sbom_validator_job
Started by upstream project "build-scripts/jobs/jdk21u/jdk21u-windows-aarch64-temurin" build number 123
originally caused by:
Started by upstream project "build-scripts/openjdk21-pipeline" build number 458
originally caused by:
Started by upstream project "build-scripts/utils/betaTrigger_21ea" build number 456
originally caused by:
Started by timer
Running as SYSTEM
Building remotely on jenkins-hetzner-worker (jsfsignX x64 git-hg gpgsign worker master) in workspace /home/jenkins/workspace/sbom_validator_job
[WS-CLEANUP] Deleting project workspace...
[WS-CLEANUP] Deferred wipeout is used...
The recommended git tool is: git
No credentials specified
Cloning the remote Git repository
Cloning repository https://github.com/adoptium/temurin-build
> git init /home/jenkins/workspace/sbom_validator_job/temurin-build # timeout=10
Fetching upstream changes from https://github.com/adoptium/temurin-build
> git --version # timeout=10
> git --version # 'git version 2.43.0'
> git fetch --tags --force --progress -- https://github.com/adoptium/temurin-build +refs/heads/*:refs/remotes/origin/* # timeout=10
> git config remote.origin.url https://github.com/adoptium/temurin-build # timeout=10
> git config --add remote.origin.fetch +refs/heads/*:refs/remotes/origin/* # timeout=10
Avoid second fetch
> git rev-parse refs/remotes/origin/master^{commit} # timeout=10
Checking out Revision a73dd1f61b103c053cc94ec5649f3fcccd95558a (refs/remotes/origin/master)
> git config core.sparsecheckout # timeout=10
> git checkout -f a73dd1f61b103c053cc94ec5649f3fcccd95558a # timeout=10
Commit message: "Disable PCH for Temurin jdk-21+ for consistent reproducible linux builds (#4431)"
> git rev-list --no-walk a73dd1f61b103c053cc94ec5649f3fcccd95558a # timeout=10
Copied 2 artifacts from "build-scripts » jobs » jdk21u » jdk21u-windows-aarch64-temurin" build number 123
[sbom_validator_job] $ /bin/sh -xe /tmp/jenkins16680377138589576027.sh
+ ls /home/jenkins/workspace/sbom_validator_job/sboms
OpenJDK21U-sbom_aarch64_windows_hotspot_21.0.11_9-ea.json
OpenJDK21U-sbom_aarch64_windows_hotspot_21.0.11_9-ea-metadata.json
+ + grep -v metadata
ls -1 /home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK21U-sbom_aarch64_windows_hotspot_21.0.11_9-ea-metadata.json /home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK21U-sbom_aarch64_windows_hotspot_21.0.11_9-ea.json
+ sh /home/jenkins/workspace/sbom_validator_job/temurin-build/tooling/validateSBOM.sh 21 jdk-21.0.11+9_adopt /home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK21U-sbom_aarch64_windows_hotspot_21.0.11_9-ea.json
validateSBOM.sh: Setting up workspace directory /home/jenkins/workspace/sbom_validator_job/sbom_validation
JDK_MAJOR_VERSION='21'
SOURCE_TAG='jdk-21.0.11+9_adopt'
SBOM_LOCATION='/home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK21U-sbom_aarch64_windows_hotspot_21.0.11_9-ea.json'
validateSBOM.sh: Downloading CycloneDX CLI binary ...
validateSBOM.sh: Downloaded CycloneDX CLI binary to 'cyclonedx-linux-x64'
validateSBOM.sh: SBOM validation start.
validateSBOM.sh: Running general SBOM validation from https://github.com/CycloneDX/cyclonedx-cli
validateSBOM.sh: Running cyclonedx-linux-x64 ...
Command: "/home/jenkins/workspace/sbom_validator_job/sbom_validation/cyclonedx-linux-x64" validate --input-file "/home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK21U-sbom_aarch64_windows_hotspot_21.0.11_9-ea.json" --input-format json
BOM validated successfully.
validateSBOM.sh: Passed CycloneDX validation check.
validateSBOM.sh: Running command: sh validateSBOMcontent.sh "/home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK21U-sbom_aarch64_windows_hotspot_21.0.11_9-ea.json" "21" "jdk-21.0.11+9_adopt"
SBOMFILE='/home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK21U-sbom_aarch64_windows_hotspot_21.0.11_9-ea.json'
MAJORVERSION='21'
EXPECTED_SCM_REF='jdk-21.0.11+9_adopt'
/home/jenkins/workspace/sbom_validator_job/sboms/OpenJDK21U-sbom_aarch64_windows_hotspot_21.0.11_9-ea.json
BOOTJDK is 21.0.8+9-LTS
FREETYPE is 2.14.2
Checking for JDK source SHA validity...
2a2ccaf55dbb193ebd6b27a0ae68ae58d925c124 refs/heads/release
2a2ccaf55dbb193ebd6b27a0ae68ae58d925c124 refs/tags/jdk-21.0.11+9_adopt^{}
SBOM SHA is a valid repository tag commit SHA: 2a2ccaf55dbb193ebd6b27a0ae68ae58d925c124
Checking for temurin-build SHA validity: Checking for temurin-build SHA a73dd1f61b103c053cc94ec5649f3fcccd95558a in https://github.com/adoptium/temurin-build
a73dd1f61b103c053cc94ec5649f3fcccd95558a HEAD
a73dd1f61b103c053cc94ec5649f3fcccd95558a refs/heads/master
validateSBOMcontent.sh: PASSED
SBOM validation complete.
validateSBOM.sh: SBOM validation complete.
[WS-CLEANUP] Deleting project workspace...
[WS-CLEANUP] Deferred wipeout is used...
[WS-CLEANUP] done
Finished: SUCCESS