Skip to content

Commit

Permalink
Disable dependency verification during each task when resolving as pa…
Browse files Browse the repository at this point in the history
…rt of SBOM generation.

Signed-off-by: Kenneth J. Shackleton <[email protected]>
  • Loading branch information
kennethshackleton committed Oct 21, 2024
1 parent 7339718 commit b21a4dd
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 0 deletions.
1 change: 1 addition & 0 deletions src/main/java/org/cyclonedx/gradle/CycloneDxTask.java
Original file line number Diff line number Diff line change
Expand Up @@ -547,6 +547,7 @@ private Map<String, org.cyclonedx.model.Dependency> buildDependencyGraph(
}
final Dependency pomDep = getProject().getDependencies().create(dependencyName + "@pom");
final Configuration pomCfg = getProject().getConfigurations().detachedConfiguration(pomDep);
pomCfg.getResolutionStrategy().disableDependencyVerification();

try {
@Nullable final File pomFile = pomCfg.resolve().stream().findFirst().orElse(null);
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,7 @@ public ModelSource2 resolveModel(String groupId, String artifactId, String versi
org.gradle.api.artifacts.Dependency dependency =
project.getDependencies().create(depNotation);
Configuration config = project.getConfigurations().detachedConfiguration(dependency);
config.getResolutionStrategy().disableDependencyVerification();

File pomXml = config.getSingleFile();
return new ModelSource2() {
Expand Down

0 comments on commit b21a4dd

Please sign in to comment.