# ACTIVITY-WP-0030 daily bounded SBOM catch-up evidence Date: 2026-08-22 Environment: railiance01, namespace `activity-core` SBOM authority: `http://sbom-nexus.sbom-nexus.svc.cluster.local:8010` ## Delivered contract - `GET /sbom/catch-up?limit=3` is the single ranked selection call. - `params.apply: true` is an explicit side-effect marker and manual runs require operator confirmation. - The response is truncated before writes, so a fire cannot process more than its declared limit. - Missing checkouts use the terminal Nexus skip route directly. Ingest failures are recorded as terminal `ingest-error` skips. - The definition has no rule block and therefore cannot emit per-repository tasks or Forgejo issues. The Activity Core implementation commits are `8e8c74b` (bounded executor), `91ae8dc` (production service URL), and `c2f797f` (enabled Railiance projection). The deployment package commit `94742b6` admits the `activity-core` namespace to the otherwise private SBOM Nexus runtime. ## Verification - Focused implementation suite: 20 passed. - Enabled projection suite: 21 passed. - Clean committed revision suite: 409 passed, 1 conditional skip. - SBOM deployment package suite: 5 passed. - Live worker read-only probe returned exactly three ranked repositories and confirmed the in-cluster Nexus URL. - SBOM Nexus deployment and migration verification remained healthy after the NetworkPolicy change. ## Production fires | Fire | Activity run | Selected repositories | Outcome | Tasks | | --- | --- | --- | --- | ---: | | 1 | `82379bc0-7d88-573d-a06f-0ef5fc43cf84` | `adaptive-pricing`, `agent-harness`, `agentic-resources` | 3 `no-checkout` skips | 0 | | 2 | `512a8570-2c33-51d6-afd8-5879c85a235d` | `artifact-store`, `audit-core`, `binky-control` | 3 `no-checkout` skips | 0 | State Hub progress IDs are `a9e8acea-a6e2-4b51-b2ed-f1769403ca73` and `f8b59633-692d-447c-8015-4778c9f27fd5`. Each event contains selected and skipped repositories, the skip reason, fleet counters, and the Activity Core run ID. The second fire selected a different batch; `never_count` moved from 101 to 98, proving that recorded skips advance queue fairness without claiming a scan success. ## Schedule posture - `daily-sbom-catchup`: enabled, Temporal schedule active, weekdays at 09:15 Europe/Berlin, limit 3. - `weekly-sbom-staleness`: disabled, Temporal schedule paused; its last fire was 2026-08-17 and it must not be re-enabled. - Next normal daily window after enablement: Monday 2026-08-24 at 09:15 Europe/Berlin.