Uploaded image for project: 'Couchbase Server'
  1. Couchbase Server
  2. MB-54594

Include Couchbase jars & shadowed dependencies in BOM for Analytics BD scans

    XMLWordPrintable

Details

    • 0

    Description

      Currently the BOMs published by Analytics build process exclude Couchbase jars – this prevents shadowed third-party dependencies from being reported on the BD reports, which can hide security & licensing issues which may manifest in those dependencies.

      In addition, Maven does not provide any metadata in the POM which indicates which dependencies are shadowed, so they are not included in the BOM. We need to explicitly map the shadowed (embedded) dependencies into our published BOM.

      Attachments

        No reviews matched the request. Check your Options in the drop-down menu of this sections header.

        Activity

          People

            michael.blow Michael Blow
            michael.blow Michael Blow
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Gerrit Reviews

                There are no open Gerrit changes

                PagerDuty