Skip to main content

An Adventure with the CycloneDX Maven Plugin

· 15 min read
Kevin Conner
Maintainer

The CycloneDX Maven Plugin can be used to generate CycloneDX Software Bill of Materials (SBOM) for your maven projects as part of your build process. The plugin is easy to integrate, however does have some issues due mostly to idiosyncrasies and shortcomings with the maven resolution mechanism. In this post I attempt to provide some background, examples and explanations for the issues I've discovered as well as context for the solutions I'm proposing.

Welcome

· One min read
Jim Crossley
Maintainer

Today, we're excited to announce the launch of Trustification, a new community dedicated to improving software supply-chain security.