The Spring Framework includes the ASL license.txt in META-INF of released jars: https://github.com/spring-projects/spring-framework/blob/05500373e2cbc5a907c4e1a954b6ad8cc163f5e1/gradle/spring-module.gradle#L53
It would be nice if Spring Security could do likewise to make it easier for SBOM tools to determine the license when scanning the jars.