Publish SBOM
envgap__JanusGraph__janusgraph-4358
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
ab3a80123844976382dc43acda6d8aaf0ff29183- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
JanusGraph/janusgraph #4358 · read the original issue
**Describe the feature:** Publish a _software bill of materials_ (SBOM) for JanusGraph. **Describe a specific use case for the feature:** This enables users to quickly inspect which packages they are getting together with JanusGraph and in which specific version. That information can for example be used to scan for known vulnerabilities (like Log4Shell) or to check whether all dependencies meet their guidelines / are compliant with relevant regulations. There seem to be 2 different major formats for SBOMs: - SPDX from the Linux Foundation - CycloneDX from the OWASP foundation I don't have a strong preference, but from a quick search it seems that CycloneDX is more popular, especially among OSS projects. Sonatype also [mostly argues](https://blog.sonatype.com/comparing-sbom-standards-spdx-vs.-cyclonedx-vs.-swid) in favor of CycloneDX.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]