A CycloneDX 1.5 BOM whose metadata → tools → components component carries a pedigree with commits/commit cannot be deserialized from XML. XmlParser.parse() throws while mapping
Pedigree.commits. The same document deserializes fine as JSON, and the same pedigree/commit on a top-level component deserializes fine from XML — so this is specific to the XML +
tools-component code path. The library will happily serialize this structure but then cannot read its own output, breaking round-tripping.
Version
org.cyclonedx:cyclonedx-core-java:13.2.0 (latest on Maven Central). Runtime: jackson-databind/jackson-dataformat-xml 2.22.2, woodstox-core 7.2.0.
Minimal reproduction
Parse the following (minimal — everything non-essential removed) with new XmlParser().parse(bytes):
<?xml version="1.0" encoding="UTF-8"?>
<bom xmlns="http://cyclonedx.org/schema/bom/1.5">
<metadata>
<tools>
<components>
<component type="application">
<name>t</name>
<pedigree>
<commits>
<commit>
<uid>u</uid>
</commit>
</commits>
</pedigree>
</component>
</components>
</tools>
</metadata>
</bom>
Code to reproduce
byte[] xml = Files.readAllBytes(Path.of("trigger.xml"));
new org.cyclonedx.parsers.XmlParser().parse(xml); // throws
Stack tracke:
org.cyclonedx.exception.ParseException: com.fasterxml.jackson.databind.JsonMappingException:
Cannot deserialize value of type `java.util.ArrayList<org.cyclonedx.model.Commit>` from Object value (token `JsonToken.START_OBJECT`)
(through reference chain: org.cyclonedx.model.Component["pedigree"]->org.cyclonedx.model.Pedigree["commits"]) (through reference chain: org.cyclonedx.model.Bom["metadata"])
at org.cyclonedx.parsers.XmlParser.parse(XmlParser.java:101)
...
Caused by: java.lang.IllegalArgumentException: Cannot deserialize value of type `java.util.ArrayList<org.cyclonedx.model.Commit>` from Object value (token `JsonToken.START_OBJECT`)
at com.fasterxml.jackson.databind.ObjectMapper.convertValue(ObjectMapper.java:4661)
at org.cyclonedx.util.deserializer.ToolInformationDeserializer.parseComponents(ToolInformationDeserializer.java:71)
at org.cyclonedx.util.deserializer.ToolInformationDeserializer.parseToolInformation(ToolInformationDeserializer.java:49)
at org.cyclonedx.util.deserializer.ToolInformationDeserializer.deserialize(ToolInformationDeserializer.java:43)
at org.cyclonedx.util.ToolsJsonParser.parse(ToolsJsonParser.java:49)
at org.cyclonedx.util.deserializer.MetadataDeserializer.deserialize(MetadataDeserializer.java:91)
...
Caused by: com.fasterxml.jackson.databind.exc.MismatchedInputException: Cannot deserialize value of type `java.util.ArrayList<org.cyclonedx.model.Commit>` from Object value (token
`JsonToken.START_OBJECT`)
at com.fasterxml.jackson.databind.deser.std.CollectionDeserializer.handleNonArray(CollectionDeserializer.java:404)
at com.fasterxml.jackson.databind.deser.std.CollectionDeserializer.deserialize(CollectionDeserializer.java:253)
Open PR #833 appears to address exactly this path but is not yet merged/released.
A CycloneDX 1.5 BOM whose
metadata → tools → componentscomponent carries apedigreewithcommits/commitcannot be deserialized from XML.XmlParser.parse()throws while mappingPedigree.commits. The same document deserializes fine as JSON, and the samepedigree/commiton a top-level component deserializes fine from XML — so this is specific to the XML +tools-component code path. The library will happily serialize this structure but then cannot read its own output, breaking round-tripping.
Version
org.cyclonedx:cyclonedx-core-java:13.2.0(latest on Maven Central). Runtime:jackson-databind/jackson-dataformat-xml2.22.2,woodstox-core7.2.0.Minimal reproduction
Parse the following (minimal — everything non-essential removed) with
new XmlParser().parse(bytes):Code to reproduce
Stack tracke:
Open PR #833 appears to address exactly this path but is not yet merged/released.