--- id: ACTIVITY-WP-0034 type: workplan title: "Freeze controlled SBOM source references across retries" domain: infotech repo: activity-core status: active owner: codex topic_slug: infotech created: "2026-08-22" updated: "2026-08-22" quality_dor: DoR-Ok quality_dor_at: "2026-08-22" quality_dor_by: codex quality_dor_note: "CUST-WP-0064 selected a reviewable full-SHA source_ref contract; Nexus owns fetch/scan, Activity Core retains the existing bounded target and stable operation identity, and rollout waits on the new Nexus/package digest." parent_workplan: CUST-WP-0064 related: - SBOM-WP-0003 - ACTIVITY-WP-0033 state_hub_workstream_id: "409c06c0-65df-5eaf-8099-9b4e70185f19" --- # Freeze controlled SBOM source references across retries ## Carry the immutable source reference ```task id: ACTIVITY-WP-0034-T01 status: done priority: high state_hub_task_id: "8d9818f3-c995-5352-8116-f5d4f1ba488b" ``` Validate and retain Nexus's `forgejo-archive-v1` source reference in the ranked selection, send it on ingest, reuse it with the existing stable operation key, and report additive source failure outcomes without selecting a replacement target. Completed in the resolver/apply adapter and daily definition with focused tests for normalization, POST payload, retry identity, and terminal reasons. ## Promote after the Nexus dark canary ```task id: ACTIVITY-WP-0034-T02 status: wait priority: high state_hub_task_id: "036de401-18de-5a94-8f0d-18d60b64c56a" ``` After `SBOM-WP-0003` and `RAPP-SBOM-NEXUS-WP-0002` migrate and pass the attended one-repository canary, project this revision to Railiance, sync the existing schedule without widening its limit, and capture the first normal scheduled controlled-source result.