Skip to content

Investigate SBOM Irreproducibility in log4j-bom #3804

Open
@ppkarwasz

Description

@ppkarwasz

Since version 2.25.0, the aggregated SBOM generated for the log4j-bom artifact is not reproducible. Specifically, two variants of the SBOM are occasionally produced, differing only in the ordering of the jspecify dependency.

To ensure full reproducibility across releases, we need to identify the root cause of this nondeterministic behavior and propose a solution to resolve it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    Status

    To triage

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions