http4k Verify ensures the integrity of every http4k dependency in your build - automatically, before your code compiles.
One Gradle plugin. No CLI tools to install. Every http4k dependency is verified automatically before compilation.
If any artifact has been tampered with, the build fails. No silent failures, no runtime surprises. Supply chain integrity verified before your code compiles.
Covers all 200+ http4k modules - verifies JARs, CycloneDX SBOMs, SLSA provenance attestations, and license compliance reports for every dependency.
Works seamlessly through Artifactory, Nexus, or any repository manager proxying maven.http4k.org. Fits into your existing infrastructure with no changes.
The CRA requires machine-readable SBOMs and secure development practices for software sold in the EU. http4k Verify validates SBOMs for every dependency at build time.
Federal agencies require SBOMs for all purchased software. http4k Verify validates that SBOM signatures are authentic and untampered.
The Secure Software Development Framework recommends consuming provenance and verifying third-party components. http4k Verify automates this at build time.
Strengthened supply chain requirements for payment-processing software. http4k Verify provides verifiable evidence of artifact integrity for your audit trail.
Step 1 - Apply the Verify plugin to your build. Every http4k dependency is now verified before compilation.

Step 2 - On first build, all artifact signatures are verified and cached. Subsequent builds have zero overhead.

Get automated supply chain verification for every http4k dependency - giving your security team the assurance they need, with zero developer overhead.
Learn about Enterprise Edition