Skip to content

Publish SBOM + provenance and enable reproducible, GPG-signed releases - #180

Merged
AndreasIgel merged 4 commits into
java-helpers:mainfrom
AndreasIgel:feature/158-sbom-provenance-reproducible
Jul 20, 2026
Merged

AndreasIgel merged 4 commits into
java-helpers:mainfrom
AndreasIgel:feature/158-sbom-provenance-reproducible

Conversation

@AndreasIgel

Copy link
Copy Markdown
Collaborator

Upstream counterpart of fork PR AndreasIgel#5. Head branch: AndreasIgel/simple-builders-fork:feature/158-sbom-provenance-reproducible → base java-helpers/simple-builders:main.

Summary

Adds supply-chain artifacts to the release: SBOM, build provenance, and reproducible builds (GPG signing already existed).

Fixes #158

Changes:

  • SBOM: CycloneDX cyclonedx-maven-plugin (2.9.1) added to the release profile of core and processor (bound to package, skipNotDeployed=false so it still runs under the central-publishing extension). Produces *-sbom.json and *-sbom.xml per module.
  • Release workflow: new Generate SBOM step, SBOM files attached to the GitHub release, and an actions/attest-build-provenance step (SHA-pinned) for the published jars (id-token: write + attestations: write added).
  • Reproducible builds: project.build.outputTimestamp set in both module POMs (overridable per release via -Dproject.build.outputTimestamp).
  • RELEASE.md documents SBOM/provenance/reproducibility/GPG.

Validation

  • mvn clean verify passes.
  • Verified SBOM generation locally: mvn -Prelease -pl core,processor -am package produces simple-builders-core-0.5.0-SNAPSHOT-sbom.json/.xml and the processor equivalents.
  • actionlint passes on the release workflow.
  • The provenance attestation and GitHub-release attachment run only in Actions (need id-token/release context) and couldn't be exercised locally.

Note: CI build/dependency-review failures are unrelated (fork lacks SONAR_TOKEN/CODECOV_TOKEN; Dependency graph disabled).

…eleases

- Add CycloneDX SBOM generation (JSON+XML) to core/processor release
  profile and attach SBOMs to the GitHub release.
- Add a build-provenance attestation step for the published jars.
- Enable reproducible builds via project.build.outputTimestamp.
- Document supply-chain artifacts in RELEASE.md.

Refs java-helpers#158

Co-Authored-By: Andreas Igel <andreas.igel@computacenter.com>
@codecov

codecov Bot commented Jul 15, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

Comment thread .github/workflows/maven-central-release.yml Outdated
Comment thread core/pom.xml Outdated
Comment thread .github/workflows/maven-central-release.yml
Comment thread core/pom.xml
…reproducible timestamp

Co-Authored-By: Andreas Igel <andreas.igel@computacenter.com>
@sonarqubecloud

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Deprecation Warning: The deny-licenses option is deprecated for possible removal in the next major release. For more information, see issue 997.

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA a54b68a.
Ensure that dependencies are being submitted on PR branches. Re-running this action after a short time may resolve the issue. See the documentation for more information and troubleshooting advice.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/actions/attest-build-provenance 0f67c3f4856b2e3261c31976d6725780e5e4c373 UnknownUnknown
maven/org.cyclonedx:cyclonedx-maven-plugin 2.9.1 UnknownUnknown
maven/org.cyclonedx:cyclonedx-maven-plugin 2.9.1 UnknownUnknown

Scanned Files

  • .github/workflows/maven-central-release.yml
  • core/pom.xml
  • processor/pom.xml

@AndreasIgel
AndreasIgel merged commit 37707da into java-helpers:main Jul 20, 2026
5 of 6 checks passed
@devin-ai-integration
devin-ai-integration Bot deleted the feature/158-sbom-provenance-reproducible branch August 16, 2026 21:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Release: publish SBOM + provenance and enable reproducible, GPG-signed builds

1 participant