sbom_validator_job

Started by upstream project "build-scripts/jobs/jdk17u/jdk17u-linux-x64-temurin" build number 680 originally caused by: Started by upstream project "build-scripts/openjdk17-pipeline" build number 1021 originally caused by: Started by upstream project "build-scripts/utils/betaTrigger_17ea" build number 494 originally caused by: Started by timer Running as SYSTEM Building remotely on jenkins-hetzner-worker (jsfsignX x64 git-hg gpgsign worker master) in workspace /home/jenkins/workspace/sbom_validator_job [WS-CLEANUP] Deleting project workspace... [WS-CLEANUP] Deferred wipeout is used... The recommended git tool is: git No credentials specified Cloning the remote Git repository Cloning repository https://github.com/adoptium/temurin-build > git init /home/jenkins/workspace/sbom_validator_job/temurin-build # timeout=10 Fetching upstream changes from https://github.com/adoptium/temurin-build > git --version # timeout=10 > git --version # 'git version 2.43.0' > git fetch --tags --force --progress -- https://github.com/adoptium/temurin-build +refs/heads/*:refs/remotes/origin/* # timeout=10 > git config remote.origin.url https://github.com/adoptium/temurin-build # timeout=10 > git config --add remote.origin.fetch +refs/heads/*:refs/remotes/origin/* # timeout=10 Avoid second fetch > git rev-parse refs/remotes/origin/master^{commit} # timeout=10 Checking out Revision add4c7da67f6165313c0cfb4783b823be7ba0d6f (refs/remotes/origin/master) > git config core.sparsecheckout # timeout=10 > git checkout -f add4c7da67f6165313c0cfb4783b823be7ba0d6f # timeout=10 Commit message: "Update linux_repro_build_compare.sh to support Attestation verify build (#4384)" > git rev-list --no-walk add4c7da67f6165313c0cfb4783b823be7ba0d6f # timeout=10 Copied 2 artifacts from "build-scripts » jobs » jdk17u » jdk17u-linux-x64-temurin" build number 680 [sbom_validator_job] $ /bin/sh -xe /tmp/jenkins1047822170248758088.sh + ls /home/jenkins/workspace/sbom_validator_job/sboms OpenJDK17U-sbom_x64_linux_hotspot_17.0.19_5-ea.json OpenJDK17U-sbom_x64_linux_hotspot_17.0.19_5-ea-metadata.json + ls -1 /home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK17U-sbom_x64_linux_hotspot_17.0.19_5-ea-metadata.json /home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK17U-sbom_x64_linux_hotspot_17.0.19_5-ea.json + grep -v metadata + sh /home/jenkins/workspace/sbom_validator_job/temurin-build/tooling/validateSBOM.sh 17 jdk-17.0.19+5_adopt /home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK17U-sbom_x64_linux_hotspot_17.0.19_5-ea.json validateSBOM.sh: Setting up workspace directory /home/jenkins/workspace/sbom_validator_job/sbom_validation JDK_MAJOR_VERSION='17' SOURCE_TAG='jdk-17.0.19+5_adopt' SBOM_LOCATION='/home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK17U-sbom_x64_linux_hotspot_17.0.19_5-ea.json' validateSBOM.sh: Downloading CycloneDX CLI binary ... validateSBOM.sh: Downloaded CycloneDX CLI binary to 'cyclonedx-linux-x64' validateSBOM.sh: SBOM validation start. validateSBOM.sh: Running general SBOM validation from https://github.com/CycloneDX/cyclonedx-cli validateSBOM.sh: Running cyclonedx-linux-x64 ... Command: "/home/jenkins/workspace/sbom_validator_job/sbom_validation/cyclonedx-linux-x64" validate --input-file "/home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK17U-sbom_x64_linux_hotspot_17.0.19_5-ea.json" --input-format json BOM validated successfully. validateSBOM.sh: Passed CycloneDX validation check. validateSBOM.sh: Running command: sh validateSBOMcontent.sh "/home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK17U-sbom_x64_linux_hotspot_17.0.19_5-ea.json" "17" "jdk-17.0.19+5_adopt" SBOMFILE='/home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK17U-sbom_x64_linux_hotspot_17.0.19_5-ea.json' MAJORVERSION='17' EXPECTED_SCM_REF='jdk-17.0.19+5_adopt' /home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK17U-sbom_x64_linux_hotspot_17.0.19_5-ea.json /home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK17U-sbom_x64_linux_hotspot_17.0.19_5-ea.json BOOTJDK is 17.0.18+8 NOTE: ALSA version not 1.1.8 (SBOM has 1.1.6) - ignoring because ALSA version is determined by devkit now FREETYPE is 2.13.3 Checking for JDK source SHA validity... d03697478b2cf3e040444f5e11816c3fa52a328d refs/heads/release d03697478b2cf3e040444f5e11816c3fa52a328d refs/tags/jdk-17.0.19+5_adopt^{} SBOM SHA is a valid repository tag commit SHA: d03697478b2cf3e040444f5e11816c3fa52a328d Checking for temurin-build SHA validity: Checking for temurin-build SHA add4c7da67f6165313c0cfb4783b823be7ba0d6f in https://github.com/adoptium/temurin-build add4c7da67f6165313c0cfb4783b823be7ba0d6f HEAD add4c7da67f6165313c0cfb4783b823be7ba0d6f refs/heads/master validateSBOMcontent.sh: PASSED SBOM validation complete. validateSBOM.sh: SBOM validation complete. [WS-CLEANUP] Deleting project workspace... [WS-CLEANUP] Deferred wipeout is used... [WS-CLEANUP] done Finished: SUCCESS