Repository navigation
Conversation
CycloneDX 1.7 added the "key-wrap" algorithm primitive and the "dtls", "quic", "eap-aka", "eap-aka-prime", "prins" and "5g-aka" protocol types, but the Primitive and ProtocolType enums were not updated. The bundled 1.7 JSON schema and XSD already accept these values, so a BOM using any of them passes validation and then fails to parse: Cannot deserialize value of type `...crypto.enums.Primitive` from String "key-wrap": not one of the values accepted for Enum class Add the missing constants, in schema order, along with JSON and XML fixtures that exercise each new value. The fixtures are also picked up by the existing schema verification and round-trip tests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Dimitri John Ledkov <dimitri.ledkov@surgut.co.uk>
Up to standards ✅🟢 Issues
|
| Metric | Results |
|---|---|
| Complexity | 0 |
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
|
Hi, Reviewing the 1.7 schema alongside the Java 13.2.0 enum confirms the mismatch: key-wrap is schema-valid but absent from the Java model. We work on CBOM interoperability and semantic fidelity. We could independently check the existing JSON/XML fixtures against the released library and this patch, including whether the added primitive and protocol values survive parsing and re-serialization unchanged. That would complement the tests already included here. We would keep the scope to the library; successful Dependency-Track import and retention would need separate verification. JAO |
CycloneDX 1.7 added the
key-wrapalgorithm primitive and six protocol types (dtls,quic,eap-aka,eap-aka-prime,prins,5g-aka). ThePrimitiveandProtocolTypeenums were never updated, even though the bundledbom-1.7.schema.jsonandbom-1.7.xsdalready accept these values. A 1.7 BOM that uses any of them passes validation and then fails to parse:We hit this importing a real CBOM, generated from OpenSSL runtime probes, into Dependency-Track 5.1.1, which uses 13.2.0. The CBOM lists
AES-*-KWalgorithms askey-wrap.Changes
Primitive: addKEY_WRAP.ProtocolType: addDTLS,QUIC,EAP_AKA,EAP_AKA_PRIME,PRINSandFIVE_G_AKA. Descriptions are taken from the schema'smeta:enum.1.7/valid-cryptography-enums-1.7.{json,xml}use each new value.schema17_cbom_enumsinJsonParserTestandXmlParserTestasserts each value is parsed. The existing schema verification and parse/generate tests also pick up the fixtures, which confirms they are valid against the 1.7 JSON schema and XSD.mvn test: 1649 tests, 0 failures.Related gaps, not fixed here
Comparing every enum against
bom-1.7.schema.jsonturned up two more enums missing values that also fail parsing. They aren't crypto-related, so I've left them for a separate change:ComponentData.ComponentDataTypelacksdefinition(in the schema since 1.5)Identity.FieldlacksomniborIdandswhid(in the schema since 1.6)🤖 Generated with Claude Code