Software Bill of Materials
Warden Supreme publishes a CycloneDX software bill of materials for every Maven publication.
SBOMs follow Maven publications rather than Gradle projects. A Kotlin Multiplatform module therefore usually produces
one for its root kotlinMultiplatform publication and another for each concrete target, such as jvm, android,
iosArm64, or iosSimulatorArm64.
Machine-Readable Index
A lightweight JSON index of every module/publication pair — with absolute Maven Central URLs for the JSON, XML, and
detached .asc signature files — is available at
sbom/index.json. See Documentation Index below for
details.
Formats
- CycloneDX JSON
- CycloneDX XML
How to Read the SBOMs
The publication name tells you which view of a module the SBOM describes:
- the
kotlinMultiplatformSBOM is the root metadata publication SBOM - target SBOMs such as
jvm,android,iosArm64, andiosSimulatorArm64describe the concrete published target artifacts - JVM-only publications such as
mavenJavadescribe the published JVM artifact for that module
This distinction matters when interpreting dependencies:
- a
kotlinMultiplatformSBOM can legitimately reference metadata-oriented artifacts used for variant selection - a target SBOM reflects the concrete artifact a consumer resolves for that platform
- JVM publications such as
mavenJavareflect the published server-side jar for that module
In practice, choose:
- use
kotlinMultiplatformif you want the root KMP metadata publication view - use a target SBOM if you want the concrete artifact a consumer resolves for that platform
- use
mavenJavafor the published JVM server-side modules
Maven Central
Each published Warden Supreme Maven publication attaches its SBOM with the standard cyclonedx classifier:
artifact-version-cyclonedx.jsonartifact-version-cyclonedx.xml
For a multiplatform module, that means one SBOM pair for each publication such as kotlinMultiplatform, jvm,
android, iosArm64, and so on is created and published.
On Maven Central, look for the normal publication artifact first and then the attached SBOM files with classifier
cyclonedx.
Detached .asc signatures are part of every published Maven Central artifact set and can be assumed for these SBOMs as
well.
Documentation Index
The documentation publishes a lightweight machine-readable index:
The index lists each module/publication pair together with absolute Maven Central URLs for the corresponding JSON, XML, and detached signature files.
Examples:
supreme-commonKotlin Multiplatform metadata: JSON, XMLsupreme-commonJVM: JSON, XMLsupreme-commonAndroid: JSON, XMLmakotoJVM: JSON, XML
The per-module pages in the navigation are generated from that index and a shared Markdown template. Each generated module page contains one row per published Maven publication, including artifact metadata and links to the corresponding JSON/XML SBOM files and their detached signatures.
Modules
- Warden makoto
- Warden roboto
- Supreme Common
- Supreme Client
- Supreme Verifier
- Config Hoplite
- Config Spring
- Attestation Generator
Tooling
The files are standard CycloneDX documents. Dependency-Track, CycloneDX-aware OWASP Dependency-Check integrations, Syft/Grype workflows, and other compatible inventory or scanning tools can consume them directly.