chore: keep Spring Boot starter dependencies out of the SBOM - #9517
Open
totally-not-ai[bot] wants to merge 1 commit into
Open
totally-not-ai[bot] wants to merge 1 commit into
totally-not-ai[bot] wants to merge 1 commit into
Conversation
List vaadin-spring in the platform and core SBOM modules instead of vaadin-spring-boot-starter. The starter brings spring-boot-starter-webmvc with embedded Tomcat, whose versions are chosen by the application's Spring Boot version and are not Vaadin components.
Contributor
Dependencies Report
|
Artur-
marked this pull request as ready for review
September 25, 2026 13:46
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The platform and core SBOM modules (
vaadin-platform-sbom,vaadin-core-sbom) now listcom.vaadin:vaadin-springinstead ofcom.vaadin:vaadin-spring-boot-starter.Why
vaadin-spring-boot-starterdepends onorg.springframework.boot:spring-boot-starter-webmvcat compile scope. That brings Spring Boot's web stack and embedded Tomcat into the published SBOM (Software.Bill.Of.Materials.jsonon releases). The application's Spring Boot version picks those versions, not Vaadin, so they should not be reported as Vaadin components. The Vaadin integration itself (vaadin-spring) stays in the SBOM. It is now listed directly because nothing else invaadin-core-sbombrings it in.Effect on the SBOM
25.4-SNAPSHOT,mvn dependency:treeon the SBOM modules shows:vaadin-core-sbom: Spring/Tomcat artifacts go from 24 to 0.vaadin-platform-sbom: they go from 38 to 24, and no Tomcat orspring-boot-starter-webmvcartifacts are left. The rest come from the Vaadin kit starters (SSO, Observability).com.vaadin:vaadin-springis still resolved in both modules.No changes to
scripts/generateAndCheckSBOM.jsor.github/workflows/sbom.yml. Neither one refers to the starter, Spring or Tomcat.Related
vaadin-spring's own Spring dependencies provided/optional.🤖 Generated with Claude Code