http4k Verify ensures the integrity of every http4k dependency in your build - automatically, before your code compiles.
Security teams and regulators increasingly require evidence that the third-party components in your build haven't been tampered with - and the bar is rising fast.
http4k Enterprise Edition publishes SLSA provenance, CycloneDX SBOMs, signed licence reports and cosign signatures for every artifact. http4k Verify checks them all automatically, before your code compiles - so the assurance is captured at build time rather than chased down at audit time.
Machine-readable SBOMs and secure development practices for software sold in the EU.
SBOMs and supply chain attestation required for federal procurement.
Consume provenance and verify third-party components (PS.3 / PW.4).
Strengthened supply chain integrity controls for payment-processing software.
One Gradle plugin. No CLI tools to install. Every http4k dependency is verified automatically before compilation.
If any artifact has been tampered with, the build fails. No silent failures, no runtime surprises. Supply chain integrity verified before your code compiles.
Covers all 200+ http4k modules - verifies JARs, CycloneDX SBOMs, SLSA provenance attestations, and license compliance reports for every dependency.
Works seamlessly through Artifactory, Nexus, or any repository manager proxying maven.http4k.org. Fits into your existing infrastructure with no changes.
Step 1 - Apply the Verify plugin to your build. Every http4k dependency is now verified before compilation.

Step 2 - On first build, all artifact signatures are verified and cached. Subsequent builds have zero overhead.

Get automated supply chain verification for every http4k dependency - giving your security team the assurance they need, with zero developer overhead.
Talk to us about your deployment