Skip to content

Commit 285c6c3

Browse files
committed
feat(cdx): Update to CycloneDX 1.6
1 parent af5b349 commit 285c6c3

File tree

5 files changed

+4
-5
lines changed

5 files changed

+4
-5
lines changed

.github/workflows/ci.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ env:
1111
CDXGEN_VERSION: '10.8.1'
1212
CDXGEN_PLUGINS_VERSION: '1.6.2'
1313
GRYPE_VERSION: 'v0.79.2'
14-
SBOMQS_VERSION: 'v0.1.5'
14+
SBOMQS_VERSION: 'v0.1.6'
1515
DEPSCAN_VERSION: 'v5.4.2'
1616
NYDUS_VERSION: '2.2.5'
1717
SWIFT_VERSION: '5.10.1'

.github/workflows/verify.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ on:
1212
env:
1313
CDXGEN_PLUGINS_VERSION: '1.6.2'
1414
GRYPE_VERSION: 'v0.79.2'
15-
SBOMQS_VERSION: 'v0.1.5'
15+
SBOMQS_VERSION: 'v0.1.6'
1616
DEPSCAN_VERSION: 'v5.4.2'
1717
NYDUS_VERSION: '2.2.5'
1818
java_version: '21'

src/main/java/com/mediamarktsaturn/technolinator/sbom/CdxgenClient.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -147,7 +147,7 @@ public CdxgenClient() {
147147
* * --project-name %s # name of main component of the SBOM, defaulting to the repository name
148148
* * --no-validate # disable cdxgen validation as we try to process everything
149149
*/
150-
private static final String CDXGEN_CMD_FMT = "cdxgen --spec-version 1.5 -o %s%s%s%s%s%s --project-name %s --no-validate";
150+
private static final String CDXGEN_CMD_FMT = "cdxgen --spec-version 1.6 -o %s%s%s%s%s%s --project-name %s --no-validate";
151151

152152
public record SbomCreationCommand(
153153
Path repoDir,

src/main/java/com/mediamarktsaturn/technolinator/sbom/DependencyTrackClient.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ public DependencyTrackClient(
5050
*/
5151
public Uni<Result<Project>> uploadSBOM(RepositoryDetails repoDetails, Bom sbom, String projectName, Project parentProject, Optional<String> commitSha) {
5252
var projectVersion = repoDetails.version();
53-
var sbomBase64 = Base64.getEncoder().encodeToString(new BomJsonGenerator(sbom, Version.VERSION_15).toJsonString().getBytes(StandardCharsets.UTF_8));
53+
var sbomBase64 = Base64.getEncoder().encodeToString(new BomJsonGenerator(sbom, Version.VERSION_16).toJsonString().getBytes(StandardCharsets.UTF_8));
5454
var payload = new JsonObject(Map.of(
5555
"projectName", projectName,
5656
"projectVersion", projectVersion,

src/test/java/com/mediamarktsaturn/technolinator/handler/PushHandlingTest.java

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,6 @@
1919
import org.kohsuke.github.GHEventPayload;
2020
import org.kohsuke.github.GitHub;
2121
import org.mockito.ArgumentCaptor;
22-
import org.testcontainers.shaded.org.hamcrest.CoreMatchers;
2322

2423
import java.io.IOException;
2524
import java.util.Optional;

0 commit comments

Comments
 (0)