Skip to content

fix: use fully-qualified GAV for cyclonedx-maven-plugin - #10

Merged
emmanuelbruno merged 2 commits into
mainfrom
fix/sbom-plugin-gav
Oct 3, 2026
Merged

emmanuelbruno merged 2 commits into
mainfrom
fix/sbom-plugin-gav

Conversation

@emmanuelbruno

Copy link
Copy Markdown
Contributor

Nexus proxy returns HTTP 500 on plugin-group maven-metadata.xml, making prefix resolution fail. Same fix as archetype-plugin GAV.

  • Replaces cyclonedx:makeBom with org.cyclonedx:cyclonedx-maven-plugin:2.9.1:makeBom

Nexus proxy returns 500 on plugin-group maven-metadata.xml,
making prefix resolution (cyclonedx:makeBom) fail. Use
fully-qualified coordinates instead.
Nexus proxy returns 500 on plugin-group maven-metadata.xml,
making prefix resolution (cyclonedx:makeBom) fail. Use
fully-qualified coordinates instead.
Copilot AI balanced review requested due to automatic review settings October 3, 2026 12:39

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The fully qualified Maven plugin invocation is valid and directly addresses the reported prefix-resolution failure.

Review effort: Balanced
Findings: None

What changed in this PR

Uses the CycloneDX plugin’s fully qualified coordinates to bypass Maven prefix-resolution failures through Nexus.

Changes:

  • Replaces cyclonedx:makeBom with the pinned plugin GAV and goal.
File Description
.github/​workflows/​security.yml Updates SBOM generation to invoke CycloneDX directly.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@emmanuelbruno
emmanuelbruno merged commit 60cf663 into main Oct 3, 2026
10 checks passed
@emmanuelbruno
emmanuelbruno deleted the fix/sbom-plugin-gav branch October 3, 2026 13:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants