-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 The Apache Ant Team is pleased to announce the release of Apache CycloneDX Antlib 0.2.
The Apache CycloneDX Antlib is a library of Apache Ant types and a task that support the creation of CycloneDX SBOMs. Version 0.2 brings major improvements over the intial release. SBOMs can now be based on Ivy modules for projects using Apache Ivy. Also the CycloneDX Core Java dependency has been updated so that CycloneDX 1.7 SBOMs are created by default now. Several lessons learned while applying the Antlib to the other Ant code bases have lead to additional improvements. The full list of changes in this release is: ## Changes that Could Break Older Environments: * The name attribute of properties is required by the spec and this is now enforced. * Generalized sbomLink to a ComponentResolver componentdef. As a side effect the nested sbomLink element of component now must live in the "antlib:org.apache.ant.cyclonedx" XML namespace (i.e. something like cdx:sbomLink). ## Fixed Bugs: * The name attribute of properties is required by the spec and this is now enforced. * metadata.tools.component of generated SBOMs now contains hashes of ant-cyclonedx as has been intended originally. ## Other Changes: * A new type "propertyset" can be used to group properties and reuse common sets of properties for multiple components. * When using sbomLink for a component, the link is an URL and the component-element doesn't define a "bom"-type external reference itself a "bom" externalreference with the URL as value is added to the component. This behavior can be suppressed by an attribute. * A new resource collection "fsonlymappedresources" has been added that decorates file-system-only resource collections modifying the names of the resources just like Ant's built-in mappedresources but still allows tasks to access the original files. This should only be used with componentbom's purefileresources nested element. Other tasks and types may bypass the mapped name if they can go to the underlying files directly. * A new specialized task "archivebom" simplifies creation of SBOMs for distribution zips/tarballs by providing a few defaults. * The componentbom and archivebom tasks honor the SOURCE_DATE_EPOCH environment variable as well as Ant's magic properties ant.tstamp.now.iso and ant.tstamp.now and use either as timestamp for the generated SBOM for reproducible builds. The default still is to use the current point in time as timestamp. * A new attribute "serialNumber" of the componentbom task allows the serial number of the generated SBOM to be set to a fixed value for reproducible builds. If the attribute is not set but SOURCE_DATE_EPOCH is defined the serial number will be calculated from SOURCE_DATE_EPOCH and the main component's coordinates. * The array valued parts of the generated SBOM now have a stable sort order to support reproducible builds. * Updated cyclonedx-java-core library dependency to 13.2.0. * The default SBOM version now is 1.7 and the isExternal attribute of component now also sets the attribute in the generated SBOM. * Added a ComponentResolver "ivyModule" which uses Apache Ivy to fill in the details of a component and its dependencies. This adds Ivy as a new dependency which is only required if you want to use this feature. * The license element now tries to guess the license's SPDX id if only a name is given. * The license element now supports a new expression attribute you can use to specify license expressions. * A new attribute compositionAggregate on component allows you to specify the completeness of the component's description. * Updated the Ant dependency to 1.10.18, but the library should work with earlier versions of Ant 1.10.x. Source and binary distributions are available for download from the Apache Ant download site: https://ant.apache.org/antlibs/bindownload.cgi https://ant.apache.org/antlibs/srcdownload.cgi When downloading, please verify signatures using the KEYS file available at the above location when downloading the release. For complete information on Ant, including instructions on how to submit bug reports, patches, or suggestions for improvement, see the Apache Ant website: https://ant.apache.org/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iEYEARECAAYFAmq2syoACgkQohFa4V9ri3L+5gCgxcJ0iQ0P4zgmSx4DeMWvHgrk wZEAoLBMJQ0600RVaOAbZYyYuwxBF6Zj =GwS1 -----END PGP SIGNATURE----- --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
