurperversion.@epugh, please review.
🤖 Generated with Claude Code