Skip to content

chore: keep Spring Boot starter dependencies out of the SBOM - #9517

Open
totally-not-ai[bot] wants to merge 1 commit into
mainfrom
chore/sbom-exclude-spring-boot-starter
Open

totally-not-ai[bot] wants to merge 1 commit into
mainfrom
chore/sbom-exclude-spring-boot-starter

Conversation

@totally-not-ai

Copy link
Copy Markdown
Contributor

Summary

The platform and core SBOM modules (vaadin-platform-sbom, vaadin-core-sbom) now list com.vaadin:vaadin-spring instead of com.vaadin:vaadin-spring-boot-starter.

Why

vaadin-spring-boot-starter depends on org.springframework.boot:spring-boot-starter-webmvc at compile scope. That brings Spring Boot's web stack and embedded Tomcat into the published SBOM (Software.Bill.Of.Materials.json on releases). The application's Spring Boot version picks those versions, not Vaadin, so they should not be reported as Vaadin components. The Vaadin integration itself (vaadin-spring) stays in the SBOM. It is now listed directly because nothing else in vaadin-core-sbom brings it in.

Effect on the SBOM

  • In the 25.3.0 SBOM, dropping the starter removes all 6 Tomcat components and 10 of the 35 Spring components.
  • On the current 25.4-SNAPSHOT, mvn dependency:tree on the SBOM modules shows:
    • vaadin-core-sbom: Spring/Tomcat artifacts go from 24 to 0.
    • vaadin-platform-sbom: they go from 38 to 24, and no Tomcat or spring-boot-starter-webmvc artifacts are left. The rest come from the Vaadin kit starters (SSO, Observability).
  • com.vaadin:vaadin-spring is still resolved in both modules.

No changes to scripts/generateAndCheckSBOM.js or .github/workflows/sbom.yml. Neither one refers to the starter, Spring or Tomcat.

Related

🤖 Generated with Claude Code

List vaadin-spring in the platform and core SBOM modules instead of
vaadin-spring-boot-starter. The starter brings spring-boot-starter-webmvc
with embedded Tomcat, whose versions are chosen by the application's
Spring Boot version and are not Vaadin components.
@github-actions

Copy link
Copy Markdown
Contributor

Dependencies Report

  • 🟠 Known Vulnerabilities:

    • Vulnerabilities in: pkg:maven/me.friwi/jcef-api@jcef-ca49ada%2Bcef-135.0.20%2Bge7de5c3%2Bchromium-135.0.7049.85 [CVE-2024-21639, CVE-2024-21640, CVE-2024-9410] (owasp)
      👌 Wait for the update from the jcefmaven community. Meanwhile the swing-kit is supposed to be used with fixed websites and not to browse the internet, we have a check for that, so the only possible attacker would be the same person that created the swing application, aka our customer devs. so this vulnerability is not classified by us as critical issue
      · cpe:2.3:a:chromiumembedded:chromium_embedded_framework::::::::
      · cpe:2.3:a:ada:ada::::::::
    • Vulnerabilities in: pkg:maven/io.opentelemetry/opentelemetry-api@1.65.0 [CVE-2026-54285] (owasp)
      👌 False positive: the advisory is for opentelemetry-js (@opentelemetry/core W3CBaggagePropagator.extract(), fixed in JS 2.8.0) and its only CPE targets node.js. io.opentelemetry is opentelemetry-java, an unrelated codebase on its own 1.x line, so the version range matches only by CPE collision; osv-scanner and ossindex report nothing for this coordinate. It reaches the sbom transitively through selenium-remote-driver under vaadin-testbench, a test only dependency.
      · cpe:2.3:a:opentelemetry:opentelemetry::::::node.js::*
    • Vulnerabilities in: pkg:maven/com.vaadin/vaadin-swing-kit-flow@3.0.1 [CVE-2021-33604] (owasp)
      👌 false report: this CVE is targeting Vaadin version prior 20, swing-kit-flow is using vaadin 24+ version, the related issue has been fixed.
      · cpe:2.3:a:vaadin:flow-server::::::::
      · cpe:2.3:a:vaadin:vaadin::::::::
  • 📔 No Core License Issues

  • 📔 No License Issues

  • 🟠 Changes in 25.4-SNAPSHOT since V25.3.0-rc1

    • 14 packages removed (13 external, 1 vaadin)
    • 1 packages added (1 external, 0 vaadin)
    • 242 packages modified (17 external, 225 vaadin)
    • 392 packages same (376 external, 16 vaadin)

[Click for more Details]

@Artur-
Artur- marked this pull request as ready for review September 25, 2026 13:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants