From d62d61581ca35f0798acaff93c688122652fb531 Mon Sep 17 00:00:00 2001 From: Moritz Halbritter Date: Wed, 29 May 2024 10:15:06 +0200 Subject: [PATCH] Add resource hints for SBOM endpoint --- .../boot/actuate/sbom/SbomEndpoint.java | 20 +++++++++++++++++++ .../boot/actuate/sbom/SbomEndpointTests.java | 11 ++++++++++ 2 files changed, 31 insertions(+) diff --git a/spring-boot-project/spring-boot-actuator/src/main/java/org/springframework/boot/actuate/sbom/SbomEndpoint.java b/spring-boot-project/spring-boot-actuator/src/main/java/org/springframework/boot/actuate/sbom/SbomEndpoint.java index 5708afba84a8..503e667f72ac 100644 --- a/spring-boot-project/spring-boot-actuator/src/main/java/org/springframework/boot/actuate/sbom/SbomEndpoint.java +++ b/spring-boot-project/spring-boot-actuator/src/main/java/org/springframework/boot/actuate/sbom/SbomEndpoint.java @@ -23,10 +23,14 @@ import java.util.Map; import java.util.TreeSet; +import org.springframework.aot.hint.RuntimeHints; +import org.springframework.aot.hint.RuntimeHintsRegistrar; import org.springframework.boot.actuate.endpoint.OperationResponseBody; import org.springframework.boot.actuate.endpoint.annotation.Endpoint; import org.springframework.boot.actuate.endpoint.annotation.ReadOperation; import org.springframework.boot.actuate.endpoint.annotation.Selector; +import org.springframework.boot.actuate.sbom.SbomEndpoint.SbomEndpointRuntimeHints; +import org.springframework.context.annotation.ImportRuntimeHints; import org.springframework.core.io.Resource; import org.springframework.core.io.ResourceLoader; import org.springframework.util.StringUtils; @@ -38,6 +42,7 @@ * @since 3.3.0 */ @Endpoint(id = "sbom") +@ImportRuntimeHints(SbomEndpointRuntimeHints.class) public class SbomEndpoint { private static final List DEFAULT_APPLICATION_SBOM_LOCATIONS = List.of("classpath:META-INF/sbom/bom.json", @@ -141,4 +146,19 @@ private static String stripOptionalPrefix(String location) { } } + static class SbomEndpointRuntimeHints implements RuntimeHintsRegistrar { + + @Override + public void registerHints(RuntimeHints hints, ClassLoader classLoader) { + for (String defaultLocation : DEFAULT_APPLICATION_SBOM_LOCATIONS) { + hints.resources().registerPattern(stripClasspathPrefix(defaultLocation)); + } + } + + private String stripClasspathPrefix(String location) { + return location.substring("classpath:".length()); + } + + } + } diff --git a/spring-boot-project/spring-boot-actuator/src/test/java/org/springframework/boot/actuate/sbom/SbomEndpointTests.java b/spring-boot-project/spring-boot-actuator/src/test/java/org/springframework/boot/actuate/sbom/SbomEndpointTests.java index 21db6474c2b0..f4c724d69031 100644 --- a/spring-boot-project/spring-boot-actuator/src/test/java/org/springframework/boot/actuate/sbom/SbomEndpointTests.java +++ b/spring-boot-project/spring-boot-actuator/src/test/java/org/springframework/boot/actuate/sbom/SbomEndpointTests.java @@ -22,6 +22,9 @@ import org.junit.jupiter.api.BeforeEach; import org.junit.jupiter.api.Test; +import org.springframework.aot.hint.RuntimeHints; +import org.springframework.aot.hint.predicate.RuntimeHintsPredicates; +import org.springframework.boot.actuate.sbom.SbomEndpoint.SbomEndpointRuntimeHints; import org.springframework.boot.actuate.sbom.SbomEndpoint.Sboms; import org.springframework.boot.actuate.sbom.SbomProperties.Sbom; import org.springframework.context.support.GenericApplicationContext; @@ -81,6 +84,14 @@ void shouldNotFailIfNonExistingOptionalLocationIsGiven() { assertThat(createEndpoint().sbom("application")).isNull(); } + @Test + void shouldRegisterHints() { + RuntimeHints hints = new RuntimeHints(); + new SbomEndpointRuntimeHints().registerHints(hints, getClass().getClassLoader()); + assertThat(RuntimeHintsPredicates.resource().forResource("META-INF/sbom/bom.json")).accepts(hints); + assertThat(RuntimeHintsPredicates.resource().forResource("META-INF/sbom/application.cdx.json")).accepts(hints); + } + private Sbom sbom(String location) { Sbom result = new Sbom(); result.setLocation(location);