Uploaded image for project: 'Couchbase Server'
  1. Couchbase Server
  2. MB-54594

Include Couchbase jars & shadowed dependencies in BOM for Analytics BD scans

    XMLWordPrintable

Details

    • 0

    Description

      Currently the BOMs published by Analytics build process exclude Couchbase jars – this prevents shadowed third-party dependencies from being reported on the BD reports, which can hide security & licensing issues which may manifest in those dependencies.

      In addition, Maven does not provide any metadata in the POM which indicates which dependencies are shadowed, so they are not included in the BOM. We need to explicitly map the shadowed (embedded) dependencies into our published BOM.

      Attachments

        No reviews matched the request. Check your Options in the drop-down menu of this sections header.

        Activity

          Build couchbase-server-7.5.0-3518 contains cbas-core commit da518c1 with commit message:
          MB-54594: += core-io-1.7.20 (6.0.x compat), shadowed deps to BOM & license

          build-team Couchbase Build Team added a comment - Build couchbase-server-7.5.0-3518 contains cbas-core commit da518c1 with commit message: MB-54594 : += core-io-1.7.20 (6.0.x compat), shadowed deps to BOM & license

          Build couchbase-server-7.5.0-3518 contains cbas-core commit b6306a0 with commit message:
          MB-54594: += core-io, shadowed deps to BOM & license

          build-team Couchbase Build Team added a comment - Build couchbase-server-7.5.0-3518 contains cbas-core commit b6306a0 with commit message: MB-54594 : += core-io, shadowed deps to BOM & license

          Build couchbase-server-8.0.0-1212 contains cbas-core commit da518c1 with commit message:
          MB-54594: += core-io-1.7.20 (6.0.x compat), shadowed deps to BOM & license

          build-team Couchbase Build Team added a comment - Build couchbase-server-8.0.0-1212 contains cbas-core commit da518c1 with commit message: MB-54594 : += core-io-1.7.20 (6.0.x compat), shadowed deps to BOM & license

          Build couchbase-server-8.0.0-1212 contains cbas-core commit b6306a0 with commit message:
          MB-54594: += core-io, shadowed deps to BOM & license

          build-team Couchbase Build Team added a comment - Build couchbase-server-8.0.0-1212 contains cbas-core commit b6306a0 with commit message: MB-54594 : += core-io, shadowed deps to BOM & license

          Closing based on changeless, no regression with functional, system and perf tests.

          ritam.sharma Ritam Sharma added a comment - Closing based on changeless, no regression with functional, system and perf tests.

          People

            michael.blow Michael Blow
            michael.blow Michael Blow
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Gerrit Reviews

                There are no open Gerrit changes

                PagerDuty