Procurement asks for a software bill of materials. Security asks which bundle carries a vulnerable library. Both questions have the same answer, and it is now generated rather than compiled by hand.
The inventory
- One task A Gradle task writes a CSV beside the third-party notices file, one row per artifact with the bundle it ships in and its licence.
- Everything that ships The main classpath plus the four side-loaded sets: the cryptography provider, the AWS, Microsoft and Google client libraries.
- Nothing that does not The report is scoped to the shipping project; test-only artifacts from sibling projects had been polluting it.
Built on
- The licence report plugin added a year earlier with custom renderers; the rework changed the notices file by 49,000 insertions and 36,000 deletions.
A buyer's security questionnaire has a line for this. It can now be answered from the build.