Skip to content

Add missing CycloneDX 1.7 crypto primitive and protocol types - #951

Open
xnox wants to merge 1 commit into
CycloneDX:masterfrom
xnox:add-missing-1.7-crypto-enums
Open

xnox wants to merge 1 commit into
CycloneDX:masterfrom
xnox:add-missing-1.7-crypto-enums

Conversation

@xnox

@xnox xnox commented Oct 6, 2026

Copy link
Copy Markdown

CycloneDX 1.7 added the key-wrap algorithm primitive and six protocol types (dtls, quic, eap-aka, eap-aka-prime, prins, 5g-aka). The Primitive and ProtocolType enums were never updated, even though the bundled bom-1.7.schema.json and bom-1.7.xsd already accept these values. A 1.7 BOM that uses any of them passes validation and then fails to parse:

org.cyclonedx.exception.ParseException: Unable to parse BOM from byte array
Caused by: com.fasterxml.jackson.databind.exc.InvalidFormatException: Cannot deserialize value of type
`org.cyclonedx.model.component.crypto.enums.Primitive` from String "key-wrap": not one of the values accepted for Enum class: [...]

We hit this importing a real CBOM, generated from OpenSSL runtime probes, into Dependency-Track 5.1.1, which uses 13.2.0. The CBOM lists AES-*-KW algorithms as key-wrap.

Changes

  • Primitive: add KEY_WRAP.
  • ProtocolType: add DTLS, QUIC, EAP_AKA, EAP_AKA_PRIME, PRINS and FIVE_G_AKA. Descriptions are taken from the schema's meta:enum.
  • Constants follow the schema's order.
  • New fixtures 1.7/valid-cryptography-enums-1.7.{json,xml} use each new value. schema17_cbom_enums in JsonParserTest and XmlParserTest asserts each value is parsed. The existing schema verification and parse/generate tests also pick up the fixtures, which confirms they are valid against the 1.7 JSON schema and XSD.

mvn test: 1649 tests, 0 failures.

Related gaps, not fixed here

Comparing every enum against bom-1.7.schema.json turned up two more enums missing values that also fail parsing. They aren't crypto-related, so I've left them for a separate change:

  • ComponentData.ComponentDataType lacks definition (in the schema since 1.5)
  • Identity.Field lacks omniborId and swhid (in the schema since 1.6)

🤖 Generated with Claude Code

CycloneDX 1.7 added the "key-wrap" algorithm primitive and the "dtls",
"quic", "eap-aka", "eap-aka-prime", "prins" and "5g-aka" protocol types,
but the Primitive and ProtocolType enums were not updated. The bundled
1.7 JSON schema and XSD already accept these values, so a BOM using any
of them passes validation and then fails to parse:

  Cannot deserialize value of type `...crypto.enums.Primitive` from
  String "key-wrap": not one of the values accepted for Enum class

Add the missing constants, in schema order, along with JSON and XML
fixtures that exercise each new value. The fixtures are also picked up
by the existing schema verification and round-trip tests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Dimitri John Ledkov <dimitri.ledkov@surgut.co.uk>
@xnox
xnox requested a review from a team as a code owner October 6, 2026 10:19
@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity

Metric Results
Complexity 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@jaooli-cyber

Copy link
Copy Markdown

Hi,

Reviewing the 1.7 schema alongside the Java 13.2.0 enum confirms the mismatch: key-wrap is schema-valid but absent from the Java model.

We work on CBOM interoperability and semantic fidelity. We could independently check the existing JSON/XML fixtures against the released library and this patch, including whether the added primitive and protocol values survive parsing and re-serialization unchanged.

That would complement the tests already included here. We would keep the scope to the library; successful Dependency-Track import and retention would need separate verification.

JAO

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants