http4k Verify ensures the integrity of every http4k dependency in your build - automatically, before your code compiles.
Security teams, customers and auditors increasingly ask for evidence that the third-party components in your build are the ones their authors published. For most teams it arrives as a security questionnaire long before it arrives as a regulation.
http4k Enterprise Edition publishes SLSA provenance, CycloneDX SBOMs, signed licence reports and cosign signatures for every artifact. http4k Verify checks them all automatically, before your code compiles - so the assurance is captured at build time rather than chased down at audit time.
Vulnerability reporting from 11 September 2026. SBOMs and due diligence over integrated components from December 2027.
SP 800-218 asks you to verify the integrity and provenance of third-party components (PW.4, PS.3).
Requirement 6.3.2 asks for an inventory of third-party software components, for anyone handling cardholder data.
Backdoors like xz-utils reach users through the release process, not through code review. Attackers have AI now too.
One Gradle plugin. No CLI tools to install. Every http4k dependency is verified automatically before compilation.
If any artifact has been tampered with, the build fails. No silent failures, no runtime surprises. Supply chain integrity verified before your code compiles.
Covers all 200+ http4k modules - verifies JARs, CycloneDX SBOMs, SLSA provenance attestations, and license compliance reports for every dependency.
Works seamlessly through Artifactory, Nexus, or any repository manager proxying maven.http4k.org. Fits into your existing infrastructure with no changes.
Step 1 - Apply the Verify plugin to your build. Every http4k dependency is now verified before compilation.

Step 2 - On first build, all artifact signatures are verified and cached. Subsequent builds have zero overhead.

Get automated supply chain verification for every http4k dependency - giving your security team the assurance they need, with zero developer overhead.
Talk to us about your deployment