This is an automated email from the ASF dual-hosted git repository. asf-gitbox-commits pushed a commit to branch support-ivy-as-component-source in repository https://gitbox.apache.org/repos/asf/ant-antlibs-cyclonedx.git
commit d558b22987c55009a733513b9158403e6d43a46d Author: Stefan Bodewig <[email protected]> AuthorDate: Sun Aug 9 10:41:28 2026 +0200 move sbomlink tests to separate build file --- src/tests/antunit/component-sbomlink-test.xml | 463 ++++++++++++++++++++++++ src/tests/antunit/component-test.xml | 489 +------------------------- src/tests/antunit/componentbom-test.xml | 56 --- src/tests/antunit/shared.xml | 33 ++ 4 files changed, 513 insertions(+), 528 deletions(-) diff --git a/src/tests/antunit/component-sbomlink-test.xml b/src/tests/antunit/component-sbomlink-test.xml new file mode 100644 index 0000000..c75a2a0 --- /dev/null +++ b/src/tests/antunit/component-sbomlink-test.xml @@ -0,0 +1,463 @@ +<?xml version="1.0"?> +<!-- + Licensed to the Apache Software Foundation (ASF) under one or more + contributor license agreements. See the NOTICE file distributed with + this work for additional information regarding copyright ownership. + The ASF licenses this file to You under the Apache License, Version 2.0 + (the "License"); you may not use this file except in compliance with + the License. You may obtain a copy of the License at + + https://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. +--> +<project name="component-sbomlink-test" default="antunit"> + + <import file="shared.xml" /> + + <target name="testSbomLinkUsesDataFromLinkedSbom" depends="createMaximalComponentData"> + <cdx:componentbom + bomName="merged" + outputdirectory="${output}" + format="xml" + xmlns:cdx="antlib:org.apache.ant.cyclonedx"> + <component> + <sbomLink> + <file file="${output}/bom.json"/> + </sbomLink> + </component> + </cdx:componentbom> + <xmlproperty file="${output}/merged.xml"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.name" + value="testname"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component(type)" + value="library"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.group" + value="org.example"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.version" + value="1.0"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.publisher" + value="test publisher"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.copyright" + value="Copyright 2026 ACME Com"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component(mime-type)" + value="text/plain"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.purl" + value="pkg:maven/org.example/[email protected]?type=jar"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component(bom-ref)" + value="pkg:maven/org.example/[email protected]?type=jar"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.description" + value="My Test Library"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.authors.author.name" + value="Author"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.authors.author.email" + value="[email protected]"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.manufacturer.name" + value="Example"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.manufacturer.url" + value="https://example.org/"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.supplier.name" + value="Example 2"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.supplier.url" + value="https://example.com/"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.licenses.license.name" + value="My License"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.tags.tag" + value="label"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.properties.property(name)" + value="foo"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.properties.property" + value="bar"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.components.component.name" + value="other-test"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.components.component(type)" + value="library"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.components.component.group" + value="org.example"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.components.component.version" + value="1.1"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.components.component.purl" + value="pkg:maven/org.example/[email protected]?type=jar"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.components.component(bom-ref)" + value="pkg:maven/org.example/[email protected]?type=jar"/> + <au:assertResourceContains + xmlns:au="antlib:org.apache.ant.antunit" + resource="${output}/bom.xml" + value='<url>https://example.com/</url>'/> + <!-- some-dependency is not here as we explicitly set the its + dependencies to unknown. We don't want top open the can of + transitive dependency worms --> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.dependencies.dependency(ref)" + value="pkg:maven/org.example/[email protected]?type=jar"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.dependencies.dependency.dependency(ref)" + value="some-dependency"/> + <!-- ensure hashes are not taken from the linked SBOM --> + <au:assertResourceDoesntContain + xmlns:au="antlib:org.apache.ant.antunit" + resource="${output}/merged.xml" + value='<hash alg="SHA-256">${ant.file.sha256}</hash>'/> + </target> + + <target name="testSbomLinkAddsBomExternalLink" depends="createMaximalComponentData"> + <cdx:componentbom + bomName="merged" + outputdirectory="${output}" + format="xml" + xmlns:cdx="antlib:org.apache.ant.cyclonedx"> + <component> + <sbomLink> + <url url="https://repo1.maven.org/maven2/org/apache/ant/ant-cyclonedx/0.1/ant-cyclonedx-0.1-cyclonedx.json"/> + </sbomLink> + </component> + </cdx:componentbom> + <xmlproperty file="${output}/merged.xml"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.externalReferences.reference(type)" + value="vcs,issue-tracker,website,bom,mailing-list,source-distribution,distribution,license,build-system,security-contact"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.externalReferences.reference.url" + value="https://gitbox.apache.org/repos/asf/ant-antlibs-cyclonedx.git,https://bz.apache.org/bugzilla/buglist.cgi?component=CycloneDX%20Antlib&product=Ant,https://ant.apache.org/antlibs/cyclonedx/,https://repo1.maven.org/maven2/org/apache/ant/ant-cyclonedx/0.1/ant-cyclonedx-0.1-cyclonedx.json,https://ant.apache.org/mail.html,https://ant.apache.org/antlibs/srcdownload.cgi,https://ant.apache.org/antlibs/bindownload.cgi,https://www.apache.org/licenses/LICENSE-2.0.txt,https://ci-bu [...] + </target> + + <target name="testSbomLinkDoesntAddBomExternalLinkWhenDisabled" depends="createMaximalComponentData"> + <cdx:componentbom + bomName="merged" + outputdirectory="${output}" + format="xml" + xmlns:cdx="antlib:org.apache.ant.cyclonedx"> + <component> + <sbomLink createBomExternalReference="false"> + <url url="https://repo1.maven.org/maven2/org/apache/ant/ant-cyclonedx/0.1/ant-cyclonedx-0.1-cyclonedx.json"/> + </sbomLink> + </component> + </cdx:componentbom> + <xmlproperty file="${output}/merged.xml"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.externalReferences.reference(type)" + value="vcs,issue-tracker,website,mailing-list,source-distribution,distribution,license,build-system,security-contact"/> + </target> + + <target name="testSbomLinkDoesntOverrideExistingBomExternalLink" depends="createMaximalComponentData"> + <cdx:componentbom + bomName="merged" + outputdirectory="${output}" + format="xml" + xmlns:cdx="antlib:org.apache.ant.cyclonedx"> + <component> + <sbomLink> + <url url="https://repo1.maven.org/maven2/org/apache/ant/ant-cyclonedx/0.1/ant-cyclonedx-0.1-cyclonedx.json"/> + </sbomLink> + <externalReference type="bom" url="https://example.org/"/> + </component> + </cdx:componentbom> + <xmlproperty file="${output}/merged.xml"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.externalReferences.reference(type)" + value="bom"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.externalReferences.reference.url" + value="https://example.org/"/> + </target> + + <target + name="testSbomLinkDoesNotUseLinkedManufacturerIfSupplierIsManufacturer" + depends="createMaximalComponentData"> + <cdx:componentbom + bomName="merged" + outputdirectory="${output}" + format="xml" + xmlns:cdx="antlib:org.apache.ant.cyclonedx"> + <component supplierIsManufacturer="true"> + <sbomLink> + <file file="${output}/bom.json"/> + </sbomLink> + </component> + </cdx:componentbom> + <xmlproperty file="${output}/merged.xml"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.manufacturer.name" + value="Example 2"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.manufacturer.url" + value="https://example.com/"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.supplier.name" + value="Example 2"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.supplier.url" + value="https://example.com/"/> + </target> + + <target + name="testDataFromLinkedSbomCanBeOverwrittenOrMerged" + depends="createMaximalComponentData"> + <cdx:componentbom + bomName="merged" + outputdirectory="${output}" + format="xml" + xmlns:cdx="antlib:org.apache.ant.cyclonedx"> + <component + type="APPLICATION" + name="testname2" + group="org.example2" + version="2.0" + description="My Second Test Library" + publisher="test2 publisher" + copyright="Copyright 2026 ACME Corp" + mimeType="text/xml" + > + <file file="${ant.file}"/> + <manufacturer name="Example 3"> + <url url="https://example.org/3"/> + </manufacturer> + <supplier name="Example 4"> + <url url="https://example.com/4"/> + </supplier> + <license name="My Other License"/> + <externalReference type="WEBSITE" url="https://example.org/site"/> + <component name="yet-another-test" group="org.example2" + version="1.2" unknownDependencies="true"/> + <author name="Author2" email="[email protected]"/> + <tag>label2</tag> + <property name="xyzzy" value="baz"/> + <dependency bomRef="my-own-dependency"/> + <sbomLink> + <file file="${output}/bom.json"/> + </sbomLink> + </component> + <additionalComponent name="my-own-dependency" bomRef="my-own-dependency"/> + </cdx:componentbom> + <xmlproperty file="${output}/merged.xml"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.name" + value="testname2"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component(type)" + value="application"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.group" + value="org.example2"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.version" + value="2.0"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.publisher" + value="test2 publisher"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.copyright" + value="Copyright 2026 ACME Corp"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component(mime-type)" + value="text/xml"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.purl" + value="pkg:maven/org.example2/[email protected]?type=jar"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component(bom-ref)" + value="pkg:maven/org.example2/[email protected]?type=jar"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.description" + value="My Second Test Library"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.authors.author.name" + value="Author2"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.authors.author.email" + value="[email protected]"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.manufacturer.name" + value="Example 3"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.manufacturer.url" + value="https://example.org/3"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.supplier.name" + value="Example 4"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.supplier.url" + value="https://example.com/4"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.licenses.license.name" + value="My Other License"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.tags.tag" + value="label,label2"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.properties.property(name)" + value="xyzzy"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.properties.property" + value="baz"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.components.component.name" + value="yet-another-test"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.components.component(type)" + value="library"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.components.component.group" + value="org.example2"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.components.component.version" + value="1.2"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.components.component.purl" + value="pkg:maven/org.example2/[email protected]?type=jar"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.metadata.component.components.component(bom-ref)" + value="pkg:maven/org.example2/[email protected]?type=jar"/> + <au:assertResourceContains + xmlns:au="antlib:org.apache.ant.antunit" + resource="${output}/merged.xml" + value='<url>https://example.org/site</url>'/> + <au:assertResourceContains + xmlns:au="antlib:org.apache.ant.antunit" + resource="${output}/merged.xml" + value='<hash alg="SHA-256">${ant.file.sha256}</hash>'/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.dependencies.dependency(ref)" + value="my-own-dependency,pkg:maven/org.example2/[email protected]?type=jar"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.dependencies.dependency.dependency(ref)" + value="my-own-dependency"/> + </target> + + <target name="testReMappingOfLinkedDependencies"> + <cdx:componentbom + outputdirectory="${output}" + format="json" + xmlns:cdx="antlib:org.apache.ant.cyclonedx"> + <component + name="testname" + group="org.example" + version="1.0"> + <dependency bomRef="pkg:maven/commons-codec/[email protected]?type=jar"/> + </component> + <additionalComponent + name="commons-codec" + group="commons-codec" + version="1.21.0"/> + </cdx:componentbom> + <cdx:componentbom + outputdirectory="${output}" + bomName="merged" + format="xml" + xmlns:cdx="antlib:org.apache.ant.cyclonedx"> + <component> + <sbomLink> + <file file="${output}/bom.json"/> + </sbomLink> + </component> + <additionalComponent + name="commons-codec" + group="commons-codec" + version="1.22.0"/> + </cdx:componentbom> + <xmlproperty file="${output}/merged.xml"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.dependencies.dependency(ref)" + value="pkg:maven/commons-codec/[email protected]?type=jar,pkg:maven/org.example/[email protected]?type=jar"/> + <au:assertPropertyEquals + xmlns:au="antlib:org.apache.ant.antunit" + name="bom.dependencies.dependency.dependency(ref)" + value="pkg:maven/commons-codec/[email protected]?type=jar"/> + </target> +</project> diff --git a/src/tests/antunit/component-test.xml b/src/tests/antunit/component-test.xml index c98a9c0..75bd7c8 100644 --- a/src/tests/antunit/component-test.xml +++ b/src/tests/antunit/component-test.xml @@ -197,39 +197,6 @@ </cdx:componentbom> </target> - <target name="createMaximalComponentData" depends="setUp"> - <checksum property="ant.file.sha256" file="${ant.file}" algorithm="SHA-256"/> - <cdx:componentbom outputdirectory="${output}" format="all" - xmlns:cdx="antlib:org.apache.ant.cyclonedx"> - <component - name="testname" - group="org.example" - version="1.0" - description="My Test Library" - publisher="test publisher" - copyright="Copyright 2026 ACME Com" - mimeType="text/plain" - > - <file file="${ant.file}"/> - <manufacturer name="Example"> - <url url="https://example.org/"/> - </manufacturer> - <supplier name="Example 2"> - <url url="https://example.com/"/> - </supplier> - <license name="My License"/> - <externalReference type="WEBSITE" url="https://example.com/"/> - <component name="other-test" group="org.example" version="1.1" - unknownDependencies="true"/> - <author name="Author" email="[email protected]"/> - <tag>label</tag> - <property name="foo" value="bar"/> - <dependency bomRef="some-dependency"/> - </component> - <additionalComponent name="dep" bomRef="some-dependency"/> - </cdx:componentbom> - </target> - <target name="testMaximalComponentData" depends="createMaximalComponentData"> <xmlproperty file="${output}/bom.xml"/> <au:assertPropertyEquals @@ -792,447 +759,25 @@ <sbomLink/> </cdx:component> </au:expectfailure> - </target> - - <target name="testSbomLinkUsesDataFromLinkedSbom" depends="createMaximalComponentData"> - <cdx:componentbom - bomName="merged" - outputdirectory="${output}" - format="xml" - xmlns:cdx="antlib:org.apache.ant.cyclonedx"> - <component> - <sbomLink> - <file file="${output}/bom.json"/> - </sbomLink> - </component> - </cdx:componentbom> - <xmlproperty file="${output}/merged.xml"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.name" - value="testname"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component(type)" - value="library"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.group" - value="org.example"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.version" - value="1.0"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.publisher" - value="test publisher"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.copyright" - value="Copyright 2026 ACME Com"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component(mime-type)" - value="text/plain"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.purl" - value="pkg:maven/org.example/[email protected]?type=jar"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component(bom-ref)" - value="pkg:maven/org.example/[email protected]?type=jar"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.description" - value="My Test Library"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.authors.author.name" - value="Author"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.authors.author.email" - value="[email protected]"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.manufacturer.name" - value="Example"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.manufacturer.url" - value="https://example.org/"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.supplier.name" - value="Example 2"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.supplier.url" - value="https://example.com/"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.licenses.license.name" - value="My License"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.tags.tag" - value="label"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.properties.property(name)" - value="foo"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.properties.property" - value="bar"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.components.component.name" - value="other-test"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.components.component(type)" - value="library"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.components.component.group" - value="org.example"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.components.component.version" - value="1.1"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.components.component.purl" - value="pkg:maven/org.example/[email protected]?type=jar"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.components.component(bom-ref)" - value="pkg:maven/org.example/[email protected]?type=jar"/> - <au:assertResourceContains - xmlns:au="antlib:org.apache.ant.antunit" - resource="${output}/bom.xml" - value='<url>https://example.com/</url>'/> - <!-- some-dependency is not here as we explicitly set the its - dependencies to unknown. We don't want top open the can of - transitive dependency worms --> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.dependencies.dependency(ref)" - value="pkg:maven/org.example/[email protected]?type=jar"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.dependencies.dependency.dependency(ref)" - value="some-dependency"/> - <!-- ensure hashes are not taken from the linked SBOM --> - <au:assertResourceDoesntContain - xmlns:au="antlib:org.apache.ant.antunit" - resource="${output}/merged.xml" - value='<hash alg="SHA-256">${ant.file.sha256}</hash>'/> - </target> - - <target name="testSbomLinkAddsBomExternalLink" depends="createMaximalComponentData"> - <cdx:componentbom - bomName="merged" - outputdirectory="${output}" - format="xml" - xmlns:cdx="antlib:org.apache.ant.cyclonedx"> - <component> - <sbomLink> - <url url="https://repo1.maven.org/maven2/org/apache/ant/ant-cyclonedx/0.1/ant-cyclonedx-0.1-cyclonedx.json"/> - </sbomLink> - </component> - </cdx:componentbom> - <xmlproperty file="${output}/merged.xml"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.externalReferences.reference(type)" - value="vcs,issue-tracker,website,bom,mailing-list,source-distribution,distribution,license,build-system,security-contact"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.externalReferences.reference.url" - value="https://gitbox.apache.org/repos/asf/ant-antlibs-cyclonedx.git,https://bz.apache.org/bugzilla/buglist.cgi?component=CycloneDX%20Antlib&product=Ant,https://ant.apache.org/antlibs/cyclonedx/,https://repo1.maven.org/maven2/org/apache/ant/ant-cyclonedx/0.1/ant-cyclonedx-0.1-cyclonedx.json,https://ant.apache.org/mail.html,https://ant.apache.org/antlibs/srcdownload.cgi,https://ant.apache.org/antlibs/bindownload.cgi,https://www.apache.org/licenses/LICENSE-2.0.txt,https://ci-bu [...] - </target> - - <target name="testSbomLinkDoesntAddBomExternalLinkWhenDisabled" depends="createMaximalComponentData"> - <cdx:componentbom - bomName="merged" - outputdirectory="${output}" - format="xml" - xmlns:cdx="antlib:org.apache.ant.cyclonedx"> - <component> - <sbomLink createBomExternalReference="false"> - <url url="https://repo1.maven.org/maven2/org/apache/ant/ant-cyclonedx/0.1/ant-cyclonedx-0.1-cyclonedx.json"/> - </sbomLink> - </component> - </cdx:componentbom> - <xmlproperty file="${output}/merged.xml"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.externalReferences.reference(type)" - value="vcs,issue-tracker,website,mailing-list,source-distribution,distribution,license,build-system,security-contact"/> - </target> - - <target name="testSbomLinkDoesntOverrideExistingBomExternalLink" depends="createMaximalComponentData"> - <cdx:componentbom - bomName="merged" - outputdirectory="${output}" - format="xml" - xmlns:cdx="antlib:org.apache.ant.cyclonedx"> - <component> - <sbomLink> - <url url="https://repo1.maven.org/maven2/org/apache/ant/ant-cyclonedx/0.1/ant-cyclonedx-0.1-cyclonedx.json"/> - </sbomLink> - <externalReference type="bom" url="https://example.org/"/> - </component> - </cdx:componentbom> - <xmlproperty file="${output}/merged.xml"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.externalReferences.reference(type)" - value="bom"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.externalReferences.reference.url" - value="https://example.org/"/> - </target> - - <target - name="testSbomLinkDoesNotUseLinkedManufacturerIfSupplierIsManufacturer" - depends="createMaximalComponentData"> - <cdx:componentbom - bomName="merged" - outputdirectory="${output}" - format="xml" - xmlns:cdx="antlib:org.apache.ant.cyclonedx"> - <component supplierIsManufacturer="true"> - <sbomLink> - <file file="${output}/bom.json"/> - </sbomLink> - </component> - </cdx:componentbom> - <xmlproperty file="${output}/merged.xml"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.manufacturer.name" - value="Example 2"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.manufacturer.url" - value="https://example.com/"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.supplier.name" - value="Example 2"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.supplier.url" - value="https://example.com/"/> + <au:expectfailure + expectedMessage='You must not specify nested elements when using refid' + xmlns:au="antlib:org.apache.ant.antunit"> + <cdx:component refid="foo" + xmlns:cdx="antlib:org.apache.ant.cyclonedx"> + <ivymodule/> + </cdx:component> + </au:expectfailure> </target> <target - name="testDataFromLinkedSbomCanBeOverwrittenOrMerged" - depends="createMaximalComponentData"> - <cdx:componentbom - bomName="merged" - outputdirectory="${output}" - format="xml" - xmlns:cdx="antlib:org.apache.ant.cyclonedx"> - <component - type="APPLICATION" - name="testname2" - group="org.example2" - version="2.0" - description="My Second Test Library" - publisher="test2 publisher" - copyright="Copyright 2026 ACME Corp" - mimeType="text/xml" - > - <file file="${ant.file}"/> - <manufacturer name="Example 3"> - <url url="https://example.org/3"/> - </manufacturer> - <supplier name="Example 4"> - <url url="https://example.com/4"/> - </supplier> - <license name="My Other License"/> - <externalReference type="WEBSITE" url="https://example.org/site"/> - <component name="yet-another-test" group="org.example2" - version="1.2" unknownDependencies="true"/> - <author name="Author2" email="[email protected]"/> - <tag>label2</tag> - <property name="xyzzy" value="baz"/> - <dependency bomRef="my-own-dependency"/> - <sbomLink> - <file file="${output}/bom.json"/> - </sbomLink> - </component> - <additionalComponent name="my-own-dependency" bomRef="my-own-dependency"/> - </cdx:componentbom> - <xmlproperty file="${output}/merged.xml"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.name" - value="testname2"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component(type)" - value="application"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.group" - value="org.example2"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.version" - value="2.0"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.publisher" - value="test2 publisher"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.copyright" - value="Copyright 2026 ACME Corp"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component(mime-type)" - value="text/xml"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.purl" - value="pkg:maven/org.example2/[email protected]?type=jar"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component(bom-ref)" - value="pkg:maven/org.example2/[email protected]?type=jar"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.description" - value="My Second Test Library"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.authors.author.name" - value="Author2"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.authors.author.email" - value="[email protected]"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.manufacturer.name" - value="Example 3"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.manufacturer.url" - value="https://example.org/3"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.supplier.name" - value="Example 4"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.supplier.url" - value="https://example.com/4"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.licenses.license.name" - value="My Other License"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.tags.tag" - value="label,label2"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.properties.property(name)" - value="xyzzy"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.properties.property" - value="baz"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.components.component.name" - value="yet-another-test"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.components.component(type)" - value="library"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.components.component.group" - value="org.example2"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.components.component.version" - value="1.2"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.components.component.purl" - value="pkg:maven/org.example2/[email protected]?type=jar"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.metadata.component.components.component(bom-ref)" - value="pkg:maven/org.example2/[email protected]?type=jar"/> - <au:assertResourceContains - xmlns:au="antlib:org.apache.ant.antunit" - resource="${output}/merged.xml" - value='<url>https://example.org/site</url>'/> - <au:assertResourceContains - xmlns:au="antlib:org.apache.ant.antunit" - resource="${output}/merged.xml" - value='<hash alg="SHA-256">${ant.file.sha256}</hash>'/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.dependencies.dependency(ref)" - value="my-own-dependency,pkg:maven/org.example2/[email protected]?type=jar"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.dependencies.dependency.dependency(ref)" - value="my-own-dependency"/> - </target> - - <target name="testReMappingOfLinkedDependencies"> - <cdx:componentbom - outputdirectory="${output}" - format="json" - xmlns:cdx="antlib:org.apache.ant.cyclonedx"> - <component - name="testname" - group="org.example" - version="1.0"> - <dependency bomRef="pkg:maven/commons-codec/[email protected]?type=jar"/> - </component> - <additionalComponent - name="commons-codec" - group="commons-codec" - version="1.21.0"/> - </cdx:componentbom> - <cdx:componentbom - outputdirectory="${output}" - bomName="merged" - format="xml" - xmlns:cdx="antlib:org.apache.ant.cyclonedx"> - <component> - <sbomLink> - <file file="${output}/bom.json"/> - </sbomLink> - </component> - <additionalComponent - name="commons-codec" - group="commons-codec" - version="1.22.0"/> - </cdx:componentbom> - <xmlproperty file="${output}/merged.xml"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.dependencies.dependency(ref)" - value="pkg:maven/commons-codec/[email protected]?type=jar,pkg:maven/org.example/[email protected]?type=jar"/> - <au:assertPropertyEquals - xmlns:au="antlib:org.apache.ant.antunit" - name="bom.dependencies.dependency.dependency(ref)" - value="pkg:maven/commons-codec/[email protected]?type=jar"/> + name="testSbomLinkAndIvyModuleAreMutuallyExclusive"> + <au:expectfailure + expectedMessage='sbomLink and ivyModule are mutually exclusive' + xmlns:au="antlib:org.apache.ant.antunit"> + <cdx:component xmlns:cdx="antlib:org.apache.ant.cyclonedx"> + <sbomLink/> + <ivymodule/> + </cdx:component> + </au:expectfailure> </target> </project> diff --git a/src/tests/antunit/componentbom-test.xml b/src/tests/antunit/componentbom-test.xml index bc70ad7..2c8b99b 100644 --- a/src/tests/antunit/componentbom-test.xml +++ b/src/tests/antunit/componentbom-test.xml @@ -538,60 +538,4 @@ resource="${output}/bom.xml" value='<hash alg="SHA-256">${ant.file.sha256}</hash>'/> </target> - - <target name="testAntlibsOwnBom" depends="commonReferences"> - <cdx:componentbom - bomName="ant-cyclonedx-${artifact.version}-cyclonedx" - outputdirectory="${output}" - format="all" - useComponentSupplier="true" - useComponentManufacturer="true" - xmlns:cdx="antlib:org.apache.ant.cyclonedx"> - <component - name="ant-cyclonedx" - group="org.apache.ant" - version="${artifact.version}" - description="Apache CycloneDX Antlib" - publisher="The Apache Software Foundation" - supplierIsManufacturer="true"> - <file file="${antlib.location}"/> - <supplier refid="ant-team"/> - <license refid="apache-2"/> - <externalReferenceSet refid="antlib-ext-refs"/> - <dependency componentRef="ant"/> - <dependency componentRef="cyclonedx-core"/> - </component> - <additionalComponent - name="ant" - group="org.apache.ant" - version="1.10.17" - isExternal="true" - unknownDependencies="true" - id="ant"> - <manufacturer refid="ant-team"/> - <license refid="apache-2"/> - <externalReference - type="VCS" - url="https://github.com/apache/ant"/> - <externalReference - type="WEBSITE" - url="https://ant.apache.org/"/> - </additionalComponent> - <additionalComponent id="cyclonedx-core"> - <sbomLink> - <file file="resources/cyclonedx-core-java-12.2.0-cyclonedx.json"/> - </sbomLink> - </additionalComponent> - <license refid="apache-2"/> - </cdx:componentbom> - <au:assertFileExists - xmlns:au="antlib:org.apache.ant.antunit" - file="${output}/ant-cyclonedx-${artifact.version}-cyclonedx.json"/> - <au:assertFileExists - xmlns:au="antlib:org.apache.ant.antunit" - file="${output}/ant-cyclonedx-${artifact.version}-cyclonedx.xml"/> - <copy todir="${java.io.tmpdir}"> - <fileset dir="${output}" includes="ant-cyclonedx*"/> - </copy> - </target> </project> diff --git a/src/tests/antunit/shared.xml b/src/tests/antunit/shared.xml index 7b66bdd..78f21ec 100644 --- a/src/tests/antunit/shared.xml +++ b/src/tests/antunit/shared.xml @@ -76,4 +76,37 @@ </cdx:externalreferenceset> </target> + <target name="createMaximalComponentData" depends="setUp"> + <checksum property="ant.file.sha256" file="${ant.file}" algorithm="SHA-256"/> + <cdx:componentbom outputdirectory="${output}" format="all" + xmlns:cdx="antlib:org.apache.ant.cyclonedx"> + <component + name="testname" + group="org.example" + version="1.0" + description="My Test Library" + publisher="test publisher" + copyright="Copyright 2026 ACME Com" + mimeType="text/plain" + > + <file file="${ant.file}"/> + <manufacturer name="Example"> + <url url="https://example.org/"/> + </manufacturer> + <supplier name="Example 2"> + <url url="https://example.com/"/> + </supplier> + <license name="My License"/> + <externalReference type="WEBSITE" url="https://example.com/"/> + <component name="other-test" group="org.example" version="1.1" + unknownDependencies="true"/> + <author name="Author" email="[email protected]"/> + <tag>label</tag> + <property name="foo" value="bar"/> + <dependency bomRef="some-dependency"/> + </component> + <additionalComponent name="dep" bomRef="some-dependency"/> + </cdx:componentbom> + </target> + </project>
