adityamparikh opened a new pull request, #247:
URL: https://github.com/apache/solr-mcp/pull/247
> **Depends on #245.** This branch is stacked on it, so the first commit in
the diff is #245's; review only the last commit, `refactor(build): read the
SBOM with the CycloneDX model instead of JsonSlurper`. The extra commit drops
out once #245 merges.
## Summary
Reads the CycloneDX SBOM with `cyclonedx-core-java`'s own `JsonParser` and
its typed `Bom` / `Component` / `License` model, instead of walking untyped
maps parsed by Groovy's `JsonSlurper`.
- `SbomLicenses` goes from 79 to 67 lines. The four
`@Suppress("UNCHECKED_CAST")` blocks and the `as? Map<String, Any?>` casts are
gone, and the Groovy dependency leaves the license lookup.
- New `buildSrc` dependency: `org.cyclonedx:cyclonedx-core-java:10.2.1`
(Apache-2.0), pinned to the version the `org.cyclonedx.bom` plugin 2.4.1 —
which *writes* the SBOM — already depends on, so reader and writer share one
model. It is `buildSrc`-only and does not appear in the binary `LICENSE`.
## Behaviour
Unchanged. The lookup keys, the SPDX-id-first label rule, the
`https://spdx.org/licenses/<id>.html` URL fallback and the expression handling
are the same.
## Testing
- `./gradlew build` (JDK 25, clean tree, including `rat`) — 421 tests, 0
failed, 0 skipped.
- On the real SBOM, the generated `LICENSE` and `ip-clearance-licenses.xml`
are byte-identical to the output of the `JsonSlurper` version.
@epugh, please review.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]