Skip to content

refactor(build): read the SBOM with the CycloneDX model instead of JsonSlurper - #247

Open
adityamparikh wants to merge 2 commits into
apache:mainfrom
adityamparikh:refactor/sbom-cyclonedx-model
Open

adityamparikh wants to merge 2 commits into
apache:mainfrom
adityamparikh:refactor/sbom-cyclonedx-model

Conversation

@adityamparikh

Copy link
Copy Markdown
Contributor

Depends on #245. This branch is stacked on it, so the first commit in the diff is #245's; review only the last commit, refactor(build): read the SBOM with the CycloneDX model instead of JsonSlurper. The extra commit drops out once #245 merges.

Summary

Reads the CycloneDX SBOM with cyclonedx-core-java's own JsonParser and its typed Bom / Component / License model, instead of walking untyped maps parsed by Groovy's JsonSlurper.

  • SbomLicenses goes from 79 to 67 lines. The four @Suppress("UNCHECKED_CAST") blocks and the as? Map<String, Any?> casts are gone, and the Groovy dependency leaves the license lookup.
  • New buildSrc dependency: org.cyclonedx:cyclonedx-core-java:10.2.1 (Apache-2.0), pinned to the version the org.cyclonedx.bom plugin 2.4.1 — which writes the SBOM — already depends on, so reader and writer share one model. It is buildSrc-only and does not appear in the binary LICENSE.

Behaviour

Unchanged. The lookup keys, the SPDX-id-first label rule, the https://spdx.org/licenses/<id>.html URL fallback and the expression handling are the same.

Testing

  • ./gradlew build (JDK 25, clean tree, including rat) — 421 tests, 0 failed, 0 skipped.
  • On the real SBOM, the generated LICENSE and ip-clearance-licenses.xml are byte-identical to the output of the JsonSlurper version.

@epugh, please review.

🤖 Generated with Claude Code

adityamparikh and others added 2 commits October 4, 2026 21:07
Add generateIpClearanceLicenseReport, which writes
build/generated/license/ip-clearance-licenses.xml: the "all items depended
upon by the project are covered by approved licenses" row of the Incubator
IP-clearance status document, listing group:artifact and license for every
bundled dependency as reported by the CycloneDX SBOM. A dependency missing
from the SBOM fails the task, the same completeness gate the binary LICENSE
uses.

Add the generateLicenseDocs aggregate (LICENSE, NOTICE and the IP-clearance
row) and make check depend on it, so a plain ./gradlew build leaves all three
in build/generated/license/. CI uploads that directory as the
solr-mcp-license-docs artifact. Extract the SBOM license lookup into a shared
SbomLicenses helper used by both license tasks.

Document the row on the Licensing & Notices page, in AGENTS.md and in
buildSrc/README.md, including a table of the generated files with the Gradle
task that produces each.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
…onSlurper

Parse the SBOM with cyclonedx-core-java's JsonParser into its typed Bom,
Component and License model instead of walking untyped maps from Groovy's
JsonSlurper. This removes the unchecked casts and the Groovy dependency
from the license lookup. The library is pinned to the version the
org.cyclonedx.bom plugin, which writes the SBOM, already uses. The
generated LICENSE and IP-clearance row are byte-identical.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Signed-off-by: Aditya Parikh <aditya.m.parikh@gmail.com>
@adityamparikh
adityamparikh marked this pull request as ready for review October 5, 2026 01:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant