Skip to content

Investigate SBOM Irreproducibility in log4j-bom #3804

@ppkarwasz

Description

@ppkarwasz

Since version 2.25.0, the aggregated SBOM generated for the log4j-bom artifact is not reproducible. Specifically, two variants of the SBOM are occasionally produced, differing only in the ordering of the jspecify dependency.

To ensure full reproducibility across releases, we need to identify the root cause of this nondeterministic behavior and propose a solution to resolve it.

Metadata

Metadata

Labels

No labels
No labels

Type

Projects

Status

Done

Relationships

None yet

Development

No branches or pull requests

Issue actions