ppkarwasz commented on PR #417:
URL: 
https://github.com/apache/commons-build-plugin/pull/417#issuecomment-4153893679

   The generated in-toto attestation is pretty much work in progress and 
currently looks like:
   
   ```json
   {
     "_type": "https://in-toto.io/Statement/v1";,
     "subject": [
       {
         "name": "commons-lang3-3.21.0-SNAPSHOT.jar",
         "uri": 
"pkg:maven/org.apache.commons/[email protected]?type=jar",
         "digest": {
           "sha256": 
"ee1651528c4192694e266ddca6020070e6ca5349f2d207c8f8315ecdc8b6d31e"
         }
       },
       {
         "name": "commons-lang3-3.21.0-SNAPSHOT-javadoc.jar",
         "uri": 
"pkg:maven/org.apache.commons/[email protected]?classifier=javadoc&type=javadoc",
         "digest": {
           "sha256": 
"f2893c0a934aae85f0917d6789f56a1a3fd06fdddf6060ced991fe78ca161590"
         }
       },
       {
         "name": "commons-lang3-3.21.0-SNAPSHOT-tests.jar",
         "uri": 
"pkg:maven/org.apache.commons/[email protected]?classifier=tests&type=test-jar",
         "digest": {
           "sha256": 
"b369929c076d7a1260662089cf7eca406ac0c249a728b59e6b33c9a663820928"
         }
       },
       {
         "name": "commons-lang3-3.21.0-SNAPSHOT-sources.jar",
         "uri": 
"pkg:maven/org.apache.commons/[email protected]?classifier=sources&type=java-source",
         "digest": {
           "sha256": 
"fde78aa1ac57bd1859991ef9fe8af6c8cb5daf65858f232328eee54d989b51f5"
         }
       },
       {
         "name": "commons-lang3-3.21.0-SNAPSHOT-test-sources.jar",
         "uri": 
"pkg:maven/org.apache.commons/[email protected]?classifier=test-sources&type=java-source",
         "digest": {
           "sha256": 
"3b40d7337ce62e56121a77d855e009a6aada65e71a3b265fab5aae5575af4097"
         }
       },
       {
         "name": "commons-lang3-3.21.0-SNAPSHOT-cyclonedx.xml",
         "uri": 
"pkg:maven/org.apache.commons/[email protected]?classifier=cyclonedx&type=xml",
         "digest": {
           "sha256": 
"909a13f4cca6532d636bfac3b14fa7bd39534dd3a1c9e6ff0a1dcab4adbfcf7d"
         }
       },
       {
         "name": "commons-lang3-3.21.0-SNAPSHOT-cyclonedx.json",
         "uri": 
"pkg:maven/org.apache.commons/[email protected]?classifier=cyclonedx&type=json",
         "digest": {
           "sha256": 
"ce14e90c8b82867046cd52217c7fa45acb7f9a9e6a3815db0f45a8044d50ffbc"
         }
       },
       {
         "name": "commons-lang3-3.21.0-SNAPSHOT.spdx.json",
         "uri": 
"pkg:maven/org.apache.commons/[email protected]?type=spdx.json",
         "digest": {
           "sha256": 
"2aeefe66942acc591768b1b6507a849addcd6accd36833963d5a43d0885f7c13"
         }
       },
       {
         "name": "commons-lang3-3.21.0-SNAPSHOT-bin.tar.gz",
         "uri": 
"pkg:maven/org.apache.commons/[email protected]?classifier=bin&type=tar.gz",
         "digest": {
           "sha256": 
"8aa63ee5fc91f3c572e8efe1be1a899beac06f4cecb7f6ad09c51883925801a5"
         }
       },
       {
         "name": "commons-lang3-3.21.0-SNAPSHOT-bin.zip",
         "uri": 
"pkg:maven/org.apache.commons/[email protected]?classifier=bin&type=zip",
         "digest": {
           "sha256": 
"54d82986f78cadbfa246a7b35d41a08b36adb6f67dc638dc16c6ea0d11419853"
         }
       },
       {
         "name": "commons-lang3-3.21.0-SNAPSHOT-src.tar.gz",
         "uri": 
"pkg:maven/org.apache.commons/[email protected]?classifier=src&type=tar.gz",
         "digest": {
           "sha256": 
"46d16144d0a6a02931349fcad252b04e6d2f7feb2bd0103a67c212a1220636e4"
         }
       },
       {
         "name": "commons-lang3-3.21.0-SNAPSHOT-src.zip",
         "uri": 
"pkg:maven/org.apache.commons/[email protected]?classifier=src&type=zip",
         "digest": {
           "sha256": 
"6de609cc8ba5011231fa466e9cce68cc631c844754df0472600067fdca995ec9"
         }
       }
     ],
     "predicateType": "https://slsa.dev/provenance/v1";,
     "predicate": {
       "buildDefinition": {
         "buildType": "https://commons.apache.org/builds/0.1.0";,
         "externalParameters": {
           "maven.profiles": [
             "release"
           ],
           "maven.cmdline": "clean verify -Prelease -DskipTests=true",
           "jvm.args": [
             "--enable-native-access=ALL-UNNAMED",
             "-Dclassworlds.conf=/opt/maven/bin/m2.conf",
             "-Dmaven.home=/opt/maven",
             "-Dlibrary.jansi.path=/opt/maven/lib/jansi-native",
             
"-Dmaven.multiModuleProjectDirectory=/home/piotr/workspace/commons/lang"
           ],
           "maven.user.properties": {
             "skipTests": "true"
           },
           "maven.goals": [
             "clean",
             "verify"
           ],
           "env": {
             "LANG": "pl_PL.UTF-8"
           }
         },
         "internalParameters": {},
         "resolvedDependencies": [
           {
             "name": "JDK",
             "digest": {
               "gitTree": "4e443b1e40192a6af6daf558eac4cb93b6000d01"
             },
             "annotations": {
               "vendor": "Eclipse Adoptium",
               "vendor.version": "Temurin-17.0.18+8",
               "vm.vendor": "Eclipse Adoptium",
               "vm.name": "OpenJDK 64-Bit Server VM",
               "vm.version": "17.0.18+8",
               "runtime.version": "17.0.18+8",
               "runtime.name": "OpenJDK Runtime Environment",
               "specification.version": "17",
               "version": "17.0.18"
             }
           },
           {
             "name": "Maven",
             "uri": "pkg:maven/org.apache.maven/[email protected]",
             "digest": {
               "gitTree": "2db3f3ef8c9fcf7f565ec36a31cf64ca0a8c4a7b"
             }
           },
           {
             "uri": 
"git+https://gitbox.apache.org/repos/asf/commons-lang.git@master";,
             "digest": {
               "gitCommit": "088be66cc47df65f628ad044a2685e9046e37b7a"
             }
           },
           {
             "name": "byte-buddy-1.17.5.jar",
             "uri": "pkg:maven/net.bytebuddy/[email protected]?type=jar",
             "digest": {
               "sha256": 
"71568c9f8396677219f650268fbf6493ded484edcdbdf2dae6129ca5be81e8db"
             }
           },
           {
             "name": "objenesis-3.4.jar",
             "uri": "pkg:maven/org.objenesis/[email protected]?type=jar",
             "digest": {
               "sha256": 
"95488102feaf2e2858adf6b299353677dac6c15294006f8ed1c5556f8e3cd251"
             }
           },
           {
             "name": "mockito-inline-4.11.0.jar",
             "uri": "pkg:maven/org.mockito/[email protected]?type=jar",
             "digest": {
               "sha256": 
"ee52e1c299a632184fba274a9370993e09140429f5e516e6c5570fd6574b297f"
             }
           },
           {
             "name": "mockito-core-4.11.0.jar",
             "uri": "pkg:maven/org.mockito/[email protected]?type=jar",
             "digest": {
               "sha256": 
"4b909690cab288c761eb94c0bf0e814496cf3921d8affac84cd87774530351e5"
             }
           },
           {
             "name": "byte-buddy-agent-1.12.19.jar",
             "uri": "pkg:maven/net.bytebuddy/[email protected]?type=jar",
             "digest": {
               "sha256": 
"3a70240de7cdcde04e7c504c2327d7035b9c25ae0206881e3bf4e6798a273ed8"
             }
           }
         ]
       },
       "runDetails": {
         "builder": {
           "id": "https://commons.apache.org/builds/0.1.0";,
           "builderDependencies": [],
           "version": {}
         },
         "metadata": {
           "invocationId": "singlethreaded",
           "startedOn": "2026-03-30T10:14:15Z",
           "finishedOn": "2026-03-30T10:14:35Z"
         }
       }
     }
   }
   ```


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to