← All tasks
javaJanusGraph/janusgraph #4358Not a task: already works

Publish SBOM

envgap__JanusGraph__janusgraph-4358

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
ab3a80123844976382dc43acda6d8aaf0ff29183
Manifest
pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

JanusGraph/janusgraph #4358 · read the original issue
**Describe the feature:**

Publish a _software bill of materials_ (SBOM) for JanusGraph.



**Describe a specific use case for the feature:**

This enables users to quickly inspect which packages they are getting together with JanusGraph and in which specific version. That information can for example be used to scan for known vulnerabilities (like Log4Shell) or to check whether all dependencies meet their guidelines / are compliant with relevant regulations.



There seem to be 2 different major formats for SBOMs:



- SPDX from the Linux Foundation

- CycloneDX from the OWASP foundation



I don't have a strong preference, but from a quick search it seems that CycloneDX is more popular, especially among OSS projects. Sonatype also [mostly argues](https://blog.sonatype.com/comparing-sbom-standards-spdx-vs.-cyclonedx-vs.-swid) in favor of CycloneDX.
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]