{"id":34967647,"url":"https://github.com/guacsec/trustify-da-java-client","last_synced_at":"2026-05-25T09:10:31.899Z","repository":{"id":167729299,"uuid":"642397799","full_name":"guacsec/trustify-da-java-client","owner":"guacsec","description":"Red Hat Dependency Analytics Exhort Java API","archived":false,"fork":false,"pushed_at":"2026-04-21T06:54:49.000Z","size":2431,"stargazers_count":2,"open_issues_count":6,"forks_count":10,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-04-21T08:41:06.071Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/guacsec.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":".github/CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":"DCO","cla":null}},"created_at":"2023-05-18T13:29:33.000Z","updated_at":"2026-04-21T06:54:01.000Z","dependencies_parsed_at":"2026-03-09T11:06:47.094Z","dependency_job_id":null,"html_url":"https://github.com/guacsec/trustify-da-java-client","commit_stats":null,"previous_names":["rhecosystemappeng/crda-java-api","rhecosystemappeng/exhort-java-api","trustification/exhort-java-api","guacsec/trustify-da-java-client"],"tags_count":33,"template":false,"template_full_name":null,"purl":"pkg:github/guacsec/trustify-da-java-client","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/guacsec%2Ftrustify-da-java-client","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/guacsec%2Ftrustify-da-java-client/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/guacsec%2Ftrustify-da-java-client/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/guacsec%2Ftrustify-da-java-client/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/guacsec","download_url":"https://codeload.github.com/guacsec/trustify-da-java-client/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/guacsec%2Ftrustify-da-java-client/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32331305,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-26T23:26:28.701Z","status":"online","status_checked_at":"2026-04-27T02:00:06.769Z","response_time":128,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2025-12-26T23:19:30.004Z","updated_at":"2026-05-25T09:10:31.885Z","avatar_url":"https://github.com/guacsec.png","language":"Java","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Trustify DA Java Client\u003cbr/\u003e![latest-no-snapshot][0] ![latest-snapshot][1]\n\n* Looking for our JavaScript/TypeScript API? Try [Trustify DA JavaScript Client](https://github.com/guacsec/trustify-da-javascript-client).\n* Looking for our Backend implementation? Try [Trustify Dependency Analytics](https://github.com/guacsec/trustify-dependency-analytics).\n\n**Requires Java 21 or later.**\n\nThe _Trustify DA Java Client_ module is deployed to _GitHub Package Registry_.\n\n\u003cdetails\u003e\n\u003csummary\u003eClick here for configuring \u003cem\u003eGHPR\u003c/em\u003e registry access.\u003c/summary\u003e\n\u003ch3\u003eConfigure Registry Access\u003c/h3\u003e\n\u003cp\u003e\nCreate a\n\u003ca href=\"https://docs.github.com/en/packages/learn-github-packages/introduction-to-github-packages#authenticating-to-github-packages\"\u003etoken\u003c/a\u003e\nwith the \u003cstrong\u003eread:packages\u003c/strong\u003e scope\u003cbr/\u003e\n\n\u003e Based on\n\u003e \u003ca href=\"https://docs.github.com/en/packages/working-with-a-github-packages-registry/working-with-the-apache-maven-registry\"\u003eGitHub documentation\u003c/a\u003e,\n\u003e In \u003cem\u003eActions\u003c/em\u003e you can use \u003cem\u003eGITHUB_TOKEN\u003c/em\u003e\n\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cem\u003eMaven\u003c/em\u003e users\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eEncrypt your token\n\n```shell\n$ mvn --encrypt-password your-ghp-token-goes-here\n\nencrypted-token-will-appear-here\n```\n\u003c/li\u003e\n\u003cli\u003eAdd a \u003cem\u003eserver\u003c/em\u003e definition in your \u003cem\u003e$HOME/.m2/settings.xml\u003c/em\u003e\n\n```xml\n\u003cservers\u003e\n    \u003c!-- ... other servers --\u003e\n    \u003cserver\u003e\n        \u003cid\u003egithub\u003c/id\u003e\n        \u003cusername\u003egithub-userid-goes-here\u003c/username\u003e\n        \u003cpassword\u003eencrypted-token-goes-here-including-curly-brackets\u003c/password\u003e\n    \u003c/server\u003e\n    \u003c!-- ... other servers --\u003e\n\u003c/servers\u003e\n```\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\n\u003cli\u003e\n\u003cem\u003eGradle\u003c/em\u003e users, save your token and username as environment variables\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003eGITHUB_USERNAME\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003cem\u003eGITHUB_TOKEN\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\n\u003ch3\u003eUsage\u003c/h3\u003e\n\u003col\u003e\n\u003cli\u003eConfigure Registry\u003c/li\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cem\u003eMaven\u003c/em\u003e users, add a \u003cem\u003erepository\u003c/em\u003e definition in \u003cem\u003epom.xml\u003c/em\u003e\n\n```xml\n  \u003crepositories\u003e\n    \u003c!-- ... other repositories --\u003e\n    \u003crepository\u003e\n      \u003cid\u003egithub\u003c/id\u003e\n      \u003curl\u003ehttps://maven.pkg.github.com/guacsec/trustify-da-java-client\u003c/url\u003e\n    \u003c/repository\u003e\n    \u003c!-- ... other repositories --\u003e\n  \u003c/repositories\u003e\n```\n\u003c/li\u003e\n\n\u003cli\u003e\n\u003cem\u003eGradle\u003c/em\u003e users, add a \u003cem\u003emaven-type repository\u003c/em\u003e definition in \u003cem\u003ebuild.gradle\u003c/em\u003e (Groovy DSL) or \u003cem\u003ebuild.gradle.kts\u003c/em\u003e (Kotlin DSL)\n\n```groovy\nrepositories {\n    // ... other repositories\n    maven {\n        url 'https://maven.pkg.github.com/guacsec/trustify-da-java-client'\n        credentials {\n            username System.getenv(\"GITHUB_USERNAME\")\n            password System.getenv(\"GITHUB_TOKEN\")\n        }\n    }\n    // ... other repositories\n}\n```\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cli\u003eDeclare the dependency\n\u003cul\u003e\n\u003cli\u003e\n\u003cem\u003eMaven\u003c/em\u003e users, add a dependency in \u003cem\u003epom.xml\u003c/em\u003e\n\n```xml\n\u003cdependency\u003e\n    \u003cgroupId\u003eio.github.guacsec\u003c/groupId\u003e\n    \u003cartifactId\u003etrustify-da-java-client\u003c/artifactId\u003e\n    \u003cversion\u003e0.0.9-SNAPSHOT\u003c/version\u003e\n\u003c/dependency\u003e\n```\n\u003c/li\u003e\n\n\u003cli\u003e\n\u003cem\u003eGradle\u003c/em\u003e users, add a dependency in \u003cem\u003ebuild.gradle\u003c/em\u003e\n\n```groovy\nimplementation 'io.github.guacsec:trustify-da-java-client:${trustify-da-java-client.version}'\n```\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\n\u003cli\u003e\nIf working with modules, configure module read\n\n```java\nmodule x { // module-info.java\n    requires io.github.guacsec;\n}\n```\n\u003c/li\u003e\n\n\u003cli\u003e\nCode example\n\n```java\nimport io.github.guacsec.trustifyda.Api.MixedReport;\nimport io.github.guacsec.trustifyda.ComponentAnalysisResult;\nimport io.github.guacsec.trustifyda.impl.ExhortApi;\nimport io.github.guacsec.trustifyda.api.v5.AnalysisReport;\nimport java.nio.file.Files;\nimport java.nio.file.Path;\nimport java.util.concurrent.CompletableFuture;\n\npublic class TrustifyExample {\n    public static void main(String... args) throws Exception {\n        // instantiate the Trustify DA Java Client implementation\n        var exhortApi = new ExhortApi();\n\n        // get a byte array future holding a html Stack Analysis report\n        CompletableFuture\u003cbyte[]\u003e htmlStackReport = exhortApi.stackAnalysisHtml(\"/path/to/pom.xml\");\n\n        // get a AnalysisReport future holding a deserialized Stack Analysis report\n        CompletableFuture\u003cAnalysisReport\u003e stackReport = exhortApi.stackAnalysis(\"/path/to/pom.xml\");\n\n        // get a AnalysisReport future holding a mixed report object aggregating:\n        // - (json) deserialized Stack Analysis report\n        // - (html) html Stack Analysis report\n        CompletableFuture\u003cMixedReport\u003e mixedStackReport = exhortApi.stackAnalysisMixed(\"/path/to/pom.xml\");\n\n        // get a AnalysisReport future holding a deserialized Component Analysis report\n        var manifestContent = Files.readAllBytes(Path.of(\"/path/to/pom.xml\"));\n        CompletableFuture\u003cAnalysisReport\u003e componentReport = exhortApi.componentAnalysis(\"/path/to/pom.xml\", manifestContent);\n\n        // get a ComponentAnalysisResult with license compatibility checking\n        CompletableFuture\u003cComponentAnalysisResult\u003e componentWithLicense = exhortApi.componentAnalysisWithLicense(\"/path/to/pom.xml\");\n        var result = componentWithLicense.get();\n        var report = result.report();              // standard AnalysisReport\n        var licenseSummary = result.licenseSummary(); // license compatibility summary (may be null)\n\n        // generate a CycloneDX SBOM locally (no backend call required)\n        String sbomJson = exhortApi.generateSbom(\"/path/to/pom.xml\");\n    }\n}\n```\n\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003ch3\u003eSupported Ecosystems\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.java.com/\"\u003eJava\u003c/a\u003e - \u003ca href=\"https://maven.apache.org/\"\u003eMaven\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.javascript.com//\"\u003eJavaScript\u003c/a\u003e - \u003ca href=\"https://www.npmjs.com//\"\u003eNpm\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://go.dev//\"\u003eGolang\u003c/a\u003e - \u003ca href=\"https://go.dev/blog/using-go-modules//\"\u003eGo Modules\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.python.org/\"\u003ePython\u003c/a\u003e - \u003ca href=\"https://pypi.org/project/pip/\"\u003epip Installer\u003c/a\u003e / \u003ca href=\"https://docs.astral.sh/uv/\"\u003euv\u003c/a\u003e (\u003ccode\u003erequirements.txt\u003c/code\u003e, \u003ccode\u003epyproject.toml\u003c/code\u003e with PEP 621 format). \u003cstrong\u003eNote:\u003c/strong\u003e Poetry-style dependencies (\u003ccode\u003e[tool.poetry.dependencies]\u003c/code\u003e) are not supported.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://gradle.org//\"\u003eGradle\u003c/a\u003e - \u003ca href=\"https://gradle.org/install//\"\u003eGradle Installation\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.rust-lang.org/\"\u003eRust\u003c/a\u003e - \u003ca href=\"https://doc.rust-lang.org/cargo/\"\u003eCargo\u003c/a\u003e\u003c/li\u003e\n\n\u003c/ul\u003e\n\n\u003ch3\u003eExcluding Packages\u003c/h3\u003e\n\u003cp\u003e\nExcluding a package from any analysis can be achieved by marking the package for exclusion using either the \u003ccode\u003etrustify-da-ignore\u003c/code\u003e syntax.\n\nAlthough both `trustify-da-ignore` and `exhortignore` patterns work identically and can be used interchangeably. The `trustify-da-ignore` syntax is recommended for new projects, while `exhortignore` continues to be supported for backwards compatibility. You can gradually migrate your projects or use both patterns in the same manifest.\n\n\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cem\u003eJava Maven\u003c/em\u003e users can add a comment in \u003cem\u003epom.xml\u003c/em\u003e\n\n```xml\n\u003c!-- Using trustify-da-ignore syntax --\u003e\n\u003cdependency\u003e \u003c!--trustify-da-ignore--\u003e\n    \u003cgroupId\u003e...\u003c/groupId\u003e\n    \u003cartifactId\u003e...\u003c/artifactId\u003e\n    \u003cversion\u003e0.0.9-SNAPSHOT\u003c/version\u003e\n\u003c/dependency\u003e\n\n\u003c!-- Using legacy exhortignore syntax --\u003e\n\u003cdependency\u003e \u003c!--exhortignore--\u003e\n  \u003cgroupId\u003e...\u003c/groupId\u003e\n  \u003cartifactId\u003e...\u003c/artifactId\u003e\n  \u003cversion\u003e0.0.9-SNAPSHOT\u003c/version\u003e\n\u003c/dependency\u003e\n```\n\u003c/li\u003e\n\n\u003cli\u003e\n\u003cem\u003eJavascript NPM\u003c/em\u003e users can add ignore arrays in \u003cem\u003epackage.json\u003c/em\u003e:\n\n```json\n{\n  \"name\": \"sample\",\n  \"version\": \"1.0.0\",\n  \"description\": \"\",\n  \"main\": \"index.js\",\n  \"keywords\": [],\n  \"author\": \"\",\n  \"license\": \"ISC\",\n  \"dependencies\": {\n    \"dotenv\": \"^8.2.0\",\n    \"express\": \"^4.17.1\",\n    \"jsonwebtoken\": \"^8.5.1\",\n    \"mongoose\": \"^5.9.18\"\n  },\n  \"trustify-da-ignore\": [\n    \"jsonwebtoken\"\n  ]\n}\n```\n\u003c/li\u003e\n\n\u003cli\u003e\n\u003cem\u003eGolang\u003c/em\u003e users can add in go.mod a comment with //trustify-da-ignore next to the package to be ignored, or to \"piggyback\" on existing comment ( e.g - //indirect) , for example:\n\n```mod\nmodule github.com/RHEcosystemAppEng/SaaSi/deployer\n\ngo 1.19\n\nrequire (\n        github.com/gin-gonic/gin v1.9.1\n        github.com/google/uuid v1.1.2\n        github.com/jessevdk/go-flags v1.5.0 //trustify-da-ignore\n        github.com/kr/pretty v0.3.1\n        gopkg.in/yaml.v2 v2.4.0\n        k8s.io/apimachinery v0.26.1\n        k8s.io/client-go v0.26.1\n)\n\nrequire (\n        github.com/davecgh/go-spew v1.1.1 // indirect trustify-da-ignore\n        github.com/emicklei/go-restful/v3 v3.9.0 // indirect\n        github.com/go-logr/logr v1.2.3 // indirect trustify-da-ignore\n)\n```\n\u003c/li\u003e\n\n\u003cli\u003e\n\u003cem\u003ePython pip\u003c/em\u003e users can add in \u003ccode\u003erequirements.txt\u003c/code\u003e a comment with #trustify-da-ignore(or # trustify-da-ignore) to the right of the same artifact to be ignored, for example:\n\n```properties\nanyio==3.6.2\nasgiref==3.4.1\nbeautifulsoup4==4.12.2\ncertifi==2023.7.22\nchardet==4.0.0\nclick==8.0.4 #trustify-da-ignore\ncontextlib2==21.6.0\nfastapi==0.75.1\nFlask==2.0.3\nh11==0.13.0\nidna==2.10\nimmutables==0.19\nimportlib-metadata==4.8.3\nitsdangerous==2.0.1\nJinja2==3.0.3\nMarkupSafe==2.0.1\npydantic==1.9.2 # trustify-da-ignore\nrequests==2.25.1\nsix==1.16.0\nsniffio==1.2.0\nsoupsieve==2.3.2.post1\nstarlette==0.17.1\ntyping_extensions==4.1.1\nurllib3==1.26.16\nuvicorn==0.17.0\nWerkzeug==2.0.3\nzipp==3.6.0\n```\n\u003c/li\u003e\n\n\u003cli\u003e\n\u003cem\u003ePython pyproject.toml\u003c/em\u003e users can add a comment with #trustify-da-ignore next to a dependency in \u003ccode\u003epyproject.toml\u003c/code\u003e:\n\n```toml\n[project]\nname = \"my-project\"\ndependencies = [\n    \"requests\u003e=2.28.1\",\n    \"flask\u003e=2.0\",  # trustify-da-ignore\n    \"click\u003e=8.0\",\n]\n```\n\u003c/li\u003e\n\n\u003cli\u003e\n\u003cem\u003eGradle\u003c/em\u003e users can add in build.gradle a comment with //trustify-da-ignore next to the package to be ignored:\n```build.gradle\n\n```groovy\nplugins {\n    id 'java'\n}\n\ngroup = 'groupName'\nversion = 'version'\n\nrepositories {\n    mavenCentral()\n}\n\ndependencies {\n    implementation \"groupId:artifactId:version\" // trustify-da-ignore\n}\n\ntest {\n    useJUnitPlatform()\n}\n```\n\u003c/li\u003e\n\n\u003cli\u003e\n\u003cem\u003eRust Cargo\u003c/em\u003e users can add a comment with #trustify-da-ignore next to the package to be ignored in \u003cem\u003eCargo.toml\u003c/em\u003e:\n\n```toml\n[dependencies]\nserde = \"1.0.136\" # trustify-da-ignore\ntokio = { version = \"1.0\", features = [\"full\"] }\n\n[workspace.dependencies]\nregex = \"1.5.4\" # trustify-da-ignore\n```\n\u003c/li\u003e\n\n\u003c/ul\u003e\n\n#### License Resolution and Compliance\n\nThe Java client includes built-in license analysis that detects your project's license, checks dependency license compatibility, and includes license information in generated SBOMs.\n\n- License checking runs automatically during **component analysis**\n- Supports reading licenses from `pom.xml`, `package.json`, `Cargo.toml`, and LICENSE files\n- Set `TRUSTIFY_DA_LICENSE_CHECK=false` to disable\n\nFor full documentation, see [License Resolution and Compliance](docs/license-resolution-and-compliance.md).\n\n#### Ignore Strategies - experimental\n\nYou can specify the method to ignore dependencies in manifest (globally), by setting the environment variable `TRUSTIFY_DA_IGNORE_METHOD` to one of the following values:\n\n**Possible values:**\n- `insensitive` - ignoring the dependency and all of its subtree(all transitives) - default.\n- `sensitive` - ignoring the dependency but let its transitives remain if they are also transitive of another dependency in the tree or if they're direct dependency of root in the dependency tree.\n\n\u003ch3\u003eCustomization\u003c/h3\u003e\n\u003cp\u003e\nThere are 2 approaches for customizing \u003cem\u003eTrustify DA Java Client\u003c/em\u003e. Using \u003cem\u003eEnvironment Variables\u003c/em\u003e or\n\u003cem\u003eJava Properties\u003c/em\u003e:\n\n```text\nSystem.setProperty(\"TRUSTIFY_DA_MVN_PATH\", \"/path/to/custom/mvn\");\nSystem.setProperty(\"TRUSTIFY_DA_NPM_PATH\", \"/path/to/custom/npm\");\nSystem.setProperty(\"TRUSTIFY_DA_PNPM_PATH\", \"/path/to/custom/pnpm\");\nSystem.setProperty(\"TRUSTIFY_DA_YARN_PATH\", \"/path/to/custom/yarn\");\nSystem.setProperty(\"TRUSTIFY_DA_GO_PATH\", \"/path/to/custom/go\");\nSystem.setProperty(\"TRUSTIFY_DA_GRADLE_PATH\", \"/path/to/custom/gradle\");\nSystem.setProperty(\"TRUSTIFY_DA_CARGO_PATH\", \"/path/to/custom/cargo\");\n//python - python3, pip3 take precedence if python version \u003e 3 installed\nSystem.setProperty(\"TRUSTIFY_DA_PYTHON3_PATH\", \"/path/to/python3\");\nSystem.setProperty(\"TRUSTIFY_DA_PIP3_PATH\", \"/path/to/pip3\");\nSystem.setProperty(\"TRUSTIFY_DA_PYTHON_PATH\", \"/path/to/python\");\nSystem.setProperty(\"TRUSTIFY_DA_PIP_PATH\", \"/path/to/pip\");\nSystem.setProperty(\"TRUSTIFY_DA_UV_PATH\", \"/path/to/custom/uv\");\n// Configure proxy for all requests\nSystem.setProperty(\"TRUSTIFY_DA_PROXY_URL\", \"http://proxy.example.com:8080\");\n// Configure Maven settings and repository\nSystem.setProperty(\"TRUSTIFY_DA_MVN_USER_SETTINGS\", \"/path/to/custom/settings.xml\");\nSystem.setProperty(\"TRUSTIFY_DA_MVN_LOCAL_REPO\", \"/path/to/custom/local/repository\");\n```\n\n\u003e Environment variables takes precedence.\n\u003c/p\u003e\n\n\u003ch4\u003eCustomizing HTTP Version\u003c/h4\u003e\n\u003cp\u003e\nThe HTTP Client Library can be configured to use HTTP Protocol version through environment variables, so if there is a problem with one of the HTTP Versions, the other can be configured through a dedicated environment variable.  \n\u003c/p\u003e\n\n\u003ctable\u003e\n\u003ctr\u003e\n\u003cth\u003eEnvironment Variable\u003c/th\u003e\n\u003cth\u003eAccepted Values\u003c/th\u003e\n\u003cth\u003eDefault\u003c/th\u003e\n\n\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eHTTP_VERSION_TRUSTIFY_DA_CLIENT\u003c/td\u003e\n\u003ctd\u003e[HTTP_1_1 , HTTP_2]\u003c/td\u003e\n\u003ctd\u003eHTTP_1_1\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/table\u003e\n\n\u003ch4\u003eProxy Configuration\u003c/h4\u003e\n\u003cp\u003e\nYou can configure a proxy for all HTTP requests made by the API. This is useful when your environment requires going through a proxy to access external services.\n\nYou can set the proxy URL in two ways:\n\n1. Using environment variable:\n```\nexport TRUSTIFY_DA_PROXY_URL=http://proxy.example.com:8080\n```\n\n2. Using Java Properties when calling the API programmatically:\n```\nSystem.setProperty(\"TRUSTIFY_DA_PROXY_URL\", \"http://proxy.example.com:8080\");\n```\n\u003c/p\u003e\n\n\u003ch4\u003eCustomizing Executables\u003c/h4\u003e\n\u003cp\u003e\nThis project uses each ecosystem's executable for creating dependency trees. These executables are expected to be\npresent on the system's PATH environment. If they are not, or perhaps you want to use custom ones. Use can use the\nfollowing keys for setting custom paths for the said executables.\n\u003c/p\u003e\n\n\u003ctable\u003e\n\u003ctr\u003e\n\u003cth\u003eEcosystem\u003c/th\u003e\n\u003cth\u003eDefault\u003c/th\u003e\n\u003cth\u003eExecutable Key\u003c/th\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://maven.apache.org/\"\u003eMaven\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cem\u003emvn\u003c/em\u003e\u003c/td\u003e\n\u003ctd\u003eTRUSTIFY_DA_MVN_PATH\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://www.npmjs.com/\"\u003eNode Package Manager (npm)\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cem\u003enpm\u003c/em\u003e\u003c/td\u003e\n\u003ctd\u003eTRUSTIFY_DA_NPM_PATH\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://pnpm.io/\"\u003epnpm\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cem\u003epnpm\u003c/em\u003e\u003c/td\u003e\n\u003ctd\u003eTRUSTIFY_DA_PNPM_PATH\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://classic.yarnpkg.com/\"\u003eYarn (Classic)\u003c/a\u003e / \u003ca href=\"https://yarnpkg.com/\"\u003eYarn (Berry)\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cem\u003eyarn\u003c/em\u003e\u003c/td\u003e\n\u003ctd\u003eTRUSTIFY_DA_YARN_PATH\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://go.dev/blog/using-go-modules/\"\u003eGo Modules\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cem\u003ego\u003c/em\u003e\u003c/td\u003e\n\u003ctd\u003eTRUSTIFY_DA_GO_PATH\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://gradle.org/\"\u003eGradle\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cem\u003egradle\u003c/em\u003e\u003c/td\u003e\n\u003ctd\u003eTRUSTIFY_DA_GRADLE_PATH\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://www.python.org/\"\u003ePython programming language\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cem\u003epython3\u003c/em\u003e\u003c/td\u003e\n\u003ctd\u003eTRUSTIFY_DA_PYTHON3_PATH\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://pypi.org/project/pip/\"\u003ePython pip Package Installer\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cem\u003epip3\u003c/em\u003e\u003c/td\u003e\n\u003ctd\u003eTRUSTIFY_DA_PIP3_PATH\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://www.python.org/\"\u003ePython programming language\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cem\u003epython\u003c/em\u003e\u003c/td\u003e\n\u003ctd\u003eTRUSTIFY_DA_PYTHON_PATH\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://pypi.org/project/pip/\"\u003ePython pip Package Installer\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cem\u003epip\u003c/em\u003e\u003c/td\u003e\n\u003ctd\u003eTRUSTIFY_DA_PIP_PATH\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://docs.astral.sh/uv/\"\u003euv Package Manager\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cem\u003euv\u003c/em\u003e\u003c/td\u003e\n\u003ctd\u003eTRUSTIFY_DA_UV_PATH\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e\u003ca href=\"https://doc.rust-lang.org/cargo/\"\u003eCargo Package Manager\u003c/a\u003e\u003c/td\u003e\n\u003ctd\u003e\u003cem\u003ecargo\u003c/em\u003e\u003c/td\u003e\n\u003ctd\u003eTRUSTIFY_DA_CARGO_PATH\u003c/td\u003e\n\u003c/tr\u003e\n\n\u003c/table\u003e\n\n#### Maven Configuration\n\nYou can customize Maven behavior by setting additional environment variables or Java properties:\n\n\u003ctable\u003e\n\u003ctr\u003e\n\u003cth\u003eConfiguration\u003c/th\u003e\n\u003cth\u003eEnvironment Variable\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003cth\u003eDefault\u003c/th\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eMaven User Settings\u003c/td\u003e\n\u003ctd\u003eTRUSTIFY_DA_MVN_USER_SETTINGS\u003c/td\u003e\n\u003ctd\u003ePath to custom Maven settings.xml file\u003c/td\u003e\n\u003ctd\u003e\u003cem\u003eUses Maven's default settings\u003c/em\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eMaven Local Repository\u003c/td\u003e\n\u003ctd\u003eTRUSTIFY_DA_MVN_LOCAL_REPO\u003c/td\u003e\n\u003ctd\u003ePath to custom Maven local repository directory\u003c/td\u003e\n\u003ctd\u003e\u003cem\u003eUses Maven's default local repository\u003c/em\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/table\u003e\n\n**Examples:**\n\nUsing environment variables:\n```bash\nexport TRUSTIFY_DA_MVN_USER_SETTINGS=/home/user/.m2/custom-settings.xml\nexport TRUSTIFY_DA_MVN_LOCAL_REPO=/home/user/custom-maven-repo\n```\n\nUsing Java properties:\n```text\nSystem.setProperty(\"TRUSTIFY_DA_MVN_USER_SETTINGS\", \"/home/user/.m2/custom-settings.xml\");\nSystem.setProperty(\"TRUSTIFY_DA_MVN_LOCAL_REPO\", \"/home/user/custom-maven-repo\");\n```\n\n\u003e Environment variables take precedence over Java properties.\n\n#### Match Manifest Versions Feature\n\n##### Background\n\nIn Python pip and in golang go modules package managers ( especially in Python pip) , There is a big chance that for a certain manifest and a given package inside it, the client machine environment has different version installed/resolved\nfor that package, which can lead to perform the analysis on the installed packages' versions , instead on the declared versions ( in manifests - that is requirements.txt/pyproject.toml/go.mod ), and this\ncan cause a confusion for the user in the client consuming the API and leads to inconsistent output ( in THE manifest there is version X For a given Package `A` , and in the analysis report there is another version for the same package `A` - Y).\n\n##### Usage\n\nTo eliminate confusion and improve clarity as discussed above, the following setting was introduced - `MATCH_MANIFEST_VERSIONS`, in the form of environment variable/key in opts ( as usual , environment variable takes precedence )\nfor two ecosystems:\n - Golang - Go Modules\n - Python - pip\n\nTwo possible values for this setting:\n\n1. MATCH_MANIFEST_VERSIONS=\"false\" - means that if installed/resolved versions of packages are different than the ones declared in the manifest, the process will ignore this difference and will continue to analysis with installed/resolved versions ( this is the original logic flow )\n\u003cbr\u003e\n\n\n2. MATCH_MANIFEST_VERSIONS=\"true\" - means that before starting the analysis,\n   the api will compare all the versions of packages in manifest against installed/resolved versions on client' environment, in case there is a difference, it will throw an error to the client/user with message containing the first encountered versions mismatch, including package name, and the versions difference, and will suggest to set setting `MATCH_MANIFEST_VERSIONS`=\"false\" to ignore all differences\n\n#### Golang Support\n\nBy default, Golang dependency resolution follows the [Minimal Version Selection (MVS) Algorithm](https://go.dev/ref/mod#minimal-version-selection).  \nThis means that when analyzing a project, only the module versions that would actually be included in the final executable are considered.\n\nFor example, if your `go.mod` file declares two modules, `a` and `b`, and both depend on the same package `c` (same major version `v1`) but with different minor versions:\n\n- `namespace/c/v1@v1.1`\n- `namespace/c/v1@v1.2`\n\nOnly one of these versions — the minimal version selected by MVS — will be included in the generated SBOM and analysis results.  \nThis mirrors the behavior of a real Go build, where only one minor version of a given major version can be present in the executable (since Go treats packages with the same name and major version as identical).\n\nThe MVS-based resolution is **enabled by default**.  \nIf you want to disable this behavior and instead include **all transitive module versions** (as listed in `go.mod` dependencies), set the system property or environment variable:\n\n```bash\nTRUSTIFY_DA_GO_MVS_LOGIC_ENABLED=false\n```\n\n####  Python Support\n\nPython support works with both `requirements.txt` and `pyproject.toml` manifest files. The `pyproject.toml` provider scans production dependencies from PEP 621 `[project.dependencies]` and Poetry `[tool.poetry.dependencies]` sections. Optional dependencies (`[project.optional-dependencies]`) and Poetry group dependencies (`[tool.poetry.group.*.dependencies]`) are intentionally excluded to focus on runtime dependencies.\n\n##### uv Support\n\nWhen a `uv.lock` file is present alongside `pyproject.toml`, the client automatically uses the [uv](https://docs.astral.sh/uv/) package manager for dependency resolution instead of pip. Dependency data is collected via `uv export --format requirements.txt --frozen --no-hashes --no-dev`. No additional configuration is required — the provider is selected automatically based on lock file detection.\n\nTo use a custom uv binary, set `TRUSTIFY_DA_UV_PATH` to the path of your uv executable.\n\n##### pip Support\n\nBy default, Python support assumes that the package is installed using the pip/pip3 binary on the system PATH, or of the customized\nBinaries passed to environment variables. If the package is not installed , then an error will be thrown.\n\nThere is an experimental feature of installing the dependencies on a virtual env(only python3 or later is supported for this feature) - in this case,\nit's important to pass in a path to python3 binary as `TRUSTIFY_DA_PYTHON3_PATH` or instead make sure that python3 is on the system path.\nin such case, You can use that feature by setting environment variable `TRUSTIFY_DA_PYTHON_VIRTUAL_ENV` to true\n\n##### \"Best Efforts Installation\"\nSince Python pip packages are very sensitive/picky regarding python version changes( every small range of versions is only tailored for a certain python version), I'm introducing this feature, that\ntries to install all packages in the manifest onto created virtual environment while **disregarding** versions declared for packages\nThis increasing the chances and the probability a lot that the automatic installation will succeed.\n\n##### Usage\nA New setting is introduced - `TRUSTIFY_DA_PYTHON_INSTALL_BEST_EFFORTS` (as both env variable/key in `options` object)\n1. `TRUSTIFY_DA_PYTHON_INSTALL_BEST_EFFORTS`=\"false\" - install requirements.txt while respecting declared versions for all packages.\n2. `TRUSTIFY_DA_PYTHON_INSTALL_BEST_EFFORTS`=\"true\" - install all packages from requirements.txt, not respecting the declared version, but trying to install a version tailored for the used python version, when using this setting,you must set setting `MATCH_MANIFEST_VERSIONS`=\"false\"\n\n##### Using `pipdeptree`\nBy Default, The API algorithm will use native commands of PIP installer as data source to build the dependency tree.\nIt's also possible, to use lightweight Python PIP utility [pipdeptree](https://pypi.org/project/pipdeptree/) as data source instead, in order to activate this,\nNeed to set environment variable/system property - `TRUSTIFY_DA_PIP_USE_DEP_TREE` to true.\n\n### CLI Support\n\nThe Trustify DA Java Client includes a command-line interface for standalone usage.\n\n#### Building the CLI\n\nTo build the CLI JAR with all dependencies included:\n\n```shell\nmvn clean package\n```\n\nThis creates two JAR files in the `target/` directory:\n- `trustify-da-java-client.jar` - Library JAR (for programmatic use)\n- `trustify-da-java-client-cli.jar` - CLI JAR (includes all dependencies)\n\n#### Usage\n\n```shell\njava -jar target/trustify-da-java-client-cli.jar \u003cCOMMAND\u003e \u003cFILE_PATH\u003e [OPTIONS]\n```\n\n#### Commands\n\n**Stack Analysis**\n```shell\njava -jar trustify-da-java-client-cli.jar stack \u003cfile_path\u003e [--summary|--html]\n```\nPerform stack analysis on the specified manifest file.\n\nOptions:\n- `--summary` - Output summary in JSON format\n- `--html` - Output full report in HTML format\n- (default) - Output full report in JSON format\n\n**Component Analysis**\n```shell\njava -jar trustify-da-java-client-cli.jar component \u003cfile_path\u003e [--summary]\n```\nPerform component analysis on the specified manifest file. License compatibility checking is included by default.\n\nOptions:\n- `--summary` - Output summary in JSON format\n- (default) - Output full report in JSON format (includes license summary)\n\n**License Information**\n```shell\njava -jar trustify-da-java-client-cli.jar license \u003cfile_path\u003e\n```\nDisplay project license information from manifest and LICENSE file in JSON format.\n\n**SBOM Generation**\n```shell\njava -jar trustify-da-java-client-cli.jar sbom \u003cfile_path\u003e [--output \u003cpath\u003e]\n```\nGenerate a CycloneDX SBOM from the specified manifest file locally, without sending anything to the backend.\n\nOptions:\n- `--output \u003cpath\u003e` - Write SBOM JSON to the specified file\n- (default) - Print SBOM JSON to stdout\n\n**SBOM for uv-managed Python project**\n```shell\n# When uv.lock is present alongside pyproject.toml, the uv provider is used automatically\njava -jar trustify-da-java-client-cli.jar sbom /path/to/uv-project/pyproject.toml\n```\n\n**Image Analysis**\n```shell\njava -jar trustify-da-java-client-cli.jar image \u003cimage_ref\u003e [\u003cimage_ref\u003e...] [--summary|--html]\n```\nPerform security analysis on the specified container image(s).\n\nArguments:\n- `\u003cimage_ref\u003e` - Container image reference (e.g., `nginx:latest`, `registry.io/image:tag`)\n- Multiple images can be analyzed at once\n- Optionally specify platform with `^^` notation (e.g., `image:tag^^linux/amd64`)\n\nOptions:\n- `--summary` - Output summary in JSON format\n- `--html` - Output full report in HTML format\n- (default) - Output full report in JSON format\n\n#### Backend Configuration\n\nThe client requires the backend URL to be configured through the environment variable:\n\n- **Environment variable**: `TRUSTIFY_DA_BACKEND_URL=https://backend.url` (required for analysis commands)\n\nThe application will fail to start if this environment variable is not set, except for the `sbom` command which operates locally without a backend connection.\n\n#### Examples\n\n```shell\nexport TRUSTIFY_DA_BACKEND_URL=https://your-backend.url\n\n# Stack analysis with JSON output (default)\njava -jar trustify-da-java-client-cli.jar stack /path/to/pom.xml\n\n# Stack analysis with summary\njava -jar trustify-da-java-client-cli.jar stack /path/to/package.json --summary\n\n# Stack analysis with HTML output\njava -jar trustify-da-java-client-cli.jar stack /path/to/build.gradle --html\n\n# Component analysis with JSON output (default)\njava -jar trustify-da-java-client-cli.jar component /path/to/requirements.txt\n\n# Component analysis for pyproject.toml\njava -jar trustify-da-java-client-cli.jar component /path/to/pyproject.toml\n\n# Component analysis with summary\njava -jar trustify-da-java-client-cli.jar component /path/to/go.mod --summary\n\n# Rust Cargo analysis\njava -jar trustify-da-java-client-cli.jar stack /path/to/Cargo.toml --summary\n\n# SBOM generation (no backend required)\njava -jar trustify-da-java-client-cli.jar sbom /path/to/pom.xml\njava -jar trustify-da-java-client-cli.jar sbom /path/to/package.json --output sbom.json\n\n# License information\njava -jar trustify-da-java-client-cli.jar license /path/to/pom.xml\n\n# Container image analysis with JSON output (default)\njava -jar trustify-da-java-client-cli.jar image nginx:latest\n\n# Multiple container image analysis\njava -jar trustify-da-java-client-cli.jar image nginx:latest docker.io/library/node:18\n\n# Container image analysis with platform specification\njava -jar trustify-da-java-client-cli.jar image nginx:latest^^linux/amd64 --summary\n\n# Container image analysis with HTML output\njava -jar trustify-da-java-client-cli.jar image quay.io/redhat/ubi8:latest --html\n\n# Show help\njava -jar trustify-da-java-client-cli.jar --help\n```\n\n### Image Support \n\nGenerate vulnerability analysis report for container images.\n\n#### Code Example\n```java\npackage io.github.guacsec.trustifyda;\n\nimport io.github.guacsec.trustifyda.api.AnalysisReport;\nimport io.github.guacsec.trustifyda.image.ImageRef;\nimport io.github.guacsec.trustifyda.impl.ExhortApi;\n\nimport java.util.Map;\nimport java.util.Set;\nimport java.util.concurrent.CompletableFuture;\n\npublic class TrustifyImageExample {\n\n    public static void main(String[] args) throws Exception {\n        // instantiate the Trustify DA Java Client implementation\n        var exhortApi = new ExhortApi();\n\n        // create a reference to image test1 by specifying image name and its platform when applicable\n        var imageRef1 = new ImageRef(\"quay.io/test/test1:latest\", \"linux/amd64\");\n\n        // create a reference to image test2 by specifying image name\n        var imageRef2 = new ImageRef(\"quay.io/test/test2:latest\", null);\n\n        // get a byte array future holding a html Image Analysis reports\n        CompletableFuture\u003cbyte[]\u003e htmlImageReport = exhortApi.imageAnalysisHtml(Set.of(imageRef1, imageRef2));\n\n        // get a map of AnalysisReport future holding a deserialized Image Analysis reports\n        CompletableFuture\u003cMap\u003cImageRef, AnalysisReport\u003e\u003e imageReport = exhortApi.imageAnalysis(Set.of(imageRef1, imageRef2));\n    }\n}\n```\n\n#### Prerequisites\nInstallation of the tools/cli for analyzing image vulnerability.\n\n| Tool   | CLI Installation                                                        | Required |\n|--------|-------------------------------------------------------------------------|----------|\n| Syft   | [syft](https://github.com/anchore/syft?tab=readme-ov-file#installation) | True     |\n| Skopeo | [skopeo](https://github.com/containers/skopeo/blob/main/install.md)     | True     |\n| Docker | [docker](https://docs.docker.com/get-docker/)                           | False    |\n| Podman | [podman](https://podman.io/docs/installation)                           | False    |\n\n#### Customization\nCustomize image analysis optionally by using *Environment Variables* or *Java Properties*.\n\n| Env / Property                | Description                                                                                                                                                     | Default Value                                                                                                                                 |\n|-------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------|\n| TRUSTIFY_DA_SYFT_PATH              | Custom path to the `syft` executable                                                                                                                            | syft                                                                                                                                          |\n| TRUSTIFY_DA_SYFT_CONFIG_PATH       | Custom path to the `syft` [configuration file](https://github.com/anchore/syft?tab=readme-ov-file#configuration)                                                | .syft.yaml, .syft/config.yaml, $HOME/.syft.yaml                                                                                               |\n| TRUSTIFY_DA_SYFT_IMAGE_SOURCE      | [Source](https://github.com/anchore/syft?tab=readme-ov-file#supported-sources) from which `syft` looks for the images (e.g. docker, podman, registry)           | (By default, Syft attempts to resolve it using: the Docker, Podman, and Containerd daemons followed by direct registry access, in that order) |\n| TRUSTIFY_DA_SKOPEO_PATH            | Custom path to the `skopeo` executable                                                                                                                          | skopeo                                                                                                                                        |\n| TRUSTIFY_DA_SKOPEO_CONFIG_PATH     | Custom path to the [authentication file](https://github.com/containers/skopeo/blob/main/docs/skopeo-inspect.1.md#options) used by `skopeo inspect`              | $HOME/.docker/config.json                                                                                                                     |\n| TRUSTIFY_DA_IMAGE_SERVICE_ENDPOINT | [Host endpoint](https://github.com/containers/skopeo/blob/main/docs/skopeo-inspect.1.md#options) of the container runtime daemon / service                      |                                                                                                                                               |\n| TRUSTIFY_DA_DOCKER_PATH            | Custom path to the `docker` executable                                                                                                                          | docker                                                                                                                                        |\n| TRUSTIFY_DA_PODMAN_PATH            | Custom path to the `podman` executable                                                                                                                          | podman                                                                                                                                        |\n| TRUSTIFY_DA_IMAGE_PLATFORM         | Default platform used for multi-arch images                                                                                                                     |                                                                                                                                               |\n| TRUSTIFY_DA_IMAGE_OS               | Default OS used for multi-arch images when `TRUSTIFY_DA_IMAGE_PLATFORM` is not set                                                                                   |                                                                                                                                               |\n| TRUSTIFY_DA_IMAGE_ARCH             | Default Architecture used for multi-arch images when `TRUSTIFY_DA_IMAGE_PLATFORM` is not set                                                                         |                                                                                                                                               |\n| TRUSTIFY_DA_IMAGE_VARIANT          | Default Variant used for multi-arch images when `TRUSTIFY_DA_IMAGE_PLATFORM` is not set                                                                              |                                                                                                                                               |\n\n### Releases\n\nTo create a new release:\n\n1. **Trigger Release Workflow**: Go to Actions → \"Release Version\" → \"Run workflow\"\n2. **Choose Version**:\n   - Leave version empty to automatically release current snapshot (e.g., `0.0.9-SNAPSHOT` → `0.0.9`)\n   - Or specify custom version (e.g., `1.0.0`)\n3. **Automatic Process**: The workflow will:\n   - Publish to Maven Central\n   - Create GitHub release with auto-generated notes\n   - Bump to next development version via pull request\n\nReleased artifacts are available on [Maven Central](https://repo1.maven.org/maven2/io/github/guacsec/trustify-da-java-client/).\n\n### Known Issues\n\n- For pip requirements.txt - It's been observed that for python versions 3.11.x, there might be slowness for invoking the analysis.\n  If you encounter a performance issue with python version \u003e= 3.11.x, kindly try to set environment variable/system property `TRUSTIFY_DA_PIP_USE_DEP_TREE`=true, before calling the analysis - this should fix the performance issue.\n\n\n\n- For maven pom.xml, it has been noticed that using Java 17 might cause stack analysis to hang forever.\n  This is caused by maven [`dependency` Plugin](https://maven.apache.org/plugins/maven-dependency-plugin/) bug when running with JDK/JRE JVM version 17.\n  This project now requires Java 21 as the minimum version, which is not affected by this issue.\n\n\n\u003c!-- Badge links --\u003e\n[0]: https://img.shields.io/github/v/release/guacsec/trustify-da-java-client?color=green\u0026label=latest\n[1]: https://img.shields.io/github/v/release/guacsec/trustify-da-java-client?color=yellow\u0026include_prereleases\u0026label=snapshot\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fguacsec%2Ftrustify-da-java-client","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fguacsec%2Ftrustify-da-java-client","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fguacsec%2Ftrustify-da-java-client/lists"}