// HTTP4K PRO

Trust every dependency. Verify every build.

http4k Verify ensures the integrity of every http4k dependency in your build - automatically, before your code compiles.

Why verify?

Security teams, customers and auditors increasingly ask for evidence that the third-party components in your build are the ones their authors published. For most teams it arrives as a security questionnaire long before it arrives as a regulation.

http4k Enterprise Edition publishes SLSA provenance, CycloneDX SBOMs, signed licence reports and cosign signatures for every artifact. http4k Verify checks them all automatically, before your code compiles - so the assurance is captured at build time rather than chased down at audit time.

From Sep 2026
EU Cyber Resilience Act

Vulnerability reporting from 11 September 2026. SBOMs and due diligence over integrated components from December 2027.

Industry benchmark
NIST SSDF

SP 800-218 asks you to verify the integrity and provenance of third-party components (PW.4, PS.3).

Mandatory
PCI DSS 4.0.1

Requirement 6.3.2 asks for an inventory of third-party software components, for anyone handling cardholder data.

Ongoing
Supply chain attacks

Backdoors like xz-utils reach users through the release process, not through code review. Attackers have AI now too.

Highlights

Zero
Friction

One Gradle plugin. No CLI tools to install. Every http4k dependency is verified automatically before compilation.

Build-Time
Enforcement

If any artifact has been tampered with, the build fails. No silent failures, no runtime surprises. Supply chain integrity verified before your code compiles.

Full
Coverage

Covers all 200+ http4k modules - verifies JARs, CycloneDX SBOMs, SLSA provenance attestations, and license compliance reports for every dependency.

Enterprise
Ready

Works seamlessly through Artifactory, Nexus, or any repository manager proxying maven.http4k.org. Fits into your existing infrastructure with no changes.

One line. That's it.

Step 1 - Apply the Verify plugin to your build. Every http4k dependency is now verified before compilation.

Apply the plugin

Step 2 - On first build, all artifact signatures are verified and cached. Subsequent builds have zero overhead.

Verification output

Included with http4k Enterprise Edition

Get automated supply chain verification for every http4k dependency - giving your security team the assurance they need, with zero developer overhead.

Talk to us about your deployment
pumb
scarf